AVLab - "Protection test against drive-by download attacks" (April 2017)

Discussion in 'other anti-virus software' started by ichito, Jun 20, 2017.

  1. ichito

    ichito Registered Member

    Joined:
    Jan 14, 2011
    Posts:
    1,997
    Location:
    Poland - Cracow
    "In recent months, viruses that were infecting personal computers and employee
    workstations through drive‐by download attacks have been playing a major role in
    global threats. These techniques are commonly used in exploit kits, tools that make it
    easy to automatically search for vulnerabilities (mostly installed in browsers and plug‐
    ins). They optimize and adapt exploits to an operating system version and an
    architecture, and an installed browser.

    (...)
    In this unique test, we wanted to check if comprehensive security applications
    protect against attacks which use software vulnerabili⵼es. If it was necessary, we
    enabled protection against exploits, as well as website scanners. All other options
    were set to default."

    https://avlab.pl/sites/default/files/68files/avlab_drive_by_download_test_en.pdf
     
  2. shadek

    shadek Registered Member

    Joined:
    Feb 26, 2008
    Posts:
    2,538
    Location:
    Sweden
    Kaspersky and Bitdefender at the top, as in all other tests.

    Webroot. :thumbd: Windows Defender. :thumbd:
     
  3. garrett76

    garrett76 Registered Member

    Joined:
    Mar 18, 2014
    Posts:
    221
    After the ransomware test another very interesting one by AVlab. Unfortunately, most of the av solutions lack adequate protection against scripts in a powershell interpreter, which is a real pity because nowadays it is one of the most used vector for infection.
     
  4. imuade

    imuade Registered Member

    Joined:
    Aug 4, 2016
    Posts:
    751
    Location:
    Italy
    Nice review indeed.
    About Comodo (which I use), they said "Software provider Comodo quickly implemented appropriate security rules for scripts and applications run by a PowerShell interpreter"

    I know that in CCAV they added an option to block incoming and outgoing internet connections of sandboxed apps. I wonder if that's what AVlab mentioned
     
  5. Lockdown

    Lockdown Registered Member

    Joined:
    Oct 28, 2016
    Posts:
    772
    Location:
    Wilders Security
    Disable powershell. Doing so eliminates an attack vector that uses the PS shell - which is what most powershell attacks do. However, powershell can be still be launched from a custom executable or *.dll. Those attacks are generated using pen-testing frameworks such as Powershell Empire.
     
  6. anon

    anon Registered Member

    Joined:
    Dec 27, 2012
    Posts:
    8,006
    AVLab (Poland) : "Protection test against drive-by download attacks"

    and the winner is......... Arcabit (Poland). :rolleyes:
     
  7. ReverseGear

    ReverseGear Guest

    All the free AV's tanked
     
  8. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    Too bad that Emsisoft was not tested...
     
  9. anon

    anon Registered Member

    Joined:
    Dec 27, 2012
    Posts:
    8,006
  10. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
  11. hawki

    hawki Registered Member

    Joined:
    Dec 17, 2008
    Posts:
    6,077
    Location:
    DC Metro Area
    Curious given Emsisoft IS's excellent results in their Ransomware Test**. Was Emsisoft afraid of something about this particular test and if so was it the validity/integrity of the testing method or something about Emsisoft IS/AM that caused the concern?

    **
    https://avlab.pl/sites/default/files/68files/ENG_2016_ransomware.pdf
     
    Last edited: Jun 20, 2017
  12. hawki

    hawki Registered Member

    Joined:
    Dec 17, 2008
    Posts:
    6,077
    Location:
    DC Metro Area
    ESET [Business and Individual User] , Norton, and Quick Heal [Individual User] also in this test.
     
  13. ArchiveX

    ArchiveX Registered Member

    Joined:
    Apr 7, 2014
    Posts:
    1,501
    Location:
    .
    Out of coincidence...:D
     
  14. Trooper

    Trooper Registered Member

    Joined:
    Jan 26, 2005
    Posts:
    5,508
    Was about to post the same. :thumb:
     
  15. anon

    anon Registered Member

    Joined:
    Dec 27, 2012
    Posts:
    8,006
    :D
     
  16. ichito

    ichito Registered Member

    Joined:
    Jan 14, 2011
    Posts:
    1,997
    Location:
    Poland - Cracow
  17. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    All these home products received the highest rating:

    Arcabit Internet Security
    Bitdefender Total Security Multi-Device 2017
    Eset Smart Security 10
    Kaspersky Total Security 2017
    Norton Security 2017
    Quick Heal Total Security 17.00
     
  18. imuade

    imuade Registered Member

    Joined:
    Aug 4, 2016
    Posts:
    751
    Location:
    Italy
    All paid products :isay:
     
  19. imuade

    imuade Registered Member

    Joined:
    Aug 4, 2016
    Posts:
    751
    Location:
    Italy
    MBAE or Hmp.a would have stopped the attack?
     
  20. Nightwalker

    Nightwalker Registered Member

    Joined:
    Nov 7, 2008
    Posts:
    1,387
    These are top solutions that score well in almost all tests, almost all the time, so no surprises here.
     
  21. garrett76

    garrett76 Registered Member

    Joined:
    Mar 18, 2014
    Posts:
    221
  22. anon

    anon Registered Member

    Joined:
    Dec 27, 2012
    Posts:
    8,006
    It's obvious that they are so good. That's why ArcaBit uses a 3rd party engine (Bitdefender).:D

    Futher to the AVLab tests, is Arkabit so good on the rest AV Testing Labs?
     
  23. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    Didn't read the report yet, but what's your take on it, did they test everything in the correct way, did everything make sense?
     
  24. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    Actually, I like this lab's creativity when it comes to testing. For example when they tested AV products in their last on-line banking comparative, no one passed all the tests. The awarding in that test was to the products that scored highest.
     
  25. Chuck57

    Chuck57 Registered Member

    Joined:
    Sep 2, 2002
    Posts:
    1,770
    Location:
    New Mexico, USA
    If you set up the firewall sandbox according to Cruelsister1's settings, the incoming and outgoing sandboxed connections are blocked. I haven't looked at the latest CCAV. Kind of like CCAV, but my comfort zone is Comodo Firewall. It works.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.