Home > Information Security Magazine > Features > Product review: Seven integrated endpoint security products
EMAIL THIS
Information Security Magazine

  CURRENT ISSUE  

  FEATURES  

  COLUMNS  

  HOT PICK & PRODUCT REVIEWS  

  ARCHIVES  

  SUBSCRIBE/RENEW  
 

Product review: Seven integrated endpoint security products
by Ed Skoudis & Matt Carpenter
Issue: Nov 2007
printer-friendly
< PREV PAGE   |   1  |   2  |   3  |   4  |   5  |   6  |   7  |   8  |   9  |   10  |   11  |   12  |   13  |   14  |   15  |   NEXT PAGE  >

ANTIMALWARE SCANNING
To gauge each vendor's ability to detect and block malware found in the wild, we ran three tests using 8,114 recent malware specimens from a private collection graciously provided by antispam researcher Bill Stearns. Our zoo included a large variety of worms, bots, backdoors and viruses. For each test, we recorded the percentage of specimens not eradicated in each round of testing (See "Antimalware Scanning Results," PDF).

[IMAGE] [IMAGE] [IMAGE] ENDPOINTS | Antimalware Scanning
[IMAGE] [IMAGE] [IMAGE] [IMAGE]
[IMAGE]
[IMAGE]
[IMAGE] The good news
Trend Micro, CA and eEye all did very well, generally detecting and blocking or removing all but about 8 to 9 percent of the malware thrown at them.

The bad news
IBM ISS crashed several times, scoring so poorly as to cause us to double-check that the protection was enabled.
[IMAGE]
[IMAGE]
Our first test was designed to evaluate each product's real-time signature-based defense...



s by copying the malware from a hardened machine to a shared directory on the protected target system. We then recorded the percentage of malware specimens that made it into the target's file system, escaping detection by the product's real-time scanning capabilities.

We then performed an on-demand scan of all malware that survived our first test, to assess the combined real-time and on-demand scan capabilities for identifying and eradicating malware.

Finally, we conducted on-demand scanning independently by disabling real-time scanning, copying all malware to the target file system, and then executing a scan of the entire zoo.

Trend Micro, CA and eEye all did very well, generally detecting and blocking or removing all but about 8 to 9 percent of the malware we threw at them in all tests.


[IMAGE] [IMAGE] [IMAGE] Antimalware Scanning Results
[IMAGE] [IMAGE] [IMAGE] [IMAGE]
[IMAGE]
[IMAGE]
[IMAGE]
Click here for our Antimalware Scanning results. (PDF).
[IMAGE]
[IMAGE]


< PREV PAGE   |   1  |   2  |   3  |   4  |   5  |   6  |   7  |   8  |   9  |   10  |   11  |   12  |   13  |   14  |   15  |   NEXT PAGE  >





TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts