MRG Effitas Comparative Efficiency Assessment of Enterprise Security Suites against In-the-wild Rans

Discussion in 'other anti-virus software' started by itman, Jun 5, 2017.

  1. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.

    http://media.kaspersky.com/pdf/201704-MRG-Ransomware-Test.pdf
     
  2. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    Thanks for posting, I still have to read the full report, but this is going to be interesting. Seems like Sophos Intercept X didn't perform as good as expected.
     
  3. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    Also for folks that want an effective free stand-alone anti-ransomware solution, Kaspersky's scored 100%; same as their full Enterprise solution.
     
  4. thanhtai2009

    thanhtai2009 Registered Member

    Joined:
    Feb 16, 2010
    Posts:
    225
    Location:
    Vietnam
    Honestly, I don't trust any of these sponsored tests - that's all.
     
  5. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    8,645
    Location:
    USA
    I don't expect that the sponsorship affects the results. That said, you aren't going to sponsor a test you aren't going to do well in.
     
  6. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    There is a testing note in the report in regards to Intercept X. It protected files "commonly" target by ransomware but other file extensions were encrypted e.g. .txt, .exe, etc.. Sage ransomware targets Python extensions i.e. .py which Intercept X allowed to be encrypted.
     
  7. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    Yes, on second thought, results weren't THAT bad. But as usual I have to comment on the fact that MRG never explains how all of those malware/ransomware samples were stopped, was it via signature or behavior blocking? This is interesting to me.
     
  8. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    Actually they did explain it in Section 5 of the report. Stated there was if the product detected by behavior with some files being encrypted prior to detection. It is also noted in the footing section of the detection results chart.

    Of note was Kaspersky was configured to run with max. protection settings whereas as Eset ran with their default settings.
     
    Last edited: Jun 6, 2017
  9. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    Yes but it doesn't answer my question. For example Kaspersky and Eset both had a 100% detection rate, but they don't tell how they managed to block all of the samples. They might as well blocked them all via signature.

    We all know how many ransomware variants there are, and how easy it is to bypass signature detection. So you must also offer behavior based detection, to catch new variants. So would be cool to know just how good behavior based detection of all of these products is. Would be cool if they can do this same test with tools like RansomOff, RansomFree and Appcheck.
     
  10. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    I believe it would be accurate to state that most AV products use a combination of signature, heuristic, and cloud rep analysis to determine if an unknown executable is attempting ransomware like activities. All these products are geared to blocking any program, script, etc. activity rather than detecting ransomware post execution phase. This insures that any secondary payload malware is blocked from installing.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.