All the latest UK technology news, reviews and analysis

Trend Micro fails anti-malware test

by Matt Chapman

03 Aug 2007

Comment: 1

  • Tweet this

All three of the anti-malware products submitted by Trend Micro for Virus Bulletin's independent tests failed because they produced false positives.

Of the 20 products submitted for testing, six generated false positives when scanning a set of known clean files and failed to meet the requirements for VB100 certification.

"Trend Micro, one of the 'big four' anti-malware companies, submitted no fewer than three of its anti-virus products, all of which falsely identified a Microsoft development tool as spyware," said a statement from Virus Bulletin.

"Other products to generate false positives were Fortinet's FortiClient, Ikarus Utilities, and VirusBuster."

The anti-malware tests were the first to be carried out by Virus Bulletin on 64-bit Windows Vista.

John Hawes, a technical consultant at Virus Bulletin, said the tests had included known clean files that were mostly taken from the 'most-popular' lists on free download sites.

"It is a concern that the additions have caused such an upsurge in false detections," Hawes said.

"A false positive can cause as much disruption as a virus infection and false warnings often lead end-users to delete valid files in the belief that they are some form of attack. The resultant damage can be significant."

Hawes said that many of today's products showed an increasing reliance on heuristic detection techniques, and anti-malware vendors had to work hard if they were going to minimise false detections.

Microsoft received widespread criticism in February 2007 after its OneCare consumer AV product failed to achieve VB100 certification on the 32-bit version of the Vista platform.

"This time its enterprise product, Forefront, put in a strong performance and was awarded VB100 status for Vista x64," the Virus Bulletin statement said.

Virus Bulletin's VB100 tests pit anti-virus products against a test set of viruses from the WildList, which are known to be circulating on computers around the world.

To earn VB100 certification, products must be able to detect 100 per cent of the viruses contained in the WildList test set and must not generate any false alarms when scanning a set of clean files.

In June three anti-virus makers failed to meet the VB100 standard for virus detection on Windows XP.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Java Developer - Belfast - Banking

Java Developer - Belfast - Banking Skills: Core Java...

Shared Accounting Service Manager - London

I am recruiting for a Shared Accounting Service Manager...

QA Tester/Automation Tester - C# .NET Agile, Epsom

QA Tester/Automation Tester - C# .NET Agile, Epsom, Surrey...

3RD LINE EXCHANGE 2010 / 2003, QUEST, LONDON, BLUE CHIP FIRM, CITY

3RD LINE EXCHANGE 2010 / 2003, QUEST, LONDON, GLOBAL...

To send to more than one email address, simply separate each address with a comma.