![]() |
|
#1
|
|||
|
|||
|
Look at the MRG test results and please tell me I'm hallucinating.
Prevx failed 3 of 4. |
|
#2
|
|||
|
|||
|
Pretty sad
![]() |
|
#3
|
||||
|
||||
|
The Flash tests are over single samples which don't reflect the tens of thousands of other samples we're blocking every day. There isn't an issue - no vendor finds 100% and it is easy to find files that would bypass every vendor listed every day if wanted - it is just the nature of today's malware.
|
|
#4
|
|||
|
|||
|
Quote:
Last edited by Kirk Reynolds : July 20th, 2011 at 12:04 AM. |
|
#5
|
||||
|
||||
|
Quote:
No, they do have value. They are a point-in-time snapshot of single file threats and need to be understood as such. Just because we missed SpyEye today doesn't mean that we miss all SpyEye - it could very well just be that we missed that single sample. To put it in perspective - we have detection over several hundred thousand unique versions of SpyEye alone. I don't have the MD5s/samples of the samples so I couldn't get further metrics on the scope of these files but most infections today are designed to only ever affect a very small number of users. |
|
#6
|
|||
|
|||
|
Ah ok, I gotcha.
![]() |
|
#7
|
|||
|
|||
|
It should be pointed out that any missed samples are sent to the vendor before the test results are published - quote by Sveta of MRG:
Quote:
|
|
#8
|
||||
|
||||
|
Quote:
Also Prevx would have them in there database when MRG scan them that's the good thing about full cloud based Anti-Malware we don't have to wait for a signature download to be protected! TH
__________________
Triple Helix - Microsoft® MVP Consumer Security 2012/14 VIP Member Of ASAP - (Alliance of Security Analysis Professionals™) Webroot® SecureAnywhere™ Complete 2013 Closed Beta Tester v8.0.2.155 - VoodooShield 1.08 - Windows 7 Ultimate 64bit and all Windows OS's from XP to Win 8 on VM's. Last edited by Triple Helix : July 20th, 2011 at 05:50 PM. Reason: added more info |
|
#9
|
||||
|
||||
|
MRG test with programs at default settings. If age/popularity based heuristics were increased, I would assume Prevx's detection rate would increase in these tests.
I have always run max program heuristics and high age/popularity and don't find false positives to be excessive, but am now considering an increase to max for both. PrevxHelp (Joe) are you able to tell from your end what difference an increase in age/popularity based heuristics would have made in each of the missed samples from the MRG tests?
__________________
Win7 Pro x64 SP1 - SUA - UAC(max) - SRP - EMET 3.5 Realtime: Webroot SecureAnywhere - Windows Firewall On Demand: Hitman Pro - Emsisoft Emergency Kit - OTL - Secunia PSI Imaging: Windows Backup & Restore - Macrium Reflect Free Router: Linksys |
|
#10
|
||||
|
||||
|
I'm not sure - I haven't been able to find who within Prevx is receiving the samples from MRG so I still don't have visibility into them. I'm still investigating and should hopefully have an answer by the morning.
|
|
#11
|
|||
|
|||
|
Could you get ur hands on them? I'm curious eheh
|
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|