Skip to content

Antivirus software is essential for safe internet browsing.

User Avatar
#20
Auto-translated
Greetings.

I offer for your review only the facts (it will be up to you to decide what is what and how it all fits together :) )

Comparison of various antiviruses based on a probabilistic assessment of their quality.

Currently, there is no shortage of information regarding antivirus testing. Moreover, the test results and the ratings assigned based on these results sometimes follow opposite vectors of evaluation.
As a rule, all tests boil down to evaluating the results of checking certain antiviruses against some set of malicious objects. The objectivity of such check results depends most heavily on the following aspects:
  • Availability of the virus collection or its composition to the antivirus authors
  • Quality of the virus collection
  • Adequacy of the virus set to real viral threats
- An antivirus whose authors know the composition of the virus collection in advance, or even better, have access to the collection itself, will always score 100 points. After all, the closer the contact between a particular antivirus and the testing experts, the better its "testing" result. Perhaps this explains such a wide variance in results across different tests?
- There are quite a few "collections" of viruses that include software modules that are only similar to viruses, but in reality are incapable of causing any harm. Most often these are programs that were infected by a virus, but subsequently the virus within them was sterilized—meaning the program was modified and the virus code no longer gains control. Such a program is no longer a malicious object, but it contains traces (signatures) of a virus's presence. If it is checked by an antivirus with primitive recognition algorithms—for example, by scanning the body of the checked object for certain signatures—then this "antivirus" will let out a victory cry, and its author will be proud that another antivirus "misses" the virus. A huge number of such examples can be given; therefore, if the quality of the collection is not verified and confirmed by independent specialists, the value of testing on such a collection will be low. Thus, primitive antiviruses will seem better than more advanced ones capable of modeling executable program code.
- Another important aspect is how adequate the chosen collection composition is to the existing threat. Again, there are a vast number of collections consisting of viruses for which the probability of landing on computers is zero. One has to deal with "testing" results using same-collector viruses held only by the antivirus author, who is very proud that this set of viruses is detected only by their antivirus and no one else! The real value of such an "antivirus" is also equal to zero.
In reality, the true value of an antivirus lies in its ability to prevent attacks from malicious objects that actually and currently threaten your computer. Unfortunately, all existing methods of testing antiviruses cannot provide such an assessment!
Below is a proposed methodology for assessing antivirus quality based on calculating the probability of an antivirus resisting attacks from malicious objects that actually threatened the computer system. The numerical value of such an assessment can be calculated using the formula:
Pav = (Nvir - Nbad) / Nvir
Where:
Pav - Probabilistic quality assessment of the antivirus; the closer it is to one, the better the antivirus.
Nvir - Total number of recorded malicious objects on this computer (organization).
Nbad - Number of malicious objects that the antivirus failed to detect at the time of attack.
Table 1 contains calculations of the reliability indicator (last column) for various antiviruses. The results of checking the reaction of various antiviruses to malicious objects actually encountered by the author of this publication between January 2006 and July 2007 were used as source data. The total number of recorded malicious objects was 51. The calculated reliability indicators for various antiviruses are provided in Table 1.
Table 1. Antivirus Reliability Indicators
Antivirus
Name
Viruses missed during the corresponding period of 2006 - 2007Viruses
missed out of
51 attacks
Antivirus
Quality
10.12 - 23.0217.0505.06 - 13.0712.0717.0721.0724-26.0727.0727.0730.0731.0703.08
DrWeb1210000300100170,667
Kaspersky1113100210011210,588
AntiVir1312021001011220,569
Fortinet1410022101111230,549
Sophos1910001001110240,529
BitDefender1413021011111250,510
McAfee1901022001101270,471
Ikarus191102110101027
eSafe1514112311000280,451
NOD32v21614021011111290,431
CAT-QuickHeal1903022011011300,412
ClamAV1603122211111310,392
VBA32180401121111131
Sunbelt2013022011011320,373
Norman211111130111032
F-Prot1614122311111330,353
Microsoft 261100100111133
Panda191402211101133
Authentium1614122311111340,333
AVG181402221111134
TheHacker2312111301111360,294
Ewido2214121311111380,255
Avast2504122011110390,235
Unfortunately, one of the antiviruses known in Russia, Symantec (better known here as Norton antivirus), did not fit into Table 1. This is because this antivirus was added to the VirusTotal website database on January 30, 2007, which made it impossible to include its indicators in the general table. However, thanks to the flexibility of the proposed assessment methodology, Symantec's reliability could be calculated using data from recent checks.
Table 2. Comparison of Symantec antivirus reliability indicator with other antiviruses.
Antivirus
Name
Viruses missed during the corresponding periodViruses
missed out of
17 attacks
Antivirus
Quality
30-0102-0202-0214-0223-0217-0717-0721-0721-07 24-0725-0725-0727-0727-0730-0731-0703-08
DrWeb0011000001110010060,647
Kaspersky0110100000111001180,529
NOD32v201100110100011111100,412
Symantec11110111111111100140,176

Sincerely K0Lb@zzeR.
:smile13: [ТУРНИР] "Гонка за Лидером" :smile13:
:smile28: [M] "Я и моя тень" - "I am and my shadow" :smile28:
:smile16: "Быстрая смерть" - "Fast Death" :smile16: