Members
  • Total Members: 14176
  • Latest: toxxxa
Stats
  • Total Posts: 42955
  • Total Topics: 16151
  • Online Today: 4556
  • Online Ever: 51419
  • (01. January 2010., 10:27:49)









Author Topic: Only Kaspersky, Trend Micro, Avast & McAfee effectively protect Microsoft users  (Read 2161 times)

0 Members and 1 Guest are viewing this topic.

Samker

  • SCF Administrator
  • *****
  • Posts: 7528
  • KARMA: 322
  • Gender: Male
  • Whatever doesn't kill us makes us stronger.
    • SCforum.info - Samker's Computer Forum


Many antivirus suites are incapable of effectively blocking malware attacks against two recent and serious Microsoft vulnerabilities despite the fact that real exploits have been circulating since June, testing organization NSS Labs has found: http://www.nsslabs.com/company/news/press-releases/nss-labs-tests-top-consumer-anti-virus-products-for-protection.html

The firm looked at the ability of 13 antivirus suites to defend unpatched systems against attacks exploiting vulnerabilities in Microsoft's XML Core Services (CVE-2012-1889) and in Internet Explorer 8.0 (CVE-2012-1875), both made public in June.

Despite the fact that both were patched in June and July and should be on the radar of antivirus companies, only four products -- from Trend Micro, Kaspersky Lab, McAfee, and Avast -- were able to offer full protection against the test exploits NSS Labs crafted to use against the vulnerabilities.

The rest were able to offer a degree of protection that depended on how the attacks were executed and which vulnerability was being tested.

Some products struggled when attacks were delivered over HTTP while a further several were unable to cope when attacks were executed via HTTPS, such as would be the case when using services such as Gmail. These included, ironically, Microsoft's own Security Essentials itself.

Security Warnings

Beyond the generally mediocre performance of some products, there seem to be two issues raised by NSS Labs' findings.

First, users shouldn't assume that antivirus offers strong protection for unpatched systems. If a vulnerability is in the public domain and no patch is available (or is available but hasn't been applied), a system is open to attack regardless of what antivirus software is defending the endpoint.

Second, malware writers probably pay attention to the strengths and weaknesses of antivirus software just as much as testers do, especially individual products. If a product has a particular type of weakness, however short-term, that will have been noticed.

"The combinations of failures and successes are dramatic and necessitate further research. It is clear that many of the products are not blocking exploits," the researchers conclude.

Antivirus firms will doubtless point out that the attacks were crafted in the lab, that the the vulnerabilities chosen were fairly recent, and that only two were looked at. Making judgements on the basis of such a narrowly-defined test offers only one indication among a number.

In one ray of positive news, the testers found that antivirus products were good at spotting common evasion techniques such as Base 64, Unicode, and JavaScript. Less optimistically, Microsoft and CA's software could be disabled by an attack using 'kill' command, NSS Labs said.

The full results can be obtained from NSS Labs website (registration required).

(PCW)

Samker's Computer Forum - SCforum.info


 

With Quick-Reply you can write a post when viewing a topic without loading a new page. You can still use bulletin board code and smileys as you would in a normal post.

Name: Email:
Verification:
Type the letters shown in the picture
Listen to the letters / Request another image
Type the letters shown in the picture:
Second Anti-Bot trap, type or simply copy-paste below (only the red letters):www.scforum.info:

Enter your email address to receive daily email with 'SCforum.info - Samker's Computer Forum' newest content:

Terms of Use | Privacy Policy | Advertising