Similar Searches

Related Posts

  • Introducing the IEEE Industry Connections Security Group (August 17, 2009)

    Agreement and collaboration have been two of the greatest challenges the security community has faced from the very beginning. In an effort to address this, The Industry Connections Security Group (ICSG), a new offering from the IEEE, allows like-minded companies to come together to solve industry or business problems that ...

  • BMC and McAfee join forces | Top Industry News, Statistics (September 25, 2009)

    Enterprise management software provider BMC Software has teamed up with security software firm McAfee to develop software to detect and fix security policy violations. The partnership is aimed at integrating BMC BladeLogic Client Automation with McAfee Policy Auditor, McAfee ePolicy Orchestrator and security and remediation information from McAfee Labs. The joint ...

  • Insight: AMTSO’s Reviews (March 8, 2010)

    Some time ago (February 25–26), the Anti-Malware Testing Standard Organization (AMTSO) had its first meeting this year. This time, it was hosted by McAfee and took place in Santa Clara, California. One of the hot topics during the meeting was related to the initiative to review ...

  • Happy Birthday, AMTSO! (May 14, 2009)

    Last week, the Anti-Malware Testing Standards Organization, or AMTSO, held its second members’ meeting this year that took place in Budapest, Hungary as an extension to the CARO Workshop. AMTSO released new papers at their website, adding to their roster ...

  • Critical Control 17: Penetration Tests and Red Team Exercises (February 17, 2010)

    Attackers penetrate networks and systems through social engineering and by exploiting vulnerable software and hardware.  Once they get access, they often burrow deep into target systems and broadly expand the number of machines over which they have control.  Most organizations do not exercise their defenses so they are uncertain about ...

Related News

Related Posts

  • Introducing the IEEE Industry Connections Security Group (August 17, 2009)

    Agreement and collaboration have been two of the greatest challenges the security community has faced from the very beginning. In an effort to address this, The Industry Connections Security Group (ICSG), a new offering from the IEEE, allows like-minded companies to come together to solve industry or business problems that ...

  • BMC and McAfee join forces | Top Industry News, Statistics (September 25, 2009)

    Enterprise management software provider BMC Software has teamed up with security software firm McAfee to develop software to detect and fix security policy violations. The partnership is aimed at integrating BMC BladeLogic Client Automation with McAfee Policy Auditor, McAfee ePolicy Orchestrator and security and remediation information from McAfee Labs. The joint ...

  • Insight: AMTSO’s Reviews (March 8, 2010)

    Some time ago (February 25–26), the Anti-Malware Testing Standard Organization (AMTSO) had its first meeting this year. This time, it was hosted by McAfee and took place in Santa Clara, California. One of the hot topics during the meeting was related to the initiative to review ...

  • Happy Birthday, AMTSO! (May 14, 2009)

    Last week, the Anti-Malware Testing Standards Organization, or AMTSO, held its second members’ meeting this year that took place in Budapest, Hungary as an extension to the CARO Workshop. AMTSO released new papers at their website, adding to their roster ...

  • Critical Control 17: Penetration Tests and Red Team Exercises (February 17, 2010)

    Attackers penetrate networks and systems through social engineering and by exploiting vulnerable software and hardware.  Once they get access, they often burrow deep into target systems and broadly expand the number of machines over which they have control.  Most organizations do not exercise their defenses so they are uncertain about ...

On the Trustworthiness of the AV Industry and AV Tests

Today, I was scanning through various industry blogs when I stumbled upon an entry from Kaspersky Labs.  What was interesting was that under the veil of improving testing quality, the blog openly admitted that the organization in question had been trying to play tricks on competing organizations just to position itself more favorably among the media.

The organization explained that it deliberately created clean files and added fake detections in order to “show” that other vendors copied it. This was a risky decision. Across the industry, research organizations share a level of trust and participate in sample-sharing programs in order to protect customers, which for Trend Micro, is what always comes first.  (I should just add here, that Trend Micro was not one of those companies affected by this, as we always QA our own detections and never rely on those of another vendor).

Aside from the organization’s cheap prank, we were very pleased that the other resounding message that came from the blog post was that it finally understood and supported the message Trend Micro has been promoting for a long time now—the need for change in testing methodologies to include real-world testing such as those delivered by NSS Labs.

The need to change testing methodologies was also a primary reason for the foundation of the Anti-Malware Testing Standards Organization (AMTSO), which aims to come up with more realistic and useful benchmarks.

This story really shows just how influential the media is on the antivirus industry in that even

...
Read the original story


Source: Martin Roesler (Director for Threat Research) @ TrendLabs | Malware Blog - by Trend Micro

Write a Comment

Copyright © 2010 The Security Blog. All rights reserved.
Web Statistics Homeland Security blogs & blog posts