Antivirus Self-Protection Test (August 2007)
Table of Contents:
- Introduction
- Test Results and Awards
Introduction
Online criminal activities are gaining momentum faster than ever. Both the rate at which new types and modifications of malicious programs appear and the complexity of malware are on the rise. Cybercriminals use increasingly sophisticated methods, including masking the presence of a malicious program in the system, compression, encryption and incapacitating antivirus solutions.
Social engineering techniques make it easy to entice users to download and launch malicious programs as yet unknown by antivirus solutions. In such cases, in order to gain complete and uninterrupted control over the system, malicious programs search for an antivirus program, firewall or other protective solution in order to disrupt its operation.
Consequently, contemporary antivirus products should be able to resist such attempts, that is, they should include self-protection functionality. This helps them to resist even the most complicated attacks, such as when malicious programs use a variety of methods to disable protection, and remove the infection using standard tools after receiving the appropriate antivirus database updates.
In the test described below, we analyzed the self-protection capabilities of antivirus solutions that run under Microsoft Windows XP with Service Pack 2.
Self-protection from the following types of attacks was analyzed:
- Modification of file and registry key access permissions.
- Modification / removal of modules.
- Deletion of antivirus databases.
- Modification / deletion of important registry keys.
- Process termination.
- Modification of processes / code.
- Driver unloading.
Metodology for Self-Protection Test »
Awards Guide of Self-Protection Test »
Fifteen of the most popular antivirus programs were tested, including:
- Avast! Professional Edition 4. 7
- Avira Premium Security Suite 7.0
- BitDefender Internet Security 10
- DrWeb 4.44
- ESET Smart Security 3.0
- F-Secure Internet Security 2007
- Kaspersky Internet Security 7.0
- McAfee Internet Security 2007
- Microsoft Windows Live OneCare 1.6
- Panda Internet Security 2007
- Sophos Anti-Virus 6.0
- Symantec Internet Security 2007
- Trend Micro PC-Cillin 2007
- VBA32 Antivirus 3.11
- ZoneAlarm Internet Security 7.0
The antivirus product self-protection test was conducted on products running under Microsoft Windows XP with Service Pack 2 for the following groups of attacks:
- Modification of file and registry key access permissions
- Modification / removal of modules
- Deletion of antivirus databases
- Modification / deletion of important registry keys
- Process termination
- Modification of processes / code
- Driver unloading.
Analysis of each antivirus product’s self-protection was based on each of the 33 parameters tested and was conducted in strict accordance with the testing methodology.
Test Results and Awards
Table 1. Final results of antivirus product self-protection testing and the awards received
Products tested |
Awards
|
Points scored |
% of maximum
|
Kaspersky Internet Security 7.0
|
|
32
|
97%
|
VBA32 Antivirus 3.11
|
|
23.5
|
71%
|
Symantec Internet Security 2007
|
23.5
|
71%
|
|
F-Secure Internet Security 2007
|
20
|
61%
|
|
ZoneAlarm Internet Security 7.0
|
|
19
|
58%
|
Panda Internet Security 2007
|
16
|
48%
|
|
McAfee Internet Security 2007
|
15.5
|
47%
|
|
ESET Smart Security 3.0
|
14.5
|
44%
|
|
Trend Micro PC-Cillin 2007
|
14
|
42%
|
|
Avast! Professional Edition 4. 7
|
Failed
|
11
|
33%
|
Avira Premium Security Suite 7.0
|
11
|
33%
|
|
Sophos Anti-Virus 6.0
|
11
|
33%
|
|
DrWeb 4.44
|
10.5
|
32%
|
|
Microsoft Windows Live OneCare 1.6
|
10.5
|
32%
|
|
BitDefender Internet Security 10
|
10
|
30%
|
In accordance with the award scheme, 1 point (+) was awarded for each parameter (type of attack) for which an attack was successfully blocked.
One-half of a point (0.5, +/-) was awarded if the product did not include complete self-protection from a specific type of attack, but retained (or automatically restored) its main functionality.
And, finally, if self-protection was absent and the product’s main functionality was deactivated, the antivirus product received no point for a specific type of attack.
As Table 1 shows, the absolute leader in terms of self-protection is Kaspersky Internet Security 7.0, which received the Gold Self-Protection Award. This antivirus product blocked 97% of attacks and scored 32 points out of a possible 33. Its score was only 1 percentage point below that required for a Platinum Self-Protection Award (see analysis of test results and awards).
High self-protection results were demonstrated by three antivirus products, including VBA32 Antivirus 3.11, Symantec Internet Security 2007 and F-Secure Internet Security 2007, which scored 61% to 71% and received the Silver Self-Protection Award.
Five more products, including ZoneAlarm Internet Security 7.0, Panda Internet Security 2007, McAfee Internet Security 2007, ESET Smart Security 3.0 and Trend Micro PC-Cillin 2007, demonstrated a satisfactory result and received the Bronze Self-Protection Award.
It is worth mentioning ZoneAlarm Internet Security, which completely failed to block only four attacks, but received a low score because its unprotected antispam module from MailFrontier was disabled by most of the attacks.
All other antivirus products failed the test, scoring less than 40% of the maximum possible points.
Table 2 shows the number of points scored by each antivirus product based on the number of attacks blocked and missed by its self-protection during testing.
Table 2. Number of attacks blocked and missed and total points scored by each product
Products tested | Number of attacks blocked | Number of attacks missed due to the absence of self-protection (0 points) 3 |
Total Points scored (out of 33) |
|
Number of attacks completely blocked (1 point) 1 |
Number of attacks partially blocked (0.5 points) 2 |
|||
Kaspersky Internet Security 7.0 |
31
|
2
|
0
|
32
|
VBA32 Antivirus 3.11 |
23
|
1
|
9
|
23.5
|
Symantec Internet Security 2007 |
19
|
9
|
5
|
23.5
|
F-Secure Internet Security 2007 |
16
|
8
|
9
|
20
|
ZoneAlarm Internet Security 7.0 |
9
|
20
|
4
|
19
|
Panda Internet Security 2007 |
11
|
10
|
12
|
16
|
McAfee Internet Security 2007 |
6
|
19
|
8
|
15.5
|
ESET Smart Security 3.0 |
7
|
15
|
11
|
14.5
|
Trend Micro PC-Cillin 2007 |
7
|
14
|
12
|
14
|
Avast! Professional Edition 4. 7 |
8
|
6
|
19
|
11
|
Avira Premium Security Suite 7.0 |
4
|
14
|
15
|
11
|
Sophos Anti-Virus 6.0
|
6
|
10
|
17
|
11
|
DrWeb 4.44 |
6
|
9
|
18
|
10.5
|
Microsoft Windows Live OneCare 1.6 |
3
|
15
|
15
|
10.5
|
BitDefender Internet Security 10 | 4 | 12 | 17 | 10 |
1) The product’s self protection successfully blocked the attack.
2) Self-protection from the attack is partially missing, but the main functionality was retained (or automatically restored).
3) The product lacks self-protection from a specific type of attack or the self-protection is present, but the product’s main functionality was disabled.
Below, we present additional information on the antivirus product self-protection testing results by type of attack.
Table 3. Testing results (the system level)
Products tested |
Points scored |
Assessment of results
|
Kaspersky Internet Security 7.0
|
6
|
Good
|
Symantec Internet Security 2007
|
4
|
Satisfactory
|
ZoneAlarm Internet Security 7.0
|
3.5
|
|
Trend Micro PC-Cillin 2007
|
2
|
Failed testing |
Panda Internet Security 2007
|
1
|
|
Avast! Professional Edition 4. 7
|
0
|
|
Avira Premium Security Suite 7.0
|
0
|
|
BitDefender Internet Security 10
|
0
|
|
DrWeb 4.44
|
0
|
|
ESET Smart Security 3.0
|
0
|
|
F-Secure Internet Security 2007
|
0
|
|
McAfee Internet Security 2007
|
0
|
|
Microsoft Windows Live OneCare 1.6
|
0
|
|
Sophos Anti-Virus 6.0
|
0
|
|
VBA32 Antivirus 3.11
|
0
|
Table 4. Testing results (process termination)
Products tested |
Points scored |
Assessment of results
|
KasperskyInternetSecurity 7.0 |
15
|
Excellent
|
F-Secure Internet Security 2007 |
13
|
|
VBA32 Antivirus 3.11 |
12.5
|
|
Symantec Internet Security 2007 |
11
|
Good
|
Panda Internet Security 2007 |
10
|
|
McAfee Internet Security 2007 |
8
|
|
ESET Smart Security 3.0 |
7.5
|
Satisfactory
|
ZoneAlarm Internet Security 7.0 |
7.5
|
|
Avast! Professional Edition 4. 7 |
5.5
|
Failed testing |
Microsoft Windows Live OneCare 1.6 |
5.5
|
|
Trend Micro PC-Cillin 2007 |
5.5
|
|
Avira Premium Security Suite 7.0 |
5
|
|
BitDefender Internet Security 10 |
5
|
|
DrWeb 4.44
|
5
|
|
SophosAnti-Virus 6.0 |
4.5
|
Table 5. Testing results (process modification)
Products tested |
Points scored |
Assessment of results
|
Kaspersky Internet Security 7.0
|
9
|
Excellent
|
VBA32 Antivirus 3.11
|
9
|
|
Symantec Internet Security 2007
|
7.5
|
|
McAfee Internet Security 2007
|
6
|
Good
|
ZoneAlarm Internet Security 7.0
|
6
|
|
ESET Smart Security 3.0
|
5.5
|
Satisfactory
|
Avira Premium Security Suite 7.0
|
5
|
|
F-Secure Internet Security 2007
|
5
|
|
Trend Micro PC-Cillin 2007
|
5
|
|
Sophos Anti-Virus 6.0
|
4.5
|
|
Avast! Professional Edition 4. 7
|
3.5
|
Failed testing |
BitDefender Internet Security 10
|
3.5
|
|
DrWeb 4.44
|
3.5
|
|
Microsoft Windows Live OneCare 1.6
|
3.5
|
|
Panda Internet Security 2007
|
3.5
|
Table 6. Testing results (driver protection)
Products tested |
Points scored |
Assessment of results
|
ZoneAlarm Internet Security 7.0
|
2
|
Excellent
|
VBA32 Antivirus 3.11
|
2
|
|
Sophos Anti-Virus 6.0
|
2
|
|
Kaspersky Internet Security 7.0
|
2
|
|
F-Secure Internet Security 2007
|
2
|
|
DrWeb 4.44
|
2
|
|
Avast! Professional Edition 4. 7
|
2
|
|
Trend Micro PC-Cillin 2007
|
1.5
|
Good
|
Panda Internet Security 2007
|
1.5
|
|
Microsoft Windows Live OneCare 1.6
|
1.5
|
|
McAfee Internet Security 2007
|
1.5
|
|
ESET Smart Security 3.0
|
1.5
|
|
BitDefender Internet Security 10
|
1.5
|
|
Symantec Internet Security 2007
|
1
|
Satisfactory
|
Avira Premium Security Suite 7.0
|
1
|
As Tables 3–6 show, the best overall results were achieved in the categories of driver protection and protection from process modification (which only five products failed).
This analysis has demonstrated that only four of the antivirus products tested (Kaspersky Internet Security 7.0, VBA32 Antivirus 3.11, Symantec Internet Security 2007 and F-Secure Internet Security 2007) are equipped with adequate self-protection.
Of these products, only the self-protection included in Kaspersky Internet Security 7.0, which scored 97% and received the Gold Self-Protection Award, is truly reliable.
Avast! Professional Edition 4.7, Avira Premium Security Suite 7.0, Sophos Anti-Virus 6.0, DrWeb 4.44, Microsoft Windows Live OneCare 1.6 and BitDefender Internet Security 10 failed testing, demonstrating that they are virtually incapable of blocking possible attacks by malicious programs.
Detailed testing results for each antivirus product and more detailed information on the calculations based on the testing results can be downloaded in Microsoft Excel format (attached to this post).
- Login to post comments