Cisco Learning Network Store Promotions Page
Showing posts with label Anti-malware. Show all posts
Showing posts with label Anti-malware. Show all posts

7.30.2015

9 OS X antimalware suites get the thumbs up from AV-TEST

AV-TEST ran 10 Mac OS X antivirus applications through its test labs, and five of the suites achieved 100% malware detection.  

Image: AV-TEST
Microsoft operating systems may soon have competition as the most popular malware targets, because the bad guys are making serious inroads with Apple products. Just yesterday, my friend's Apple notebook caught some new form of ransomware and is completely locked up.
 
Seeing an emerging trend, AV-TEST GmbH, an independent IT security and antivirus research house, started testing antimalware products for Apple in 2014, Mac OS X in the Crosshairs - 18 Malware Scanners Put to the Test. AV-TEST just released its 2015 survey, Mac OS X under attack - 10 security packages put to the test. The 2015 report starts out with good news, "While the first test of OS X security solutions in 2014 revealed that many products had massive problems in malware detection, the results in the 2015 test were significantly better."
 
The 10 systems tested are:
  • Avast Mac Security - free
  • Avira Free Antivirus
  • Bitdefender Antivirus for Mac
  • Kaspersky Internet Security
  • Symantec Norton Security
  • Intel Security/McAfee Internet Security
  • Intego VirusBarrier
  • Sophos Anti-Virus - free
  • Webroot SecureAnywhere
  • ClamXav - free

Test setup

One reason to pay attention to AV-TEST reports is the willingness of company management to publish, in detail, the procedures used during the testing. This test report was no different.
  • All products were installed on identical iMacs with a 2.7 GHz Core i5 CPU, 16 GB memory, and a 500 GB SSD hard disk running OS X 10.10 (Yosemite) with recent updates.
  • All test systems were connected to the internet, so the products could reach their respective cloud and reputation services.
  • Each product was installed and ran on the test system individually.
  • All product versions were cross-checked with the developer's website (when available) to ensure that we had the latest product version and updates installed (before the start of each test).
Maik Morgenstern, one of the company's CEOs and technical director, mentioned, "We only tested downloadable products offered at the AV vendors' websites. The versions available at the Mac App Store appeared to be limited in functionality."

Testing for malware detection

To be realistic, care was taken in creating the test set of more than 160 malware threats. "All samples are confirmed to include malicious functionality," explained Morgenstern. "During the creation of the test set, we selected the most recent samples from several different malware families."
 
Morgenstern added, "There may be archive files included in the test set, as long as the specific malware is distributed that way (e.g. DMG or PKG)."
 
As for the actual tests, engineers performed on-demand scans of "native" malware, Potentially Unwanted Applications (PUA), and Potentially Unwanted Programs (PUP) samples, including scripts.
 
When the initial test run was finished, the engineers checked for application updates; if any were available, they were installed and the application was tested again to see if the updated version detected samples missed earlier. On-access tests were also run twice. Morgenstern said, "However, we excluded archives as such formats are not scanned by all products."
 
The report stated that Avast, Avira, Bitdefender, Kaspersky, and Symantec had 100% malware detection. The only antimalware that had detection rates less than 88% was the security package from ClamXav, detecting 39.6% of the malware threats.

No false positives

Engineers at AV-TEST understand that false positives are the bane of the antimalware industry. If false positives appear regularly, users will ignore both false positives and real warnings. The 2015 report explains how AV-TEST engineers check for false positives:
 
"We perform an on-demand scan while installing and using the top 100 products for the Mac OS X platform. This includes, but is not limited to Adobe Reader XI, Apache OpenOffice, CCleaner, Firefox, GIMP, Google Chrome, iTunes, Java Runtime Environment, Libre Office, Opera, Picasa, Raw Therapee, Safari, Skype, Thunderbird, Virtualbox, and VLC media player."
 
Morgenstern added, "Only Webroot sounded a warning twice in the test when launching programs. The other security solutions passed this test category without a glitch."

Performance slowdown

Almost as bad as false positives are system slowdowns due to inefficient antimalware programs. To test for slowdowns, AV-TEST engineers first created a reference baseline by timing how long a Mac OS X reference machine without antimalware took to copy 20 - 30 GB of files (documents, media files, presentations, and programs). That averaged out to 66.1 seconds. The adjacent slide lists the results, with Symantec Norton Utility ending up on top.
 
The free versions of antimalware held their own. As for features, Morgenstern told me the free versions were spartan. He added, "Most paid versions were not much better feature-wise, but were better equipped than the freeware solutions." For example:
  • Intel Security (McAfee) and Norton include a firewall
  • Kaspersky offers parental control

Bottom line

What I took away from the tests and Morgenstern's explanations was that, except for ClamXav, the OS X security package you choose from this list of 10 appears to be a matter of personal preference.
 
It might be best to reiterate something Morgenstern mentioned earlier: make sure to download the antimalware program from the manufacturer's website or purchase the boxed version from a retail store.
 
~ Michael Kassner

4.08.2012

Three-quarters of Mac owners don't use anti-malware software

Early results from our "do you have anti-malware installed on your primary computer" polls are in, and there's some change from the ones conducted last May. More respondents on Mac and Windows use security software, but the split remains polarized: 75 percent of Mac users don't, while 90 percent of their Windows counterparts do. Welcome to the wonderful world of Apple denial. There are no pesticides to save this crop.

Responses are unusually low to both polls. I should know better asking anything over the Easter holiday weekend and start of Passover. I'm re-embedding the polls, hoping to jack up the numbers -- 315 for Mac and 358 for Windows, as I write. But the polarized results are consistent enough with the previous polls, when 86 percent of Windows PC users answered yes and 81 percent of Mac owners no. The difference between the polls is within reasonable margin of error, particularly considering respondents aren't qualified. Responses also could represent increased anti-malware usage in both camps.

I asked the poll following reports that the Flashback Trojan infects more than 600,000 Macs, binding them together as a botnet. Flashback first popped up last summer, so this isn't something new -- just the success as new variants appeared, Apple released updates (often too slowly) and Mac users failed to apply them.

Readers Respond


BetaNews reader Joel Medina uses OS X and Windows, and on the latter runs Microsoft Security Essentials. "But on my mac I rarely install an AV program -- not because I think I'm immune but because it's just so rare that Macs get them because the focus for years for hackers was to attack Windows. But now that Macs are starting to get into mainstream usage I'm considering an antivirus program for my Macs."

Andrew Johnson comments earlier today:
Getting nasties such as Mac Defender or System Tool 2012 or whatever on your computer has always been more about the user's browsing habits than about any supposed flaws, or lack thereof, in the browser and/or operating system. This is not to say that those flaws do not exist, but they would be harder to exploit if most users knew what and how to avoid infection.
Mac has had a pretty good track record up until recently, but I have always said, Apple versus Microsoft is an irritating debate, because it's all code, and if you can write code for it, you can write malicious code. I'm not using the "security through obscurity" argument here, I'm just saying it was always just a matter of time.
On a side note, I find it sad how many people think that their smartphones are unassailable fortresses even though the number of infected mobile devices is on the rise.
The real question to ask: Do you need antivirus software at all? Reader capncoad has an answer for that: "Anti-malware apps are simply a moron detector with no real security. Every time it dings and tell you that it blocked a virus, it's really saying 'moron'...If someone created an antivirus app that caused your PC to shock you every time you downloaded a 200kb executable thinking it was a free song then I think we'd be on to something".

That's the point isn't it? Behavior. Windows 7 and OS X 10.7 are pretty hardened. Often malware infections are about stupid online behavior. "How stupid can people be", maddy143ded writes. "Why download stuff from websites that promise you a song and instead give you a small executable?"

Do I Feel Lucky?

There are lots of reasons, like social media. Your friend whom you trust recommends a link and you click. Or you trust Google and search for band X, only to find SEO poisoning in place. Or you trust Apple marketing statements like "Mac OS X doesn't get PC viruses", creating a false sense of security. Or you're browsing from home, you feel safe and project that feeling to web browsing. Trust is the constant.

Last year I kicked Apple in the groin for making security claims like this: "Mac OS X doesn't get PC viruses", which fosters a false sense of security. Oftentimes, as Flashback and countless Windows malware show, successful attacks are more about social engineering than lax operating system security. Human behavior matters as much, sometimes more. Criminals can break in no matter how good the locks if people open the door for them.

But do they need to install a separate security system (e.g. anti-malware)? I would feel pretty safe using Windows 8 and OS X Snow Leopard without anti-malware software. But then, again, I'm cautious of what I click.

After making Snow Leopard seem like the toughest thing next to the Terminator, the updated OS X security page concedes and recommends:
The Mac is designed with built-in technologies that provide protection against malicious software and security threats right out of the box. However, since no system can be 100 percent immune from every threat, here are some other ways to help keep your information as safe as possible:
  • Download files only from known and trusted websites.
  • Use FileVault 2 to encrypt everything on your Mac.
  • Control access to your Mac by locking your screen after a period of inactivity.
  • Securely delete outdated sensitive files with the Secure Empty Trash command.
As Clint Eastwood playing Dirty Harry said, "You've got to ask yourself one question: Do I feel lucky? Well, do ya, punk?"

~ Joe Wilcox