Results 1 to 10 of 11
Thread: On the way to better testing
- 02-04-2010 #1
On the way to better testing
Analyst Diary | Viruslist.comHave you ever found a false positive when uploading a file to a website like VirusTotal? Sometimes it happens that not just one scanner detects the file, but several. This leads to an absurd situation where every product which doesn't detect this file automatically looks bad to users who don't understand that it's just false positives.
PCmag| Tests Show Problems With AV Detections"positive anything is better than negative nothing"
- 02-04-2010 #2
wow, ceyfer, thanks for the article...it was good read....and also shows that such scanners cant be totally relied on.....
If nothing else works, open command prompt and type 'del C:\Windows'
- 02-04-2010 #3
Agreed...that is why I don't rely on VirusTotal as much as I used to...false positives are becoming more 'common' nowadays...what started out as a service to help users differentiate a clean file from a malicious file has now become a "try-and-guess" service...especially now that it has been widely abused by the warez community....
They call me the mysterious one...
my motto is...when it's hot, chill baby
- 02-04-2010 #4*nix Technical Support
Achievements:




Awards:
- Join Date
- Jan 2009
- Location
- /home/hellnoire
- Posts
- 10,231
- Liked
- 293 times
Well, what I like is my application that I've written myself trips off Norton... that kinda tells me Norton and other scanners need to update, and quickly.
pacman -Syyu life not found in sync db
- 02-04-2010 #5
Norton's Sonar is known for being sensitive if I'm not wrong (that's what most users said)...perhaps ceyfer can tell us more in detail...but then again, I'm sure ceyfer would ask you hellnoire to report it to Norton since it's a FP
- 02-04-2010 #6
I could understand them- the malware cleaning industry is now having a stiff competition, no one would like to leave behind.But, understand is not tolerate just like detecting doesn't mean successful clean.Hence, they should carefully analyse the samples before compile it into database...
- 02-04-2010 #7I forgot that I wanted to say YES!!! Quite a few times in factHave you ever found a false positive when uploading a file to a website like VirusTotal? Sometimes it happens that not just one scanner detects the file, but several. This leads to an absurd situation where every product which doesn't detect this file automatically looks bad to users who don't understand that it's just false positives.
- 02-04-2010 #8
Overall, that's a Dead-End situation:
-"Aggressive" Scanners =>False Positives!
-"Mild" Scanners =>Lower Detection!
Taking this "about FP" Thread as an initiative, I ask you:
-What AV Scanner to Trust?
-Do AV vendors respond *Early enough* to Malware
(through Heuristics, Cloud etc.)
when 50,000 new types of Malware, on Average, come up each day?
Reymond's TEST No.6 revealed much...Summary Results:
http://lookpic.com/i/872/AjUmZCPC.png
Thank you Reymond for your Revealing work!!!Last edited by 212eta; 02-04-2010 at 09:02 PM.
- 02-04-2010 #9*nix Technical Support
Achievements:




Awards:
- Join Date
- Jan 2009
- Location
- /home/hellnoire
- Posts
- 10,231
- Liked
- 293 times
Ceyfer can tell me to report a FP, I already have. Norton hasn't gotten back to me yet.
- 02-08-2010 #10
I guess it'll take time hellnoire...they can't possibly attend to everyone who reports within a short time...what more if it is the developer of the program himself who reports it..
Similar Threads
-
Five tips for testing Web browser security
By sujay in forum Spyware/VirusesReplies: 7Last Post: 01-09-2011, 01:48 PM -
BackBox Linux 1 RC - Penetration testing
By leofelix in forum LinuxReplies: 5Last Post: 09-24-2010, 01:55 PM -
AV-Test: Real World Testing
By Neo in forum Spyware/VirusesReplies: 12Last Post: 09-17-2010, 01:59 AM -
web site testing tool
By netha in forum General ForumReplies: 3Last Post: 02-03-2010, 09:54 PM -
browser for testing and reviews
By trinidude in forum General ForumReplies: 11Last Post: 07-01-2008, 05:32 PM


LinkBack URL
About LinkBacks





Reply With Quote