Choose fontsize:   L *
Welcome, Guest. Please login or register.
Did you miss your activation email?
July 05, 2008, 01:48:36 PM

Login with username, password and session length
Stuff
  Our Stuff
     Gallery
     Arcade
     Bookmarks
     Tags
     Staff
     Members
     NetQuerry
  Friend's Stuff
     ASAP
     SpywareBeware
     CastleCops
     SpywareWarrior
     LandzDown
     TeMercIC
     MRU
     SecurityGarden
     MalwareBytes
     BISS
     hpHosts
     Malware Complaints
     MickeyTheMan
     GoingGreek
Scroogle

VOPWWW
Arcade
5 Most Played Games
ico
Diamond Mine Played 2886 times.
ico
Bubble Shooter Played 1132 times.
ico
Manjongg Solitare Played 783 times.
ico
Great Mahjong: Classic Played 473 times.
ico
Solitaire Played 269 times.
Our Best
5 Best Players
ico
- NetWidow with 38 Wins
ico
- brynn with 22 Wins
ico
- mikey with 5 Wins
ico
- cjdiedrich with 2 Wins
Admin

Themes

Members
Total Members: 34
Latest: cjdiedrich
Stats
Total Posts: 484
Total Topics: 109
Online Today: 8
Online Ever: 24
(June 08, 2007, 02:22:13 PM)
Users Online
Users: 0
Guests: 6
Total: 10
by mikey on September 28, 2007, 01:29:00 PM
Thoughts on Anti-Malware Comparison Testing


When I see all the many different so called tests of anti-malware products, all I see is a bunch of advertising. In addition to the fact that no two of these so called tests find the same results, I have some other concerns; How does one who is testing take into account the fact that all of the variables involved as well as the tools themselves are in a perpetual state of flux? Any real testing takes a bit of time. Even before any test is published, the results will already be invalid. While BrandX is still working on a particular definition, BrandY has already done so. Yet the BrandX definition will be published the next day and possibly better developed than that of BrandY.

Any real benchmark of these tools must include the study of it's removal routines for each type of nasty currently in the wild. That alone is a daunting study. But without it, there is no value to the testing.

Most F/Ps (false positives) don't occur on a freshly installed system. Removing items falsely can and very often does cripple innocent components. How do you measure the probability of F/Ps?

A true benchmark of the detections must include a validating sampling of targets. Limiting the sampling does not represent a true test at all. I can make any tool look good by simply limiting the sampling for the test. In all of the testing that has been published by online magazines and other so called professionals, this limiting has caused every single one to have different results. This has also been used as a marketing strategy.

In addition to studying the detections and removals, what other features are offered by the tools? What proactive features exist and do they work as pitched? Almost every scanner advertises that it protects the system. Do they really?...to what degree?...how much of it is just bloat?

Should any testing done by those affiliated with a particular tool be considered viable? How does anyone reading a test result know if a test was done by someone who is affiliated or has interest in a particular tool?

I have yet to see a real viable comparison test/benchmark. IMO, the methodology to perform a real comparison does not exist. Also, I believe that 99% of the so called tests published to date are simply advertising ploys and have absolutely no truth to them. I believe the other 1% are just done by well meaning folk who just simply don't have the understanding or expertise required in order to perform such testing.

Ask yourself; Why doesn't any two published comparison testings report the same results?

9136 Views | 0 Comments | Rating: (0 rates)
Commenting option has been turned off for this article.
Powered by SMF | SMF © 2006-2008, Simple Machines LLC
TinyPortal v0.9.8 © Bloc
BlueSkies design by Bloc | XHTML | CSS

Page created in 0.326 seconds with 27 queries.


Google visited last this page Yesterday at 05:46:34 AM