Network and Computer Security

The Network and Computer Security Blog

Bookmark this site!

September 2, 2006

Latest polymorphism hides viruses better

Filed under: News, Virus, Windows — SecuNews @ 11:27 am

Just as if we needed that, a new polymorphism technique allows viruses on AMD-64 processors to be even harder to detect.

The virus, dubbed W64.Bounds, is not spreading in the wild, but was submitted as a proof of concept to antivirus researchers. The program is not easy to detect because it encrypts itself using a new algorithm and exploits a Windows feature available only on AMD64 systems to control execution”, Peter Ferrie, senior antivirus researcher for Symantec, said.

See the full article on SecurityFocus.

July 24, 2006

Why popular antiviruses still don’t work well

Filed under: Virus, Articles — SecuNews @ 12:13 pm

It’s no news that no antivirus is 100% safe.

It has always been that way and will always be. The answer is simple: there are actually very few antiviruses sharing the biggest market share (the top 5 AVs most likely represent more than 95% of the installed base). So the virus writters can very quickly check their “lastest,not-released-in-the-wild-yet” virus and see which antivirus applications detect it as a malware and modify it accordingly.

ZDNet just published a good paper on the subject: Why popular antivirus apps ‘do not work’?

July 1, 2006

Want to know that the best antivirus software is?

Filed under: News, Virus, Articles — SecuNews @ 11:25 am

We’re all wondering which antivirus is the best one to protect our servers.

The guys from Nephentes wondered the same thing and took the time to submit a sample of 4987 viruses to 14 antivirus softwares running on *nix platforms (some free some not).

The full study is here, but if you’re impatient here’s the summary:

Rank Product Hit Rate Trend
1 Antivir 99,04% +7,07%
2 BitDefender 96,23% +1,52%
3 VirusBlokAda 95,17% +1,42%
4 F-Prot 94,02% +2,39%
4 Authentium 94,02% new
5 Norman Virus Control 93,78% +1,19%
6 Fortinet 87,29% +2,35%
7 F-Secure Antivirus 85,22% +5,99%
8 Kaspersky 85,10% +5,73%
9 VirusBuster 82,53% +11,76%
10 Trend Micro 76,19% +5,14%
11 ClamAV 71,41% -0,85%
12 NOD32 70,06% +4,05%
13 Sophos SWEEP 68,58% +2,45%
14 eTrust 63,97% new

(Note: the ‘Trend’ percentage is the variation between the current test and the previous one)

March 8, 2006

Nessus 3.0.2 released

Filed under: Virus, Linux — SecuNews @ 5:01 pm

In december, Nessus 3.0.0 has been released bringing major evolutions compared to the Nessus 2 branch. It’s hard to memtion all the changes, but basically Nessus 3 is a fully rewrite of Nessus 2 and as a result performances got a huge boost. However during those major changes some new problems creep in. Nessus 3.0.1 fixed most of them and the newly released Nessus 3.0.2.