<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Antivirus suites fail more often than not</title>
	<atom:link href="http://lastwatchdog.com/antivirus-suites-fail/feed/" rel="self" type="application/rss+xml" />
	<link>http://lastwatchdog.com/antivirus-suites-fail/</link>
	<description>on Internet security by Byron Acohido</description>
	<lastBuildDate>Wed, 10 Mar 2010 13:59:48 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: antivirus express</title>
		<link>http://lastwatchdog.com/antivirus-suites-fail/#comment-851</link>
		<dc:creator>antivirus express</dc:creator>
		<pubDate>Tue, 20 Oct 2009 13:31:09 +0000</pubDate>
		<guid isPermaLink="false">http://lastwatchdog.com/?p=2861#comment-851</guid>
		<description>Pretty good post. I just came across your site and wanted to say that I&#039;ve really liked browsing your posts. I hope you post again soon!</description>
		<content:encoded><![CDATA[<p>Pretty good post. I just came across your site and wanted to say that I&#8217;ve really liked browsing your posts. I hope you post again soon!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Francesco</title>
		<link>http://lastwatchdog.com/antivirus-suites-fail/#comment-782</link>
		<dc:creator>Francesco</dc:creator>
		<pubDate>Thu, 24 Sep 2009 14:26:36 +0000</pubDate>
		<guid isPermaLink="false">http://lastwatchdog.com/?p=2861#comment-782</guid>
		<description>When I say &quot;same thing as behavior analysis&quot;, of course, I&#039;m talking about that it is based on actually running the executable, hence it can&#039;t be considered something that can be present in every type of AV scanner. I&#039;m not saying that it&#039;s the same thing with a different hame.</description>
		<content:encoded><![CDATA[<p>When I say &#8220;same thing as behavior analysis&#8221;, of course, I&#8217;m talking about that it is based on actually running the executable, hence it can&#8217;t be considered something that can be present in every type of AV scanner. I&#8217;m not saying that it&#8217;s the same thing with a different hame.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Francesco</title>
		<link>http://lastwatchdog.com/antivirus-suites-fail/#comment-781</link>
		<dc:creator>Francesco</dc:creator>
		<pubDate>Thu, 24 Sep 2009 14:05:25 +0000</pubDate>
		<guid isPermaLink="false">http://lastwatchdog.com/?p=2861#comment-781</guid>
		<description>William, what are you saying, exactly?

Heuristics? They are not ignored in the detections generated by *any* scanner, be it online or in a real product. If a scanner detects a file through heuristics, it&#039;s considered detected in any &quot;test&quot;. Period. I don&#039;t know what gave you the idea that it isn&#039;t.

Blacklisting? What? Blacklisting *is* signature-based detection; a very poor type of signature based detection.

Whitelisting has *nothing* to do with detecting malicious files.

Behavior analysis can&#039;t be used in tests because it&#039;s based on running the executable, therefore is not suited for general purpose scanners such as gateway scanners. Behavior analysis is also extremely unreliable because if a malware gets the upper hand and doesn&#039;t get detected, it may completely disable the AV.

Protocol anomaly detection? Huh?

Process controls: same thing as behavior analysis.</description>
		<content:encoded><![CDATA[<p>William, what are you saying, exactly?</p>
<p>Heuristics? They are not ignored in the detections generated by *any* scanner, be it online or in a real product. If a scanner detects a file through heuristics, it&#8217;s considered detected in any &#8220;test&#8221;. Period. I don&#8217;t know what gave you the idea that it isn&#8217;t.</p>
<p>Blacklisting? What? Blacklisting *is* signature-based detection; a very poor type of signature based detection.</p>
<p>Whitelisting has *nothing* to do with detecting malicious files.</p>
<p>Behavior analysis can&#8217;t be used in tests because it&#8217;s based on running the executable, therefore is not suited for general purpose scanners such as gateway scanners. Behavior analysis is also extremely unreliable because if a malware gets the upper hand and doesn&#8217;t get detected, it may completely disable the AV.</p>
<p>Protocol anomaly detection? Huh?</p>
<p>Process controls: same thing as behavior analysis.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: William</title>
		<link>http://lastwatchdog.com/antivirus-suites-fail/#comment-767</link>
		<dc:creator>William</dc:creator>
		<pubDate>Wed, 23 Sep 2009 01:31:52 +0000</pubDate>
		<guid isPermaLink="false">http://lastwatchdog.com/?p=2861#comment-767</guid>
		<description>Really? Someone published Cyveillance&#039;s self-promoting and antivirus bashing report? They don&#039;t give any detailed information on their methodology, what version of the antivirus software they were running or any other test details. On the most serious note, they continue the myth that antivirus companies are only using signatures to detect attacks still.. MOST of those companies listed use all kinds of new technologies including Heuristics, blacklisting, whitelisting, behaviour analysis, protocol anomaly detection, process controls, and many more. For shame.</description>
		<content:encoded><![CDATA[<p>Really? Someone published Cyveillance&#8217;s self-promoting and antivirus bashing report? They don&#8217;t give any detailed information on their methodology, what version of the antivirus software they were running or any other test details. On the most serious note, they continue the myth that antivirus companies are only using signatures to detect attacks still.. MOST of those companies listed use all kinds of new technologies including Heuristics, blacklisting, whitelisting, behaviour analysis, protocol anomaly detection, process controls, and many more. For shame.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Robert</title>
		<link>http://lastwatchdog.com/antivirus-suites-fail/#comment-755</link>
		<dc:creator>Robert</dc:creator>
		<pubDate>Sat, 19 Sep 2009 08:00:58 +0000</pubDate>
		<guid isPermaLink="false">http://lastwatchdog.com/?p=2861#comment-755</guid>
		<description>I am not taking this report serious at all. It all comes down to them trying to sell their own defense system. 
As long as they not publish a full report about how and what they exactly tested, i&#039;m not buying it.</description>
		<content:encoded><![CDATA[<p>I am not taking this report serious at all. It all comes down to them trying to sell their own defense system.<br />
As long as they not publish a full report about how and what they exactly tested, i&#8217;m not buying it.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
