home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!ukma!darwin.sura.net!jvnc.net!netnews.upenn.edu!netnews.cc.lehigh.edu!news
- From: bontchev@fbihh.informatik.uni-hamburg.de (Vesselin Bontchev)
- Newsgroups: comp.virus
- Subject: Re: Comment on the MtE wars (PC)
- Message-ID: <0003.9211091912.AA05064@barnabas.cert.org>
- Date: 2 Nov 92 13:59:51 GMT
- Sender: virus-l@lehigh.edu
- Lines: 42
- Approved: news@netnews.cc.lehigh.edu
-
- hobbit@ftp.com (*Hobbit*) writes:
-
- > Obviously none of you are willing to publicly discuss the exact hows
- > and whys of anyone's MtE-detection algorithm, for the usual reasons.
-
- Yes, this is usually considered a trade secret.
-
- > So the entire discussion is so far based on percentage hit rate, which
-
- Correction: the discussion is not based on the percentage hit rate.
- There is no such thing as percentage hit rate when you are speaking
- about a known virus. Your scanner either is able to detect it
- reliably, or it isn't. My tests are trying to show which scanners are
- NOT able to detect the known MtE-based viruses reliably (because I
- cannot prove that I scanner DOES reliable detection - I can only try
- to find out an example that proves that a scanner is NOT able to do
- reliable detection).
-
- > for me has significantly less meaning in terms of explaining WHY
- > product A sucks and product B is so much better. Is this just me, or
-
- Simple. :-) Reliable detection of the MtE-based viruses is -extremely-
- difficult. Therefore, only anti-virus companies with very capable R&D
- departments are able to solve the puzzle. (Note: this is not a flame
- to anyone; for instance I don't know how reliable detection can be
- achieved.) The current tests clearly show that very few AV companies
- have indeed solved the puzzle.
-
- BTW, it was demonstrated to me that no scanner can be made to detect
- reliably unknown unencrypted MtE-based viruses. Sorry, but I cannot
- discuss the details in public. The important thing is that the virus
- could do some tricks to prevent this. None of the currently known
- MtE-based viruses does this trick, so this fact should have any
- impact on the current MtE detection by the scanners.
-
- Regards,
- Vesselin
- - --
- Vesselin Vladimirov Bontchev Virus Test Center, University of Hamburg
- Tel.:+49-40-54715-224, Fax: +49-40-54715-226 Fachbereich Informatik - AGN
- < PGP 2.0 public key available on request. > Vogt-Koelln-Strasse 30, rm. 107 C
- e-mail: bontchev@fbihh.informatik.uni-hamburg.de D-2000 Hamburg 54, Germany
-