home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!ukma!darwin.sura.net!jvnc.net!netnews.upenn.edu!netnews.cc.lehigh.edu!news
- From: gary@sci34hub.sci.com (Gary Heston)
- Newsgroups: comp.virus
- Subject: Re: Comment on the MtE wars (PC)
- Message-ID: <0010.9211091912.AA05064@barnabas.cert.org>
- Date: 2 Nov 92 20:07:28 GMT
- Sender: virus-l@lehigh.edu
- Lines: 39
- Approved: news@netnews.cc.lehigh.edu
-
- hobbit@ftp.com (*Hobbit*) writes:
- >Obviously none of you are willing to publicly discuss the exact hows
- >and whys of anyone's MtE-detection algorithm, for the usual reasons.
- >So the entire discussion is so far based on percentage hit rate, which
- >for me has significantly less meaning in terms of explaining WHY
- >product A sucks and product B is so much better. Is this just me, or
- >does it smell like so much handwaving to anyone else, too?
-
- No, not to me. I want to see a high hit rate from a large suite of
- test files, using every MtE-based virus known to generate the test
- files. I'm not concerned with the algorithm, for a few reasons:
-
- a) I'm not writing viral or antiviral code, so I have no use for it;
-
- b) The authors of the antiviral products have invested a considerable
- amount of work in them, and I see no reason to disclose that information
- to their competitors (free information is a nice idea, but won't work in
- other than a utopia, which we're not in...);
-
- c) Disclosing how the scanners detect MtE would assist Darkie in finding
- ways around detection, something I'm *not* in favor of;
-
- d) There are independent surveys of the effectiveness of the scanners,
- listing how well each of them do in identical environments.
-
- >Unfortunately I feel like I still have to slog through it all to find
- >the occasional hard useful facts.
-
- ..Welcome to the net.... :-)
-
- I find this group to be quite useful, due in great part to the excellent
- job being done by KvW, and really appreciate his time and efforts. I
- shudder to think what this group would be like if unmoderated....
-
- - --
- Gary Heston SCI Systems, Inc. gary@sci34hub.sci.com site admin
- The Chairman of the Board and the CFO speak for SCI. I'm neither.
- "...I looked out my window, and saw Kyle Pettys' car upside down, then I
- thought 'One of us is in real trouble'." Davey Allison, re: a 150MPH crash
-