Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos v9 detection rate not improving?

Hey there base on this test report by an individual, it seems that your detection rate has not improved and there are a few locations/files that you miss.. Avast seems to be improving their detection rate. Could you update your database/scan engine to improve the detection rate at those missing location/files

April's detection rate
http://securityspread.com/S0urce/Arch1ve/LatestDetectionRates-Apr2014.pdf

Source:http://securityspread.com/

Other vendors also seem to use this results and it seems that F-secure improve its detection rate once after those results are release

:1017517


This thread was automatically locked due to age.
  • Update on getting the malware samples not covered by Sophos in the latest testing from Security Spread.

    ruckus, this is a list of all the OSX malware samples used in testing. The latest Detection Rates PDF which you already downloaded contains all the necessary MD5 hashes needed in order to get those samples.

    http://securityspread.com/mac-antivirus-applications/  shows a list of the sources Security Spread used for these malware samples.

    All this information is publicly available on the Sec Spread site. I hope this will enable Sophos to include the missing definitons.

    :1017789
  • Checksums will confirm the file passed to SophosLabs is the same as the one used in a particular test but they aren't the files themselves.  Where are the files?  I've clicked around a bit but there is not a zip or similar that I can see.  Actually I would hope that testers don't publicly share malware for any and all to get hold of.  Therefore I would suggest the way to proceed is if security spread can forward the actual files to SophosLabs.

    It would be good to update detection but we don't have a process for manually hunting around different sites for hundreds of individual files. :smileysad:

    :1017791

     - - - - - - - - - - - -

    Communities Moderator, SOPHOS
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.

  • I don't feel very comfortable being in the middle of this: Jay at Sec Spread has told me that he is obligated by his sources not to distribute the malware samples anywhere. Wouldn't you be able to contact the sources he's listed?

    What about asking those sources just for the Mac samples Sophos appears to missing, according to the PDF? Wouldn't that narrow it down to a manageable size? I don't think it's that many.

    :1017793

  • brvx wrote:

    I don't feel very comfortable being in the middle of this


    I can understand that - you want to hand it over to either the people with the files, or the people who want the files.


    brvx wrote:

    Jay ... is obligated by his sources not to distribute the malware samples anywhere.


    I can imagine they shouldn't be handed out to private individuals, but not even an anti-virus firm?  I would think that a restriction on that wouldn't exist otherwise detection would be seriously delayed - unless the idea is to have a nice set of undetected files to shout about. :smileysurprised:

    A rather good test surely would be to forward them to each vendor and retest 24/48 hours later and see who's done something about it. :smileyhappy:


    brvx wrote:

    Wouldn't you be able to contact the sources he's listed?

    What about asking those sources just for the Mac samples Sophos appears to missing, according to the PDF? Wouldn't that narrow it down to a manageable size? I don't think it's that many.


    I can't go into detail but there are file exchanges setup so we would see a lot samples from other places (AV companies are all in the business of stopped malware and not about keep our files to ourselves).  I'll look into the missing detections more on Monday and speak to the labs and see what they want to do.  However (if Jay is listening) it would be ten times easier to host the files somewhere on a private link and email it the labs (or zip them up and email/upload them), labs grab the whole bunch at once, drop them into the mega machines that process all the files, URLs, spam emails, etc. and produce new detections within a couple of hours.

    :1017795

     - - - - - - - - - - - -

    Communities Moderator, SOPHOS
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.

Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?