Monday, October 26, 2015

Software often not well protected: Which antivirus is confident? – N-tv.de NEWS


 Art

 

 Monday, 26 October 2015

 
 
 

 
 AV-Test tested how well antivirus software protects itself against attackers. Some manufacturers maintain the protection perfect, others are far too easy to attack. The top grade get only 3 of 21

 

 
 

Anyone who moves on the Internet without security software, has been negligent. Good anti-virus programs are such a strong immune system, protect the computer from threats, attacks and infections from the network. But security solutions are as well actually even protected against attackers? The independent institute AV-Test has investigated this issue and has 31 Antivirus programs tested.

Already eleven months ago AV-Test manufacturer of protective packages had felt on the tooth and examined how well they protect themselves. The testers wanted to know whether the programmer to use the freely available protections DEP and ASLR, which can be used with little effort, for its program code. The result: Only 2 of 24 examined products put both mechanisms to 100 percent, 4 other only in the 64-bit version of their product

300 days later pulls AV-Test now balance. What has since then done? Manufacturers have responded and improved self-protection of their programs? 21 solutions for the home and 10 enterprise solutions were tested for their use of DEP and ASLR this time, both in the 32 and in the 64-bit variant. And indeed, there has been progress: in this test had six products 100 percent protection: Avira, BullGuard, ESET, Kaspersky, McAfee and Symantec. Two packages arrived in the evaluation 99.4 (F-Secure) and 99.5 percent (G Data). Avast Free Antivirus came to 96.9 percent, AVG Internet Security to 95.9 percent. Trend Micro was able to improve from 71 percent last year to 76 percent. Taillight is K7 Security with 25.9 percent.

ASLR and DEP

ASLR or Address Space Layout Randomization is a Speicherverwürfelung which makes it difficult to exploit vulnerabilities in computer systems. By ASLR address ranges allocated to the programs on a random basis. So attacks are to be prevented by a buffer overflow or at least more difficult.

DEP or Data Execution Prevention is also known as NX bit (No eXecute). The protection its base already in the hardware. The processor manufacturer AMD and Intel have implemented this technology for 10 years under the proper names EPP or XD bit in all its processors. You should prevent programs to execute arbitrary data as a program and start in this way malicious code.

One of the biggest proponents of these techniques is a long-time Microsoft. ASLR is used without exception since Windows Vista. DEP is supported since version XP SP. 2 Almost always tears an installed third-party software, the gaps in Windows-based system. Popular members of this genus are about Adobe Reader, Flash or Java.

As in the previous test has AV-Test out that some vendors have indicated to apply your own protection techniques, which are not compatible with DEP and ASLR. Which techniques are the in detail, the manufacturer

sobering result

but did not want to divulge. In addition, the testers have tested this time, if all the files are signed with a valid certificate. Finally, it is said in the report, expected that manufacturers of security software from other software producers that use these valid signatures and certificates. The help that is in the assignment and evaluation of files – unsigned files put in security products is a potential security hole is because anti-virus software to check authenticity and integrity even in their own files must

The result of the test. is sobering: The enterprise solutions had 50 percent of the products unsigned files in the products for home users, there were even 60 percent. With Avast, Check Point and thread track there was also still files with invalid certificates. This does not mean that these programs are unsafe per se, but keep them loopholes for potential attackers ready that would have to be really tightly

The best performing in the test ESET, McAfee and Symantec from -. All set DEP ASLR and 100 percent and work properly with signed files. Avira, BullGuard and Kaspersky have still to catch up, but also put the safety techniques a 100 percent.

  Source: n-tv.de
 

  themes
 
 

LikeTweet

No comments:

Post a Comment