Thursday, August 25, 2011

August 2011 – Virus Bulletin RAP Averages Quadrant, February 2011 through August 2011, Steve Jobs

November update - go to a more current write-up at http://kensek.blogspot.com/2011/11/october-2011-virus-bulletin-rap.html

Virus Bulletin released their latest RAP Averages Quadrant, representing February 2011 through August 2011 data. The bar gets set higher on this blog for a mention since almost 30 companies achieved greater than 90% on Reactive Detection and 80% on Proactive Detection. The standard this time, 90% Reactive and Proactive. Ten companies met this threshold; in approximate order - Bkis, Coranti, TrustPort, BullGuard, G Data, F-Secure IS, Avira Pro, Kaspersky Pure, Nifty (who the heck are they?) and Check Point.

Coranti, TrustPort and BullGuard were among the top four during the December 2010 through June 2011 test. Congratulations for consistency.

Double kudos to Avira and Kaspersky. These two companies had products that received the only 3 stars in AV-Comparatives.org’s Anti-Virus Comparative Retrospective test (static detection of new/unknown malicious software) earlier this year. http://kensek.blogspot.com/2011/05/av-comparatives-retrospective-test.html

What’s with Kingsoft solutions? They’ve consistently been in the lower left hand corner of the grid with around 15%/20% with respect to Reactive/Proactive Detection. In their case, consistency is bad.

The relative performance of vendors can best be viewed by looking at the RAP Averages Quadrant chart at http://www.virusbtn.com/vb100/latest_comparative/index Subscribers to Virus Bulletin's publications have access to more details on the results.

This test measures products' detection rates across four distinct sets of malware samples. The first three test sets comprise malware first seen in each of the three weeks prior to product submission. These measure how quickly product developers and labs react to the steady flood of new malware emerging every day across the world. A fourth test set consists of malware samples first seen in the week after product submission.

Best Wishes to Steve Jobs

Applause and best wishes to Steve Jobs and his family. To the extent he wants/demands it; he should be given his privacy. Jobs has been an icon, introducing some “insanely great” products to the world. He’s been a fanatic on product design. The 1984 Super Bowl advertisement was a classic. He may also, on a humorous note; be remembered for his “don’t hold it that way” comment…. regarding the iPhone's earlier reception problems. He drove the growth of Pixar before selling it to Disney for a gazillion dollars.

The computer mouse and GUI may have originally been developed by PARC (Palo Alto Research Center). However, it was Jobs and Apple that took these technology leaps, saw their value and introduced them into widespread use. Fortune Magazine recognized Steve Jobs as the CEO of the Decade in 2009.

Interesting books to read - “iCon: Steve Jobs, the Greatest Second Act in the History of Business”. “Options: The Secret Life of Steve Jobs - A Parody”. The Woz introduced the author at a book signing at Kepler’s books in Menlo Park, California in 2007, when the book came out. Wozniak was hilarious. Yes, I was there. Also, “The Journey Is the Reward” by Jeffrey S. Young, a biography about Jobs.

Tuesday, August 23, 2011

Virus Bulletin August VB100 Awards

Virus Bulletin has released their latest VB100 awards results. Thirty-eight antivirus internet security solutions received a VB100 award. Eleven antivirus internet security solutions failed to make the grade. The tests were done on Windows Vista SP2 x64 Business Ed. Of the eight 3 star performers in av.comparatives.org “Whole Product ‘Real World’ Dynamic Test” March through June, five of them, F-Secure, BitDefender, G Data, Eset, and Avast, received VB100 Awards.

Not in the Virus Bulletin August VB100 test were some major vendors - Symantec, and Trend Micro, as well as Panda. Trend Micro and Panda received 3 stars from av.comparatives.org in the above test. McAfee participated this time but not in the June test. To see the complete August VB100 test results - http://www.virusbtn.com/vb100/archive/test?order=result&id=165&tab=onDemand

G Data did not receive an award in the Virus Bulletin June VB100 Awards. The largest paid vendor that failed to receive a VB100 award in August was Kaspersky. One company had a streak of 20 consecutive VB100 awards that they had entered for, ended. Comodo, who had won a survey on CNET's download sight earlier this year, failed to receive a VB100. For the June results http://kensek.blogspot.com/2011/06/virus-bulletin-june-vb100-awards.html

To view av.comparatives.org “Whole Product ‘Real World’ Dynamic Test” March through June 2011, go to http://www.av-comparatives.org/images/stories/test/dyn/wpdt2011_1_en.pdf

VB100 Test Methodology

The purpose of the VB100 comparative is to provide insight into the relative performance of the solutions taking part in the tests, covering as wide a range of areas as possible within the limitations of time and available resources. More details are available at http://www.virusbtn.com/vb100/about/methodology.xml

UK based Virus Bulletin www.virusbtn.com started in 1989. The organization provides PC users with a regular source of intelligence about computer viruses, their prevention, detection and removal, and how to recover programs and data following an attack. VB’s website is at www.virusbtn.com.


Saturday, August 20, 2011

Best Channel Products 2011 – Business Solutions Magazine

Business Solutions Magazine (BSM) has published the results of their “Best Channel Products 2011" survey. Fortinet, SonicWall, and AVG Technologies dominated the Network Security category. In the area of Network Security, below are the top products from the survey.

Email Security


• AVG Internet Security Business Edition -Top 2 Categories: Ease Of Integration, Ease Of Upgrade
• Fortinet FortiMail-3000C - Top 2 Categories: Reliability/Durability, Features/Functionality

Endpoint Security

• AVG Internet Security Business Edition - Top 2 Categories: Features/Functionality, Reliability/Durability
• Fortinet FortiClient - Top 2 Categories: Reliability/Durability, Ease Of Integration

Unified Threat Management

• Fortinet FortiGate-80C - Top 2 Categories: Features/Functionality, Reliability/Durability
• SonicWALL TZ Series - Top 2 Categories: Reliability/Durability, Features/Functionality

Web Content Filtering

• Fortinet FortiWeb-1000C -Top 2 Categories: Reliability/Durability, Ease Of Integration
• SonicWALL Content Filtering Service (CFS) - Top 2 Categories: Ease Of Integration, Ease Of Upgrade

Fortinet had a pair of products that were finalists for SC Magazine (US) Reader Trust Awards 2011. These were for Best Enterprise Firewall and for Best Integrated Security UTM.

Other categories in the survey were: Data Collection, ECM, General Computing, Managed Services & Networking, Networking, Physical Security (Access Control & Video Surveillance), Point of Sale & Payment Processing, Storage, and Unified Communications & VoIP.

Methodology for Business Solutions Magazine Best Channel Products 2011


Business Solutions Magazine partnered with Penn State University to conduct the survey. During the web survey, they collected 11,711 votes from 1,490 discrete reseller subscribers. Questions in the survey were:

• Richness of Features/Functionality: Does the product meet your customers' functionality needs? Is it easily configurable? Is it easily customizable (i.e. scalable and flexible)?
• Product Reliability/Durability: Does the product meet your quality needs? Do you frequently need to fix the product? Is it durable enough to withstand regular usage?
• Ease of Integration: Is it easily integrated with other products — new or existing?
• Ease of Upgrade: Is it easily upgradeable to meet your customers' needs and technology changes?
• VAR's Ability to Service: Is the product easy for you to service?

For more details on the methodology http://www.bsminfo.com/article.mvc/Best-Channel-Products-2011-Survey-Methodology-0001

For the complete article on Business Solutions Magazine Best Channel Products 2011 http://bsminfo.com/article.mvc/Best-Channel-Products-Page-2011-0001#Index

Thursday, August 18, 2011

Best Internet Security Suites 2012 - Best 2012 Security Suites - PC Magazine

September 11 - This blog is comprehensive with respect to 2012 versions.  2013 versions have "started" to come out and be reveiwed. After reading this blog, you may want to click on the following link for to see the 2013 versions.





Internet Security vendors are now starting to release their Internet Security Suite 2012 solutions. Most of the solutions out there are still Internet Security 2011. Below are the rankings of a number of internet security suites that have been reviewed by PC Magazine. The stars are out of 5. The number in ( ) is the score received in 2011.


Best Internet Security Suites 2012 - Best 2012 Security Suites

4.5 - Webroot SecureAnywhere Complete
4.5 - Norton Internet Security 2012
4.0 – BitDefender Internet Security Suite 2012 (3.5)
4.0 – Zone Alarm Extreme Security 2012
3.5 - Trend Micro Titanium Security 2012
3.5 – Kaspersky Internet Security Suite 2012 (4.0)
3.0 – G Data Internet Security 2012 (3.0)
3.0 - AVG Internet Security 2012 (2.5)
2.5 – Panda Global Protection 2012
2.5 – TrustPort Internet Security Suite 2012 (2.5)
2.5 - ESET Smart Security 5
2.5 - Bullgaurd Internet Secrity 12
2.0 – Outpost Security Suite Pro 7.5(2.5)

For the PC Magazine Reviews

To see the reviews by PC Magazine's Neil Rubenking go to http://www.pcmag.com/article2/0,2817,2373529,00.asp

PC Magazine reviews each of the products in the table in detail. People looking for a solution should look at these individual reviews. They contain detailed (and extremely knowledgeable) qualitative data about the products as well as results of malware tests that were done by PC Magazine. Most internet security firms seem to have a basic antivirus package, an internet security suite, and then one or more ultra internet security suites. The range of additional features varies. It’s like, “But wait, there’s more.” Everything but a ginzu knife. The variety of features will be the subject of another blog.

PC Magazine and AV-Comparatives.org Combined

The table below combines several results from AV-comparatives.org as well as PC Magazine. The second column is the ranking for detection rate from the AV-Comparatives On Demand Detection of Malicious Software report – September 2011

http://www.av-comparatives.org/images/stories/test/ondret/avc_od_aug2011.pdf. The third column is the same but for the April report. The fourth column is for AV-Comparatives Whole Product Real World Dynamic Test in August. The last column is the score for PC Magazine’s Internet Security 2012 reviews.

What Does the Table below Mean?

With respect to on Demand Detection, with the exception of McAfee; there was a consistency of performance among the top five vendors. There seems to be little relationship between the Whole Product Real World Dynamic test and the On Demand Detection tests. PC Magazine’s ratings don’t correlate with any of the three tests. However, PC Magazine’s scores are for much more than detection of malware. They are for a total product review.

.



























To see a ranking of the Best Internet Security Suites 2011, go to http://kensek.blogspot.com/2011/04/best-internet-security-suites-2011-pc.html

To see an evolving compilation of Best Antivirus 2012 reviews, go to http://kensek.blogspot.com/2011/08/best-antivirus-software-2012-pc.html


Other Sites to Look at For Product Tests

• www.av-test.org
• www.av-comparatives.org
• www.virusbtn.org

Pay attention to the exact product tested and the version number. This is a particularly dynamic document and will be updated as other internet security suites are released, as the test groups above perform more tests, and as other publications do reviews.

Get ready for the press releases.

AV-Comparatives is an Austrian Non-Profit-Organization, which provides independent Anti-Virus software tests free to the public. www.av-comparatives.org Go to their website for complete details about the organization and the many tests they perform.

Tuesday, August 16, 2011

Oct. Update - Bullguard Internet Security 12 – Beta

Bullguard has now been released. To see where it ranks among the other Internet Security suites in PC Magazine:

http://kensek.blogspot.com/2011/08/best-antivirus-software-2012-pc.html

To go to the PC Magazine review:

http://www.pcmag.com/article2/0,2817,2394166,00.asp#

Bullguard currently has Bullguard Internet Security 12 in beta. Features being promoted within Bullguard Internet Security Suite 12 (they’re skipping 11) during beta testing include:

• Parental Control
• PC Tune up
• Improved Behavioral Detection
• Improved Firewall
• Improved Spamfilter
• Improved General Performance
• New and improved UI

You can obtain more information and register as a beta customer at http://www.bullguard.com/beta/Signup.aspx?c=IS12

How Has Bullguard Internet Security 10 Performed?


• Bullguard is 9 and 2 in the last 11 Virus Bulletin tests they’ve entered since 2007 http://www.virusbtn.com/vb100/archive/vendor?id=48
• Bullguard Internet Security Suite 10 received certification Q2 2011 certification on Windows XP from AV-test.org http://www.av-test.org/certifications
• Bullguard Internet Security Suite 10 received 2.5 stars (ouch) in an October review by PC Magazine’s Neil Rubenking http://www.pcmag.com/article2/0,2817,2372100,00.asp Two other products received this score
• They were one of the top performers in the Virus Bulletin VB RAP tests, December 2010 through June 2011with the top score in proactive detection http://www.virusbtn.com/vb100/rap-index.xml
• Bullguard was not part of av-comparative.org’s testing

Some Other Products Also in Beta

• Kaspersky currently has Kaspersky Internet Security 2012 in beta at http://support.kaspersky.com/kis2011/all?more=1&qid=208284251
• Webroot has Webroot Cloud Antivirus in beta at http://www.webroot.com/customerSupport/betaRegistration.php
• F-Secure currently has F-Secure Internet Security 2012 in beta at http://www.f-secure.com/en_EMEA-Labs/beta-programs/home-users-beta/IS2012beta/
• Trend Micro Maximum Security 2012 and others at https://www.trendbeta.com/pages/main
• Norton Internet Security 2012 and Anti-Virus 2012 beta http://us.norton.com/beta/index.jsp
• BitDefender Total Security 2012 http://beta2012.bitdefender.com

Panda Global Protection 2012

In brief, PC Magazine’s Neil Rubenking was disappointed with Panda Global Protection 2012. It received 2.5 stars out of 5. According to Rubenking: (a) in malware removal, malware blocking, antiphishing, and antispam tests it scored lower than the 2011 edition. Its backup and cleanup modules don't come close to the top competition. (b) a number of its nominal components are actually available for free without purchase of the suite. (c) the 2012 suite impacts system performance more than its predecessor. For the comprehensive review: http://www.pcmag.com/article2/0,2817,2386220,00.asp

Sunday, August 14, 2011

AV-Test Product Review and Certification Report – Q2 2011

During the 2nd quarter of 2011, AV-Test (www.AV-Test.org ) tested 22 internet security products in the areas protection, repair and usability. The highest score possible in each category was 6.0. The test was on Windows XP. Six company’s products failed the test by failing to achieve a score of 11 or greater. The companies with the top 4 scores and the avg score of the three categories are below:

AV-Test Top Performers Q2 2011


• 5.7 - F-Secure
• 5.7 - BitDefender
• 5.3 - Kaspersky
• 5.2 - Panda
• 4.5 - Symantec
• 4.5 - Sophos
• 4.5 - G Data
• 4.5 - Avast

For more details on the test, scores for all 22 companies, names of the product tested and a detailed one-page report for each product tested, go to http://www.av-test.org/certifications

Comodo did not perform well in this test. They did not receive an AV-test certificate. They topped a CNET poll for top free antivirus solution in March. http://kensek.blogspot.com/2011/03/comodo-internet-security-suite-tops.html

For a table showing AV-Test.org’s results for Q1 on Windows Vista combined with AV-Comparatives.org Whole Product Dynamic Test, go to http://kensek.blogspot.com/2011/07/av-comparativesorg-whole-product.html

About AV-Test (www.av-test.org)


AV-Test GmbH is an independent supplier of services in the fields of IT Security and Anti-Virus Research, focusing on the detection and analysis of the latest malicious software and its use in comprehensive comparative testing of security products. To learn more about them, go to http://www.av-test.org/about

Saturday, August 13, 2011

Internet Security Tag Line Quiz, For When You Can’t Sleep

For a brief respite from evaluating internet security suites, worrying about malware, reading antivirus reviews, reading best internet security round-ups, or generating security reports, test your corporate internet security tag line skills. Match the company name in the first column with the internet security product’s or corporate tagline in the second column. This puzzle qualifies as IPO. That, is, It’s Partially Original.

Internet security providers in the quiz – Avast, TrustPort, Avira, F-Secure, Avg Technologies, G Data, Panda, Ad-Aware, Trend Micro, Astaro, McAfee, Kaspersky, Symantec, and Webroot.






















No guarantees that success in this will make you the center of attention in any sort of gathering. The answers are below.

Dude, take the quiz first. Move your eyes back up the screen.

• Webroot Lets get you protected
• TrustPort Keep IT secure
• Trend Micro Securing your journey to the cloud
• Symantec Confidence in a connected world
• Panda Protection for your family
• McAfee Securing your digital world
• Kaspersky Premium protection against viruses, spyware, hackers and spam for home & small office
• G Data Award winning internet security solution
• F-Secure Keep viruses, identity thieves and hackers away
• BitDefender Enhanced Silent Security
• Avira Live free All around protection for you and your family
• AVG Technologies Ultimate protection for everything you do online
• Avast Maximum protection
• Astaro Connect with confidence
• Ad-Aware Total security-total piece of mind




Wednesday, August 10, 2011

Pwnie Awards Announced During Black Hat USA 2011

The Pwnie Awards is an annual awards ceremony celebrating the achievements and failures of security researchers and the security community. This year’s awards were given out August 3, concurrent with the Black Hat USA 2011 conference. Some of these are positive. Some of the incidents were a major “Maalox moment” for the winners. Kind of like the Razzies, that salute the worst of Hollywood each year.

The Pwnie Winners

• Pwnie for Best Server-Side Bug - ASP.NET Framework Padding Oracle (CVE-2010-3332) - : Juliano Rizzo, Thai Duong
• Pwnie for Best Client-Side Bug - FreeType vulnerability in iOS (CVE-2011-0226) - : Comex
• Pwnie for Best Privilege Escalation Bug - Windows kernel win32k user-mode callback vulnerabilities (MS11-034) -Tarjei Mandt
• Pwnie for Most Innovative Research - Piotr Bania
• Pwnie for Lifetime Achievement -pipacs/PaX Team
• Lamest Vendor Response - RSA SecurID token compromise
• Pwnie for Most Epic FAIL - Sony
• Pwnie for Epic 0wnage - Stuxnet

For more details on the awards, go to http://pwnies.com/winners/ Worth checking out.

Another interesting read - "Top 10 Security SNAFUs of 2010" at http://kensek.blogspot.com/2011/01/top-10-security-snafus-of-2010_25.html

Tuesday, August 09, 2011

AV-comparatives.org Whole Product Dynamic Test – June through July 2011

A bit of a switch in the top five products in the AV-Comparatives.org and their Whole Product Dynamic "Real World" Test, June through July, versus the January through June test. These results were out of the box capture rates.

1. 99.3 - F-Secure
2. 99.3 - Panda
3. 98.8 - Trend Micro
4. 98.3 - BitDefender
5. 98.1 - G Data

Symantec/Norton dropped to seventh, blocking 98.1%, out of the top five. The top six for the January through June time period were BitDefender, F-Secure, Symantec, G Data, Panda, and Kaspersky.

To see a table of the AV-Comparatives.org Whole Product Dynamic Test and AV-Test.org Certification Test Combined, go to http://kensek.blogspot.com/2011/07/av-comparativesorg-whole-product.html


Go to http://www.av-comparatives.org/en/comparativesreviews/dynamic-tests to play with the interactive table. You can also modify the time period and view results.

About AV-comparatives.org - www.av-comparatives.org

AV-Comparatives is an Austrian Non-Profit-Organization, which is providing independent Anti-Virus software tests free to the public.

Sunday, August 07, 2011

Inside the Exhibitors Ballroom at Black Hat USA 2011

Day One at Black Hat USA 2011

80 plus vendors, waiting for seminars to end, so that the Black Hat attendees will come through Exhibitors Ballroom at Caesars Palace in Las Vegas. The first day ran almost 12 hours (including the drinks/appetizers for the last couple of hours on day one).

The doors open. The rush begins. For knowledge? Well, almost. For the prime tchotchkes, primarily tee shirts. McAfee was also doing a book signing on Day One. That, a motorcycle and tradeshow women in biker garb and phishnet stockings… Strike that, fishnet stockings, helped create traffic around their booth.

A zombie wandering the floor caught people’s attention. As did a booth having a drawing for a chain saw. A real chain Stihl® saw. Courtesy of Solera Networks. Interestingly enough, they weren’t the company sponsoring the zombie walking around. Explain the chainsaw to security at McCarran International! “Sir, you’ll have to check that.”

Breaks in the morning and afternoon. Security catching someone who put a piece of yellow paper into an official pass holder hoping that security wouldn’t notice that there was nothing on it. One of the top sellers at the Black Hat store – lock picking kits.

Lines for food and drinks at 5:30. Pasta, pizza, and more…. Later, Crystal Meth at one of the Wednesday evening functions. Absolut Vodka as a sponsor for one event. People moaning about having to get up at 5:30 in the morning to try and buy a Defcon pass being held at another casino immediately following the end of Black Hat.

The booths aren’t set up for sit down presentations, so vendors are able to have one on one discussions with individuals coming through, demoing SW, etc.

Day Two

Quite a few bleary eyes when the Exhibition Ballroom doors open. Quiet compared to the day before. In one corner of the Ballroom, people working with soldering irons to make their own robots. Some traffic around the Symantec booth for the energy boost/caffeine gum. Line for popcorn at one booth.

Many people walking around with their heads bent downward. Checking their mobiles? Nope, looking at the card they were carrying to see which booths they had to go to get stamped and be eligible for drawings.

One o’clock hits – another line forms. Qing Li autographing copies of “IPv6 Advanced Protocols Implementation” at the Blue Coat booth. 300 signatures later, they’re gone. More than a few handfuls of people wearing a black tee from a vendor. If they’re seen by that vendor walking around, they become eligible for drawings.

People seemed to be generally pleased with the talks, keynotes and the education tracks. There was a blend of highly technical to not so technical. The mix appears to change slightly from year to year. One person wasn’t pleased that one presentation began with the presenter explaining what a virtual appliance was.

As the end of the day approaches, and before the make your own sundae break (yes, more food), the exchanging of the tchotchkes begins, when competitors briefly become friends, long enough to trade for t shirts, in situations where there are extras.

4:45 hits, attendees are ushered out, and the sponsors begin teardown. Until next year….

Sunday, July 31, 2011

Unlimited Online Storage Defined – Black Hat USA 2011

Unlimited Online Storage Defined

The pitch - *UNLIMITED storage. The asterisk - *Subject to fair use policy. The details - "In the event you chose an unlimited storage option for the bbb Paid Services, your usage of the Services if in excess of 500GB may at bbb’s sole discretion be subject to additional usage fees, as referenced in f) above and in this paragraph". Unlimited, and fair use, appears to be 500GB. As a reference point, 500GB is the hard drive size of a number of laptops. Online storage service providers such as Box.net, dropbox, carbonite, livkive, mozy, and sugarsync must be pleased that that has been cleared up. Note, each vendor has their own plans with various storage amounts. Next week – infinite and pi brought to closure.

Black Hat USA 2011


The Black Hat conference runs in Las Vegas August 1 through 4 at Caesars Palace. Potential blogs may be published during the event. Over 5000 attendees will hear a number of speakers. There are nine training tracks. Over 80 vendors will be part of the tradeshow. Sponsors include internet security providers Norman, Symantec, McAfee, and GFI. Qualys is the diamond sponsor. https://www.blackhat.com/html/bh-us-11/bh-us-11-sponsors.html There may be some IPO (initial public offering) candidates in there.

About Black Hat


The Black Hat Briefings remains the biggest and the most important technical security conference series in the world by remaining true to our core value: serving the information security community by delivering timely, actionable security information in a friendly, vendor-neutral environment.
https://www.blackhat.com/html/bh-us-11/bh-us-11-home.html

Pwnie Awards


The Pwnie Awards is an annual awards ceremony celebrating the achievements and failures of security researchers and the security community. The awards are given out once a year. The fifth annual ceremony will take place on August 3rd, during Black Hat USA. http://pwnies.com/about/

Thursday, July 28, 2011

Sophos Endpoint Security and Control 10 – Sophos Beta

Sophos currently has their Sophos Endpoint Security and Control 10 offering in beta. Improvements in the product they’re promoting include:

Sophos Endpoint Security Endpoint and Control


• New technologies that will improve scanning performance and web-based malware detection rates. Provide the ability to filter inappropriate websites whether your users are on or off your network
• Boost performance, which results in faster boot-up scanning and improved malware detection accuracy
• Enhance web-based malware protection with browser independent scanning
• Identify computers missing patches for vulnerabilities being exploited by the latest threats

How Has Sophos Been Performing in Tests


They are 9/10 in the last Virus Bulletin VB100 Awards tests they have been participating g in http://www.virusbtn.com/vb100/archive/vendor?id=1

Scored just below 90% in Reactive Detection and about 80% for Proactive Detection in Virus Bulletin’s December 2010 – June 2011 RAP Test http://www.virusbtn.com/vb100/rap-index.xml

Was certified in Q1 2011 on Windows 7 by AV-test.org http://www.av-test.org/certifications

Received an Advanced Rating (2 stars) in AV-comparatives.org On-demand Detection of Malicious Software in February http://www.av-comparatives.org/images/stories/test/ondret/avc_od_feb2011.pdf . This was out of 3 stars. They were not at the top among the two star recipients.

For more information or to download the beta, go to http://www.sophos.com/en-us/products/beta.aspx

Sophos is a B2B focused company, though they do offer a free download for Mac products. They’ve invested internally in “the cloud” offering solutions for live antivirus, URL filtering, and spam filtering technologies.

Early in July, Sophos completed their acquisition of Astaro, which has allowed them to broaden their internet security portfolio and buy some market share. http://www.sophos.com/en-us/press-office/press-releases/2011/07/sophos-broadens-security-portfolio-with-completion-of-astaro-acquisition.aspx

Sophos had sold a majority stake of the company to Apax Partners for $830 million last year http://kensek.blogspot.com/2010/12/2010-year-of-security-acquisitions.html Funds like this can help finance a lot of purchases. If you’re not going IPO (initial public offering), this is another way to get cash.

The usual suspects, McAfee, Panda, Avast, Avira, AVG Technologies, G Data, among others, will be announcing their betas over the coming months

Also in Beta (Consumer Products)


• Webroot has Webroot Cloud Antivirus in beta at http://www.webroot.com/customerSupport/betaRegistration.php
• F-Secure currently has F-Secure Internet Security 2012 in beta at http://www.f-secure.com/en_EMEA-Labs/beta-programs/home-users-beta/IS2012beta/
• Trend Micro Maximum Security 2012 and others at https://www.trendbeta.com/pages/main
• Norton Internet Security 2012 and Anti-Virus 2012 beta http://us.norton.com/beta/index.jsp
• BitDefender Total Security 2012 http://beta2012.bitdefender.com

Sunday, July 24, 2011

Security Executive(s) Say Every Security Company is Misleading Consumers about Protection Offered, (Seven Years Apart)

In a July 15 ITPro article, M86 Chief Executive Officer John Vigouroux stated that every other security company bar his is misleading consumers about the malware protection they offer. "The security industry has done a miserable job of defending the world against malware," Vigouroux said, claiming the best legacy systems are only stopping 40 per cent of threats. http://www.itpro.co.uk/634951/is-the-security-industry-lying-about-malware-protection

Vigouroux did not discuss in any detail the wide variety of techniques beyond pattern files being by security providers to identify and stop malware and other threats, other than for M86. Technologies beyond pattern files include heuristic analysis, sandboxing, and pushing defense to the cloud, not waiting to stop malware before it reaches the desktop. M86’s product line utilizes a variety of technologies, including URL filtering, and standard malware signatures. Vigouroux is quite vigorous in denigrating pattern files, nonetheless. M86’s “parts” through acquisition/merger are, Marshal, Avinti, 8e6, and Finjan. M86 positions themselves as delivering “Today’s Technology for Tomorrow’s Threats”.

Nonetheless, there is some truth in what Vigouroux is talking about. In Av-Comparatives.org May 2011 “Retrospective Test, Static Detection of new/unknown malicious software”, the top four results were from:

• 61% - G Data
• 59% - Eset
• 59% - Avira
• 55% - Kaspersky

This particular test evaluated only the offline heurist/generic detection of the company’s products against unknown and known malware. www.AV-comparatives.org , www.AV-test.org , www.virusbtn.org, www.icsalabs.com, and www.westcoastlabs.com are great sites to go to for information on products tests.

http://www.av-comparatives.org/images/stories/test/ondret/avc_retro_may2011.pdf

Revisiting Trend Micro, March 22, 2004 – Déjà vu, All over Again

Trend Micro Executive Eva Chen had a Q&A with CRN (www.crn.com) in March 2004. Chen stated in response to a question about security management, “The other thing we are thinking about is outbreak prevention. We always say we are in the antivirus business. But I was so frustrated that I called our CEO, Steve Chang, and said we've been lying to our customers for 10 years. We call ourselves antivirus, but we have never prevented a virus from hitting our customers. None of the antivirus vendors have ever done that. From that day, we started to rethink the whole business about antivirus.” http://www.crn.com/news/channel-programs/18841262/crn-interview-eva-chen-trend-micro.htm since 2004 has probably been one of the leaders in moving protection out to the cloud. Quite a migration from their pre 2000 positioning as “Your Internet Viruswall”.

Eva Chen gets bonus points for being prescient and raising the pattern file issue in the press seven years before Vigouroux. Obviously, the industry has evolved. Viruses and malware are just a small part of the threats. Larger companies may also find themselves targeted by Advanced Persistent Threats (APTs). Both companies (and numerous others) have pushed the battle out to the cloud in addition to providing other technologies to provide a multi layer solution. A number of vendors are also offering security as a service, though the acronym SecaaS has not quite caught on, yet.

Trend Micro positions themselves as “Securing Your Journey to the Cloud”. From a traditional AV/Malware security provider perspective, they are in 3rd after Symantec and Intel subsidiary McAfee. Kaspersky is going after them for the 3rd position.

Virtualization as an Option

This is a topic for another blog. However, virtual desktops are being utilized by some larger organizations. MokaFive (www.mokafive.com), for example, promotes providing seven layers of security for their virtual desktops. These layers are:

• Built-in anti-virus scanning (AVG Technologies)
• Virtual desktop encapsulation to keep the virtual desktop completely independent of the host computer.
• AES 256 encryption to keep data secure
• Tamper resistance and copy protection to keep the virtual desktop from being moved or edited.
• AD and two-factor RSA SecurID authentication to allow access to only authorized users.
• Granular security policies
• Remote revoke or kill

Friday, July 22, 2011

The End Is Near For Paid Antivirus On PCs

This was the premise of an interesting article by Mathew Schwarz in an Information Week article on June 23. http://www.informationweek.com/news/security/antivirus/231000191 . Eric Domage, manager of western European security research and consulting for IDC, stated, “This is a highly commoditized sector. It used to be a market, but now it's a commodity--look at what Microsoft is now doing for free."

The freemium market has worked for several vendors. Microsoft created a bit of a disruptive event when they unleashed their free Microsoft Security Essentials. Excluding trial basis programs, www.download.com has approximately 60 free antivirus downloads on their site.

Some of this may be a definition issue. Antivirus is only a small portion of “malware”. The masses use the phrases interchangeably. Antivirus vendors hope that people will migrate up to a paid antivirus product or an internet security suite.

At the same time, traditional viruses are not the problem. Most major security vendors have written though leader ship whitepapers on internet threats. They detail the most current threats and how the battle has moved out to the cloud and there is more danger from getting infected while surfing the internet.

The larger vendors, on the business side of the fence, promote a multi-layered approach that begins with the cloud and often ends at the desktop. Or increasingly, they utilize a cloud solution for their desktops, road warriors, and mobile devices.

"McAfee and Symantec have decided to escape this market," said Domage in the article. CA decided to sell much of its security portfolio to UpData partners in June http://www.crn.com/news/security/229500801/ca-to-sell-antivirus-business.htm

A new market for these vendors is mobile devices using Symbian (shrinking) and Android operating systems. This includes tablets as well as smart phones. Some of the security vendors have a free product. Others have incorporated it into other technology security solutions. Those offering a free product often market a premium version. Trend Micro, Kaspersky, AVG Technologies, F-Secure, and McAfee, for example, all offer some kind of mobile security solution. some of them free.

In the denouement, while the end may be near for paid antivirus on the desktop, threats still exist. The battlefield has moved more extensively out to the internet. Protection is still essential. It costs companies to develop solutions. They need to continue to invest and these investments have to be recouped.

Below is a non-comprehensive set of links to some vendors providing security solutions for mobile devices.

http://www.f-secure.com/en_US/products/mobile/, http://usa.kaspersky.com/products-services/home-computer-security/mobile-security, http://us.trendmicro.com/us/products/personal/mobile-security-for-android/, http://home.mcafee.com/Store/ , http://www.avg.com/us-en/antivirus-for-android

Monday, July 18, 2011

August 8 Addendum - Where Have All the Free Antivirus Downloads Gone

August 8 – Note the comments at the end of the blog. This probably explains what is happening.















July 22 - The one week change in downloads was not not kind to any of the below vendors. Not a lot can be read into one week. Could mean vacations. Could mean that there were no major outbreaks that would cause people to download a copy, either on a first time basis, or to use because their existing product had failed. The below are in (000) for weeks ending July 15 and 22, respectively.














For the past several years, AVG Technologies has led the download battle on CNET, with weekly downloads on www.download.com on the order of 1.2 to 2.0 million. Avast has typically been second, a few hundred thousand behind AVG Technologies with Avira a poor 3rd. The sum of the latter two has typically been greater than AVG’s. Avast has blogged that the sum of a handful of downloads on other sites has given them a larger installed base. However, each firm defines what constitutes an active account differently.

For the week ending 7/16 AVG has gone below a million on www.download.com. Avast has dropped "way" below a million and now ranks 4th on the www.download.com site.

• AVG – 986k
• Avira – 261k
• Ad-Aware – 238k
• Avast – 173k
• Comodo – 89k

The above could represent (a) a major changing of the guard in “free” (b) potentially a slowdown in downloads (c) slower churn among the major vendors (d) Microsoft’s free product cannibalizing everyone (e) glitches at www.download.com

The marketing people at Avast, in particular have to be saying “Dám si jedno pivo prosím”, and not in a happy way, with the decrease in downloads. The gap in downloads between them and AVG Technologies has increased to over 800k. Ouch.

It’ll be interesting to see what Opswat’s September market share figures will show. From “June 2011 OPSWAT Report on Worldwide Antivirus Application Market Share” http://kensek.blogspot.com/2011/03/march-2011-opswat-report-on-worldwide.html


Worldwide Market Share Leaders – Product


• Microsoft Security Essentials – 10.66% (was 3rd in March report)
• Avira Antivir Personal – 10.18% (was 2nd in March report)
• Avast Free Antivirus – 8.66% (was 1st in March report)

About OPSWAT – www.opswat.com

Founded in 2002, OPSWAT is the industry leader in software management SDKs, interoperability certification and multiple engine scanning solutions. With both manageability and multi-scanning products, OPSWAT offers simplified and comprehensive SDKs that reduce time and costs for your engineering and testing teams

Where Have All the Free Anti-Virus Downloads Gone?

For the past several years, AVG Technologies has led the download battle on CNET, with weekly downloads on the order of 1.2 to 2.0 million. Avast has typically been second, a few hundred thousand behind AVG Technologies and Avira a poor 3rd. However, the sum of the latter two has typically been greater than AVG’s. Avast has blogged that the sum of a handful of downloads on other sites has given them more downloads than AVG.

For the week ending 7/16 AVG has gone below a million on www.download.com.

• AVG – 986k
• Avira – 261k
• Ad-Aware – 238k
• Avast – 173k
• Comodo – 89k

The above could represent (a) a major changing of the guard in “free” (b) potentially a slowdown in downloads (c) slower churn among the major vendors (d) Microsoft’s free product cannibalizing everyone (e) glitches at www.download.com (f) major slowdown overall

The marketing people at Avast, in particular have to be saying “Dám si jedno pivo prosím”, and not in a happy way, with the decrease in downloads. The gap in weekly downloads between them and AVG Technologies has increased to over 800k. Ouch.

It’ll be interesting to see what Opswat’s September market share figures will show. From “June 2011 OPSWAT Report on Worldwide Antivirus Application Market Share”

Worldwide Market Share Leaders – Product


• Microsoft Security Essentials – 10.66% (was 3rd in March report)
• Avira Antivir Personal – 10.18% (was 2nd in March report)
• Avast Free Antivirus – 8.66% (was 1st in March report)


About OPSWAT

Founded in 2002, OPSWAT provides soft¬ware engineers and IT professionals with development tools and data services to power manageability and security solutions. www.opswat.com

Tuesday, July 12, 2011

Kaspersky Internet Security 2012 – Kaspersky Beta

Kaspersky currently has Kaspersky Internet Security 2012 in beta. You can learn more about the product and register to download at http://support.kaspersky.com/kis2011/all?more=1&qid=208284251

Features Being Promoted in Kaspersky Internet Security 2012

• File security detection. A function to define the file security before starting work with it has been added
• Technologies of rootkit detection (rootkit is a program designed to hide the fact of system infection) has been improved
• Protection against unknown threats has been improved with the help of System Watcher
• Protection against phishing has been improved: information about the availability of a particular resource is first checked in the local database of phishing websites stored on Kaspersky Lab servers. Next, a request is sent to the “cloud” (Kaspersky Security Network). If there is no information in the two sources, heuristic analysis is carried out
• The URL Advisor module has been enhanced.
• The application’s efficiency has been improved and its impact on the computer’s performance has been reduced
• The impact of the application on the system performance has been optimized for the most common online user scenarios: watching movies (including high-resolution (HDTV)), listening to the radio, searching and browsing websites, making calls via VoIP (Skype and etc.), online games and etc
• Touch-screen support added
• The interface of Kaspersky Internet Security 2012 has been considerably re-designed

The list above is not comprehensive.

Good article about how Kaspersky has been growing over the past year and is rapidly closing in on Trend Micro to become the number 3 “800 pound” gorilla. “Kaspersky Signs Monster Enterprise Deal”. View Larry Walsh’s Channelnomics blog about this on http://channelnomics.com/2011/06/02/kaspersky-signs-monster-enterprise-deal/

Makes for a good read while sitting in cafes in Prague, Amsterdam, and Silicon Valley.

How Was Kaspersky Internet Security 2011 Viewed?

PC Magazine gave Kaspersky Internet Security 2011 4.0 stars http://kensek.blogspot.com/2011/04/best-internet-security-suites-2011-pc.html
Seth Rosenblatt and CNET’s readers gave the product 4.5 stars http://download.cnet.com/Kaspersky-Internet-Security/3000-18510_4-10012072.html?tag=mncol;6
VB100 Awards – 7 out of 8 since December 2009 http://www.virusbtn.com/vb100/archive/vendor?id=74
www.av-test.org Certified on Windows 7 in Q1 http://www.av-test.org/certifications.php
www.av-comparatives.org The antivirus product was one of only two to receive 3 stars (highest rating) in the May Retrospective Test http://www.av-comparatives.org/images/stories/test/ondret/avc_retro_may2011.pdf

The usual suspects, McAfee, Panda, Avast, Avira, AVG Technologies, G Data, among others, will be announcing their betas over the coming months

Also in Beta

• Webroot has Webroot Cloud Antivirus in beta at http://www.webroot.com/customerSupport/betaRegistration.php
• F-Secure currently has F-Secure Internet Security 2012 in beta at http://www.f-secure.com/en_EMEA-Labs/beta-programs/home-users-beta/IS2012beta/
• Trend Micro Maximum Security 2012 and others at https://www.trendbeta.com/pages/main
• Norton Internet Security 2012 and Anti-Virus 2012 beta http://us.norton.com/beta/index.jsp
• BitDefender Total Security 2012 http://beta2012.bitdefender.com

Webroot Cloud Antivirus 2012 – Webroot SecureAnywhere Antivirus Released – Their Beta Agreement

October 4 addendum - Webroot has finally come out with 2012 product. Webroot SecureAnywhere Antivirus received 4.5 stars in its recent PC Magazine review. It tied for Editors' Choice with Norton Antivirus 2012 from PC Magazine's Neil Rubenking. The review was posted October 4. Go to the following link for the review:

http://www.pcmag.com/article2/0,2817,2393678,00.asp

Go to the link below for PC Magazine's rankings of the Antivirus 2012 products reviewed to date.

http://kensek.blogspot.com/2011/08/best-antivirus-software-2012-pc.html

Original Post

Webroot currently has Webroot Cloud Antivirus in beta. You can learn more about the product and register to download at http://www.webroot.com/customerSupport/betaRegistration.php


Webroot is playing it close to the vest about the product. Below are their “we’re no fun” paragraphs in the licensing agreement.


The Beta Software and all information provided by Webroot about the Beta Software is confidential information of Webroot ("Confidential Information"). You will not disclose Confidential Information to any third party or use Confidential Information for any purpose other than as expressly permitted in this Agreement. You agree that You will treat all Confidential Information with the same degree of care as You accord to Your own confidential information, which in no event will be less than reasonable care.


You will not disclose the existence of this Agreement, the existence, features, or capabilities of the Beta Software, or any of the activities pursued hereunder, without Webroot's prior written consent.


What was it Shakespeare wrote about lawyers?

The usual suspects, McAfee, Avast, Avira, G Data, among others, will be announcing their betas over the coming months.

Also in Beta

• F-Secure currently has F-Secure Internet Security 2012 in beta at http://www.f-secure.com/en_EMEA-Labs/beta-programs/home-users-beta/IS2012beta/
• Trend Micro Maximum Security 2012 and others at https://www.trendbeta.com/pages/main
• Norton Internet Security 2012 and Anti-Virus 2012 beta http://us.norton.com/beta/index.jsp
• BitDefender Total Security 2012 http://beta2012.bitdefender.com

Addendum, July 21 - AV-Comparatives Whole Product Real World Dynamic Test

Webroot may need to look at their scanning engine following the results of AV-Comparatives Whole Product Real World Dynamic Test, March through June. Webroot's product rated "tested" http://www.av-comparatives.org/images/stories/test/dyn/wpdt2011_1_en.pdf

To see how PC Magazine has ranked some of the latest releases of best Internet Security 2012 suites, go to http://kensek.blogspot.com/2011/08/best-internet-security-suites-2012-pc.html . To see ratings of 20 best Internet Security 2011 suites, go to http://kensek.blogspot.com/2011/04/best-internet-security-suites-2011-pc.html

Thursday, July 07, 2011

AMTSO Guidelines on Facilitating Testability

There is another brief publication out by the Anti-Malware Testing Standards Organization (AMTSO) for those who may do deep dive or even casual testing of internet security products. “AMTSO Guidelines on Facilitating Testability” This document covers ways in which “testers and vendors can collaborate and share information in order to make testing more efficient and accurate, and to enable external verification of results.” It is only six pages long but is a good read. It was published in late May. www.amtso.org

AMTSO (as I’ve previously written) has a number of useful documents for those who perform testing for companies, the “reviewers” of the world, and people who may want to be able to look at product tests and reviews at a deeper level than the casual reader. The list of titles is at http://www.amtso.org/documents.html and they’re free! These will make you much smarter than a fifth grader! No guarantees in how mentioning these documents will be useful to help meet people in clubs or cafes across North America and Europe.

If you can read only one document, I suggest “The Fundamental Principals of Testing”. It is a five-page read and will provide some points to look at tests with a more discerning eye (as well as design your own tests and reviews). Sometimes the wisdom of experts is better than the wisdom of crowds, even if the experts don’t have 300k or 500k Facebook fans. Read some of AMTSO’s documents before this season’s Internet Security 2012 reviews come out. Click here to “like”. Then send to all your friends. ;) . Check out the member organizations when you visit their site.

About AMTSO

The Anti-Malware Testing Standards Organization, or AMTSO, is dedicated to helping improve the objectivity, quality and relevance of anti-malware technology testing. AMTSO membership is open to industry-wide academics, reviewers, testers and vendors, subject to guidelines determined by AMTSO. www.amtso.org

Wednesday, July 06, 2011

AV-Comparatives.org Whole Product Dynamic Test – AV-Test.org Certification Test Combined

The table below combines the top 10 products from AV-Test.org and their Q1 certification test on Windows 7 with AV-Comparatives.org and their Whole Product Dynamic Test (January through June). The top 10 products making the cut were BitDefender Internet Security Suite 2011, F-Secure Internet Security 2011, Norton Internet Security 2011, G Data Internet Security 2011, Panda Internet Security 2011, Kaspersky Internet Security, AVG Internet Security 2011, Sophos Endpoint Security and Control 9.5, and Trend Micro Titanium Internet Security 2011, and Eset Smart Security 4.2.

For AV-Test.org (22 products), scores in Protection, Repair, and Usability were averaged together. The top score achievable for each category was 6.0. The product also had to be certified. For AV-Comparatives.org (17 products), the percent of malware blocked during the January through May timeframe was used.

av-test.org and av-comparatives.org Combined Test Results













About the Results

You probably will never see this table on either web site. It’s interesting that the same three products were in the top three in each test. Kudos to them. If this were a top 12 table, Avast and Avira would have made the cut. Five products failed to achieve certification by AV-test.org.

Go to www.av-test.org to see the 1-page reports for each product and to view the individual scores for Protection, Repair and Usability. The table is sortable.

Go to http://www.av-comparatives.org/en/comparativesreviews/dynamic-tests to play with the interactive table. You can also modify the time period and view results.