Virus Weekly Stats....0Day

Discussion in 'other anti-virus software' started by apm, Jan 9, 2008.

Thread Status:
Not open for further replies.
  1. C.S.J

    C.S.J Massive Poster

    Joined:
    Oct 16, 2006
    Posts:
    5,029
    Location:
    this forum is biased!
    bunk, I still ain't sure

    Waiting for someone to find out if it is ;)

    By either way, alot of malware is tested and drweb detects alot of it, so, so far I'm happy

    I never rely on tests but some ppl do, to me ... I know from personal experience that drweb is better than most ppl think here on wilders.
     
  2. Blackcat

    Blackcat Registered Member

    Joined:
    Nov 22, 2002
    Posts:
    4,024
    Location:
    Christchurch, UK
    Most of these critics have never even used Dr Web!
     
  3. Bubba

    Bubba Updates Team

    Joined:
    Apr 15, 2002
    Posts:
    11,271
  4. patrikr

    patrikr AV Expert

    Joined:
    Aug 9, 2005
    Posts:
    97
    Location:
    California, USA
    Got a reply and they're using the publicly available signatures for all of the scanners and are testing all products against the same set of binaries. So the numbers are true.

    Patrik
     
  5. freed0

    freed0 Registered Member

    Joined:
    Jan 13, 2008
    Posts:
    1
    Evening all,

    Richard here from Shadowserver. You can blame me for any mistakes on our web pages. In the future if anyone has a question about any of the statistics, our methods on generating them, or anything, please drop me an email.

    Now on to the more specific questions.

    All the results that you see on our pages are really controlled by several factors. The primary being what types of binaries we actually gathered in the last day, and which ones were queued up for the testing. Some of the AV vendors do very well against certain types of malware and not as well against others.

    We get in between 50k to 200k new unique binaries each day. We are only able to test a portion of those because of resource constraints. We generate the test list and each vendor is tested against the exact same list. Not all vendors were created equal, and some can take a large amount of time to test the same set of binaries. So, this limits us on how many we can test. Unless of course someone wants to donate more dual quad-core machines for us to use... :)

    The specific results are those that each vendor spits out. We did our best to write a generic parser to catch each of the 'real' names that the vendors uses, but even that can never be perfect.

    We treat each of the vendors equally and are not sponsored by any of them. Several have donated licenses for us to us, but we have paid for the majority of them ourselves. Any vendor that donates a license will be sent up to 10k binaries each day that they do not detect. Assuming that do not detect that many.

    Each vendor is updated once an hour from the normal public repositories that any normal user would be using. So, depending on your version and options, YMWV. You can see the specifics on our command usage here:

    http://www.shadowserver.org/wiki/pmwiki.php?n=Stats.Viruses

    We have tried to show the data as impartially as possible, so, if anyone has any suggestions on how to improve upon what we are showing, I am happy to take in any suggestions that you may have. I just cannot promise to try to reply to all the posts, unless someone warns me that I should.. :)

    Hopefully this helped clarify some of how we are generating the statistics that seemed to have created some confusion.


    Richard
     
  6. FRug

    FRug Registered Member

    Joined:
    Feb 7, 2006
    Posts:
    309
    The problem is, people have a tendency to see numbers as an absolute, while often (as in this case) they do not mean exactly what they think they do.
    Admittedly that's not really the fault of Shadowserver, but you may want to add something about the numbers explaining there is a heavy bias towards samples of a malware variant that you receive very often.

    Taking todays stats as an example:
    Total number of samples: 67400
    Brontok.Z.1: 63334

    So, ~93% of the sample set are actually one and the same malware strain. Binary-different maybe, but that's not really relevant here now is it?

    Dear Forum Folks, you should know by now that you can't take such values as absolute indicators of detection rate.

    @freed0: You really should add something mentioning that bias to your stats pages, it might even prevent some misunderstandings of what you guys do and keep random accusations off your backs. In very large red letters ;)
     
  7. C.S.J

    C.S.J Massive Poster

    Joined:
    Oct 16, 2006
    Posts:
    5,029
    Location:
    this forum is biased!
    well done for drweb then ;)
     
  8. Mele20

    Mele20 Former Poster

    Joined:
    Apr 29, 2002
    Posts:
    2,495
    Location:
    Hilo, Hawaii
    Does that web site not like Firefox? The 0Day Summary and ReTry Summary (whatever that is) is not there. Two large blank spots.
     

    Attached Files:

  9. Gizzy

    Gizzy Registered Member

    Joined:
    Oct 5, 2007
    Posts:
    149
    Location:
    NJ, USA
    works fine with Firefox for me,
    perhaps an add-on is causing the problem?
     
  10. jrmhng

    jrmhng Registered Member

    Joined:
    Nov 4, 2007
    Posts:
    1,268
    Location:
    Australia
    Yes it works fine for me too. Maybe just refer to the screenies posted before.
     
  11. Mele20

    Mele20 Former Poster

    Joined:
    Apr 29, 2002
    Posts:
    2,495
    Location:
    Hilo, Hawaii
    I don't know what it could be. I only have 7 extensions and none of them should affect the display of the page like that. I tried on both Fx 1.5.12 and Fx 2.0.

    I then tried on Opera 9.24 and I can see it there. Fx displays EVERYTHING on that website in a weird manner. I didn't realize how strange the display is of the part of the page I can see on Fx until I tried Opera there.
     
  12. Bunkhouse Buck

    Bunkhouse Buck Registered Member

    Joined:
    May 29, 2007
    Posts:
    1,286
    Location:
    Las Vegas
    I have Fx and no problems at all.
     
  13. flyrfan111

    flyrfan111 Registered Member

    Joined:
    Jun 1, 2004
    Posts:
    1,229
    Same here, Firefox and Opera work perfectly. It must a plug in or something Mele:eek:
     
  14. BlueZannetti

    BlueZannetti Registered Member

    Joined:
    Oct 19, 2003
    Posts:
    6,590
    or something with how Proxomitron is handling things....

    Blue
     
  15. Sjoeii

    Sjoeii Registered Member

    Joined:
    Aug 26, 2006
    Posts:
    1,240
    Location:
    52?18'51.59"N + 4?56'32.13"O
  16. C.S.J

    C.S.J Massive Poster

    Joined:
    Oct 16, 2006
    Posts:
    5,029
    Location:
    this forum is biased!
    there are many 99% avs this week for zero day
     
  17. Sjoeii

    Sjoeii Registered Member

    Joined:
    Aug 26, 2006
    Posts:
    1,240
    Location:
    52?18'51.59"N + 4?56'32.13"O
    Indeed
    They did well
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.