The WannaCry ransomware has been a major news story over the last few days. It has infected hundreds of thousands of computers worldwide (mostly in Russia), including some well-known companies and institutions. All the programs in our public Main Test Series now detect the WannaCry malware samples by means of signatures, but we decided to find out which of these programs would have blocked the malware sample (not the exploit) proactively, i.e. before the the outbreak started and the malware samples became known.
Proactive protection against the WannaCry ransomware (not the exploit)
Introducing AV-Comparatives’ Malware Protection Test
The Malware Protection Test is an enhancement of the File Detection Test which we performed in previous years. It assesses a security program’s ability to protect a system against infection by malicious files; what is unique about this test is that in addition to checking detection in scans, it additionally assesses each program’s last line of defence. Any samples that have not been detected e.g. on-access are executed on the test system, with Internet/cloud access available, to allow features such as behavioural protection to come into play.
Sample quality for the Malware Protection Test
The test set for Malware Protection Test consisted of about 38,000 samples. As we only use samples that have been analysed by our own in-house automated sandboxes, the quality of our sets is very high. Unlike some other testers, we only use malware in our tests, and do not include PUAs or other controversial software. What is malicious and what is “potentially unwanted” is sometimes debatable. We welcome feedback from vendors; however, the decision as to whether something can or cannot be classified as malware is ultimately up to us, even if our decisions may sometimes be regarded as imperfect.
Schneier on Testing…
Certificate authorities issue SSL certificates to fraudsters
https://news.netcraft.com/archives/2015/10/12/certificate-authorities-issue-hundreds-of-deceptive-ssl-certificates-to-fraudsters.html
Safe Harbor agreement ruled invalid by top EU court
https://nakedsecurity.sophos.com/2015/10/06/safe-harbor-agreement-ruled-invalid-by-top-eu-court/
10-Year Participation Awards
At VB2015 we handed out the 10-Year Participation Awards to Avast, AVG, Avira, Bitdefender, ESET, F-Secure, Kaspersky Lab and McAfee.
Read more here (PDF).
URL Competition @VB2015
For the second time, we ran an URL competition during the Virus Bulletin conference 2015. We plan to host a URL competition every year.
Conference delegates received a code to register for the competition.
26 Malware Hunters (from 14 different companies) joined the competition and submitted in total 238 URLs during the conference. Most of the submissions were 404, PUA, exploits that did not work on the target system or clean URLs/files. Continue reading…
List of AV Vendors (Mac)
In the Mac security comparative tests/reviews, we usually include only products of vendors which applied to get their security product scrutinized and publicly evaluated.
On the page below you can find a list of 25 relatively well-known Mac security vendors.
List of AV Vendors (PC)
We get sometimes asked why we do not test all AV’s out there. There exist several hundred (several thousand worldwide, if we would count every rebranded security software or other various products providing some form of security). We usually include only about 16-20 of the most well-known AV products in our public main test-series. Some other can be found in our single product tests, several more are getting tested only internally.
On the following pages you can find a list of well-known AV vendors, just to give you an impression that there are more products out there than most of the users even known/heard about.











