Skip to navigation
   
Davey Winder's Blog

Half of all rootkits still not detected by security software

By Davey Winder in Editorial

Posted in Blog, Security on May 14, 2008 at 12:17 pm

Permalink | Author Profile

Now that the media interest in rootkits seems to have all but evaporated, you might be forgiven for thinking that the problem has been solved, that the bad guys have moved on to another mode of attack, that the good guys have won. Forgiven, but wrong.

According to recently published tests by those hardy chaps over at AV.Test who, funnily enough, spend pretty much their entire working lives being a thorn in the side of the AV industry by putting security products under the microscope and testing them until they burst, rootkits are still very much on the criminal radar.

The trouble is they are unlikely to be on yours because the AV.Test grilling has revealed that around half of the rootkits they used during the testing process went undetected by security suites and online web scanners alike. The German security boffins used both Windows XP Home Edition and Windows Vista Ultimate Edition in the tests which threw multiple rootkits onto the clean computing lab-rats as well as multiple malware infections that used those rootkit technologies to remain hidden.

As far as XP was concerned the security suites performed better than the online web scanners, catching 66 percent of the installations compared to 53 percent. Actually cleaning up and removing the detected rootkits proved to be a real problem for the web based scanners in particular, in fact they could only manage an average successful removal rate of just 32 percent. XP based dedicated rootkit detection and removal tools did better, although with an average detection rate of 80 percent it is hardly confidence inspiring if you ask me: they still left 20 percent of the evil little buggers running quietly away with the user none the wiser.

The Vista testing was a little confusing, using only those AV tools which had been updated or ‘frozen’ as of October 2007, and AV.Test reports that the average detection rate of 90 percent upon inactive samples was surprising as most of the samples involved were released two or three years previously. Certainly you might imagine a newly updated AV tool to find all of those. You might even imagine they could remove them, but only 54 percent were removed OK.

When it came to the more recent active rootkit installations, Windows Live Onecare did pretty badly considering it should have the edge when talking about things that hook into the Vista OS at kernel level. According to the report it could only detect one of the six installed and active rootkits.

So which tools proved to be the ones with big smiles on their binary faces? Only three AV solutions managed to detect and remove all the active and inactive rootkits thrown at them:

  • F-Secure Anti-Virus 2008 6.80.2610.0
  • Norton Antivirus 2008 15.0.0.58
  • Panda Security Antivirus 2008 3.00.00
12345
Rated: 100% (1 votes)
Loading ... Loading ...

Previous Post | Next Post

 
 
Comments

Comment by Franchise Whale - May 15, 2008 on 3:53 pm

Really enjoyed it, I wanted to click out and
you kept pulling me back in! Many thanks
and keep up the great work!

Make a comment

* required

* required

We stop spam using reCaptcha.
Type the words below and click Submit Comment.

   
Tag cloud

virtual world School size Cisco disclosure library IP adware outsourcing Mobile Phone policy Netbook Adobe hacking Texting Rumour Deal museum Silverlight productivity Steve Ballmer lawsuit economics economy biometrics MiniBook social networking Conference ecommerce Death EU holidays betting Noro Bill Gates MSN Steve Jobs China web 2.0 Supercomputer IT desktop Windows McKinnon exploit Media rootkits ASUS admin Mobile Phones broadband Finjan snooping hubdub YouTube Psychic Web Development banking virtualisation service Banned Army Project IBM Gartner Internet iPhone 3G Eee students fun Firefox technology Experiment Energy christmas Beta HPC BOFH hardware Texas Instruments spending news mobile privacy worm theft archiving development universe tech web credit card fraud acquisition work campaign teleworking linkedin Health books Battery Trojan Gadget surveys Blogging Kill Switch IDC world of warcraft stupid e-commerce debian CAPTCHA Jesus Phone Flash virtual machine spam compromise payments Application fraud Space XP second life help shopping innovation crime Parenting black hat Government prison Business USA iPod graphics Sony Olympics standards console patch management Eee PC Trousers SMS network Madness patent Dell Psion fake code search Linux scareware banks Software trust Sex staffing NBC Pirate global Acer remote working meme avatar science Browser Recall open source email green survey tax Video recession Vista transactional security poll The Federation family phishing report Google Earth Jobs scam gaming data millions Facebook OCR ROFL copyright hypervisor Apple President MSNBC botnet Patents stupidity Rant Big Brother migration services Michael Jackson Programming Meh games Education FBI VM Microchip Lotus remote Retail statistics Digg iPhone Twitter BSI scan Gateway politics Funny malware MessageLabs security environment payment server xmas Children chips man-in-the-middle Study Mars office digitise Windows 7 ID Theft Zango NASA dumb Russia Nintendo memory SSL worker information home OS InfoSec Paris Hilton monetisation Hack hacker Microsoft carbon copy Blog PS3 Data Centre workplace data protection Ballmer earth hour Game AMD computing money Performance computing documentation Google sick Obama VPN Porn HP credit crunch Yahoo storage DNS fool Military virus management Top 500 ISPA law terrorism computer Kaspersky symantec Research Notebooks VeriSign printing RAM
Advertisement
Advertisement