Skip to navigation
   
Davey Winder's Blog

Half of all rootkits still not detected by security software

By Davey Winder in Editorial

Posted in Blog, Security on May 14, 2008 at 12:17 pm

Permalink | Author Profile

Now that the media interest in rootkits seems to have all but evaporated, you might be forgiven for thinking that the problem has been solved, that the bad guys have moved on to another mode of attack, that the good guys have won. Forgiven, but wrong.

According to recently published tests by those hardy chaps over at AV.Test who, funnily enough, spend pretty much their entire working lives being a thorn in the side of the AV industry by putting security products under the microscope and testing them until they burst, rootkits are still very much on the criminal radar.

The trouble is they are unlikely to be on yours because the AV.Test grilling has revealed that around half of the rootkits they used during the testing process went undetected by security suites and online web scanners alike. The German security boffins used both Windows XP Home Edition and Windows Vista Ultimate Edition in the tests which threw multiple rootkits onto the clean computing lab-rats as well as multiple malware infections that used those rootkit technologies to remain hidden.

As far as XP was concerned the security suites performed better than the online web scanners, catching 66 percent of the installations compared to 53 percent. Actually cleaning up and removing the detected rootkits proved to be a real problem for the web based scanners in particular, in fact they could only manage an average successful removal rate of just 32 percent. XP based dedicated rootkit detection and removal tools did better, although with an average detection rate of 80 percent it is hardly confidence inspiring if you ask me: they still left 20 percent of the evil little buggers running quietly away with the user none the wiser.

The Vista testing was a little confusing, using only those AV tools which had been updated or ‘frozen’ as of October 2007, and AV.Test reports that the average detection rate of 90 percent upon inactive samples was surprising as most of the samples involved were released two or three years previously. Certainly you might imagine a newly updated AV tool to find all of those. You might even imagine they could remove them, but only 54 percent were removed OK.

When it came to the more recent active rootkit installations, Windows Live Onecare did pretty badly considering it should have the edge when talking about things that hook into the Vista OS at kernel level. According to the report it could only detect one of the six installed and active rootkits.

So which tools proved to be the ones with big smiles on their binary faces? Only three AV solutions managed to detect and remove all the active and inactive rootkits thrown at them:

  • F-Secure Anti-Virus 2008 6.80.2610.0
  • Norton Antivirus 2008 15.0.0.58
  • Panda Security Antivirus 2008 3.00.00
12345
Rated: 100% (1 votes)
Loading ... Loading ...

Previous Post | Next Post

 
 
Comments

Comment by Franchise Whale - May 15, 2008 on 3:53 pm

Really enjoyed it, I wanted to click out and
you kept pulling me back in! Many thanks
and keep up the great work!

Trackback by Syreeta Quilliams - February 9, 2012 on 5:13 am

sopa pipa…

[…]have offered their decision prior to Christmas but as the new yr strategies it now appearsĀ […]…

Make a comment

* required

* required

We stop spam using reCaptcha.
Type the words below and click Submit Comment.

   
Tag cloud

Sex Nexus Intel sick statistics FBI XP Blogging Geeks stupid computer politics graphics Psion Apple Retail hoax App Store HP Health books hacking Backlash monetisation GMail Jesus Phone Blog Ballmer ASUS Palm Pre law black hat Russia MSN YouTube Firefox Top 10 App RATM help Government holidays crime Gateway Android Johnny Depp Palm USA Flash theft Networks symantec Microchip Recall service productivity data MessageLabs AMD prison NASA Developers spam Facebook work scan console survey christmas Children Nintendo Windows Phone 7 Series security Military Press Experiment adware money Bill Gates biometrics hypervisor parental control museum Banned green McKinnon science data protection Top 500 code fake smartphone email hacker teleworking migration social networking remote working virus Kin Finjan outsourcing fraud Apps web 2.0 Internet Explorer Beta Paris Hilton computing services PS3 mail universe virtual machine iPad Election worker stupidity hubdub Tesco OCR Battery spending iPhone 3G VM chips Steve Ballmer Texas Instruments economy Microsoft Spotify Linux Windows web Education InfoSec encryption ISP Meh China Texting Parenting iPhone Europe eBook Vista ROFL Guardian Noro Army shopping e-commerce report Opinion Web Development VeriSign worm HPC banking mobile MSNBC Review Zango computers BOFH network documentation SSL compromise gaming Kill Switch e search Jobs Conference Rant library ID Theft President IBM credit crunch development fun global man-in-the-middle gadgets earth hour DNS Google linkedin Sony Mobile Phones Business virtual world Programming copyright Scotland betting phishing SMS desktop home VPN Twitter nightmare archiving Yahoo acquisition tax EU banks Marketing Rumour economics IDC Notebooks Adobe exploit workplace Windows 7 Data Centre iPod IP IT printing Acer standards OS Software storage Obama MiniBook campaign second life RAM Internet Lotus Browser family patent Application ecommerce Pirate Amazon Mobile Phone Google Earth students debian Netbook Eee malware Kindle credit card fraud Olympics dumb Digg memory technology Hack trust Cisco office Psychic management Gadget remote Addiction Trojan Research Patents iPhone 3GS policy admin Funny avatar xmas Digital Footprint BSI Dell botnet Kaspersky Supercomputer The Federation Michael Jackson staffing Architecture tech Analysis disclosure privacy Gartner carbon copy payments snooping CAPTCHA environment Mars Video surveys recession Employment Study support cloud lawsuit meme open source GSM football Enterprise Music Steve Jobs broadband Big Brother Silverlight Death virtualisation Mafia world of warcraft scam Trousers Advertising hardware wifi patch management fool size Porn information ISPA payment server Licensing Media innovation Project millions NBC Voice Madness rootkits Browsers news Deal Performance computing poll School Eee PC terrorism Energy scareware transactional security digitise Harry Potter Game Space games
Advertisement
Advertisement