Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Extracting signature snippets from AV databases |
|---|---|
| Date: | Tue, 9 May 2006 11:04:53 -0400 |
On Monday 08 May 2006 05:56 pm, Bill Stout wrote:
Hi Jose, I'm familiar with EICAR. However I'd like to trigger signatures across the board. Ultimately I'd like to run a real malware test, but that can only be done in an isolated lab, and that requires a continuous investment of time and money to insure the collection is up to date. http://www.av-test.org/ is another possibility, but I have no contacts there, and it's somewhat isolated proof (can't touch the environment, and it's a run-once deal).
That's been tried before, (R. Utilities, his name shall remain unmentioned). As was pointed out at the time, since these are not viruses (or Malware), they should not be detected as such. Any detection of 'strings' would be a false positive. Additionally, most current products do not rely on strings, rather incorporate heuristics and strings for better Positive identification and detection of minor variants. This is why it's important to rely on testing orgs like V-Tests, Virus Bulletin, ICSALabs, and West Coast Labs. They all publish free public results, and will do private testing for a fee. The EICAR and SpyCAR files should be used to validate the product is installed and properly functioning, independent peer reviewed scientific tests should be relied upon to verify product efficiency. This is a debate that goes back to the early to mid 90's, and the arguments have not changed. The only thing that has changed is the availability of "Virus Collections" on the web, but like then, what is the quality of those collections, are they really viruses, are they really the virus name the collector has promised them to be? Again a bad idea, as you have no control of quality of the zoo, nor positive identification of the samples or intendeds. Once again we come full circle to let the professional test orgs/ individuals do what they do best, and cross reference their tests, to help you be able to say with authority, that the tests are as unbiased as possible, and not influenced by vendors. -- Kenneth L. Bechtel, II Team Anti-Virus Phone - 717-579-9083 | WildList Reporter P.O. Box 635, Palmyra, PA 17078 | Founding member AVIEN E-mail - kbechtel@teamanti-virus.org | Member AVAR I can't be an impostor - I don't know what I'm doing! PGP Footprint: 969E 2A27 3042 EE52 AEFB 6FF0 2711 9467 D38C 5C0F
| Previous by Date: | Re: Extracting signature snippets from AV databases, Nick FitzGerald |
|---|---|
| Next by Date: | Re: Extracting signature snippets from AV databases, Nick FitzGerald |
| Previous by Thread: | Re: Extracting signature snippets from AV databases, Nick FitzGerald |
| Next by Thread: | RE: Extracting signature snippets from AV databases, Bill Stout |
| Indexes: | [Date] [Thread] [Top] [All Lists] |