Malware Blocking Tests Put Trend Micro on Top

By Erik Larkin, PC World |  Security, antivirus, Trend Micro Add a new comment

Trend Micro scored well above its competition in new, antivirus test results that gauged whether an antivirus product can block malware you're tricked into downloading.

The unsponsored test of socially engineered malware protection from NSS Labs used just-collected URLs of malicious sites and downloads. The sites used social engineering lures, such as claims that visitors need to download a fake video codecs to watch a movie, to trick potential victims into downloading the malware.

According to NSS Labs president Rick Moy, these results indicate that Trend Micro stopped 91 percent of downloads by either blocking the URL prior to downloading the file, or recognizing the file as malicious after it was downloaded, but before it was executed/double-clicked. Trend recognized as malicious and stopped an additional 5.5 percent of malware after it was executed but before it could install, for a total block rate of 96.4 percent. Kaspersky came in second with an 87.8 percent overall success rate.

Moy's report notes that Trend Micro's high score was significantly boosted by the company's use of an in-the-cloud reputation system that checks URLs and downloads against a server-based list of known malicious sites and files.

It's important to note that because the execution blocking tests only used the malware that had first made it through the first two tests (blocking the URL or recognizing the download prior to execution), the execution results in the chart don't represent an overall test of any given product's ability to stop malware using behavioral analysis or something similar.

Also, NSS Labs' results don't represent a complete test of a product's overall efficacy, as the results don't measure how well AV might block malware that comes in as an e-mail attachment or any other vector aside from a socially engineered download. The tests also don't include sites that use hidden exploits on Web pages to attempt to install malware without your ever knowing. While exploits sites are highly dangerous, Moy says the attack code they use essentially breaks the method NSS Labs uses to automate downloads and testing (for more exploits and NSS Labs' methodology, see my previous post on IE 8 and browser URL blocking).

Instead, these tests' value lies in their ability to simulate real-world protection against a broad category of threats that are out there right now, based on the critical point of "did it keep the malware from running on the PC." NSS labs gathered lists of suspicious URLs and downloads, filtered and verified them as malicious, and then immediately used the lists to test antivirus products. The company used 3,243 verified URLs over the course of its tests, which were run during July and August.

Unlike previous browser blocking tests, Moy says these antivirus tests were not sponsored by any company. The full test report is available from the NSS Labs site for those who register. And for full antivirus product reviews that include malware blocking tests from AVTest.org, see PC World's charts for free antivirus and security suites (from January and May).

ITworld LIVE

SecurityWhite Papers & Webcasts

Webcast On Demand

Seven Deadly Sins of Cloud Security (Video)

As cloud computing gains popularity, too few people are aware of the security threats that are emerging. In this short video, experts from HP discuss the latest cloud security threats and explain measures to help overcome them. Hear about the seven deadly sins of cloud security and learn how to avoid becoming a victim of poor security in your cloud environment.Intel and the Intel logo are trademarks of Intel Corporation in the U.S. and/or other countries.

Sponsor: HP & Intel

White Paper

Establishing a Strategy for Database Security is No Longer Optional

The options for securing increasingly valuable databases are very broad and deep, and can be confusing. This research provides an overview of three categories of controls that should be implemented to ensure that enterprise data is protected in the most efficient and effective manner.

White Paper

Database Activity Monitoring Is Evolving

Read the analyst report and learn how you can leverage the core capabilities of a DAP solution for better database security.

White Paper

Protecting Against Database Attacks and Insider Threats: Top 5 Scenarios

Read this new eBook to learn the top five scenarios and essential best practices for preventing database attacks and insider threats.

Webcast On Demand

Distributed Database Security with Real-time Monitoring

View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with a holistic approach to data security and compliance.

Sponsor: IBM

See more White Papers | Webcasts

Ask a question

Ask a Question