Skip to navigation
   
Davey Winder's Blog

Half of all rootkits still not detected by security software

By Davey Winder in Editorial

Posted in Blog, Security on May 14, 2008 at 12:17 pm

Permalink | Author Profile

Now that the media interest in rootkits seems to have all but evaporated, you might be forgiven for thinking that the problem has been solved, that the bad guys have moved on to another mode of attack, that the good guys have won. Forgiven, but wrong.

According to recently published tests by those hardy chaps over at AV.Test who, funnily enough, spend pretty much their entire working lives being a thorn in the side of the AV industry by putting security products under the microscope and testing them until they burst, rootkits are still very much on the criminal radar.

The trouble is they are unlikely to be on yours because the AV.Test grilling has revealed that around half of the rootkits they used during the testing process went undetected by security suites and online web scanners alike. The German security boffins used both Windows XP Home Edition and Windows Vista Ultimate Edition in the tests which threw multiple rootkits onto the clean computing lab-rats as well as multiple malware infections that used those rootkit technologies to remain hidden.

As far as XP was concerned the security suites performed better than the online web scanners, catching 66 percent of the installations compared to 53 percent. Actually cleaning up and removing the detected rootkits proved to be a real problem for the web based scanners in particular, in fact they could only manage an average successful removal rate of just 32 percent. XP based dedicated rootkit detection and removal tools did better, although with an average detection rate of 80 percent it is hardly confidence inspiring if you ask me: they still left 20 percent of the evil little buggers running quietly away with the user none the wiser.

The Vista testing was a little confusing, using only those AV tools which had been updated or ‘frozen’ as of October 2007, and AV.Test reports that the average detection rate of 90 percent upon inactive samples was surprising as most of the samples involved were released two or three years previously. Certainly you might imagine a newly updated AV tool to find all of those. You might even imagine they could remove them, but only 54 percent were removed OK.

When it came to the more recent active rootkit installations, Windows Live Onecare did pretty badly considering it should have the edge when talking about things that hook into the Vista OS at kernel level. According to the report it could only detect one of the six installed and active rootkits.

So which tools proved to be the ones with big smiles on their binary faces? Only three AV solutions managed to detect and remove all the active and inactive rootkits thrown at them:

  • F-Secure Anti-Virus 2008 6.80.2610.0
  • Norton Antivirus 2008 15.0.0.58
  • Panda Security Antivirus 2008 3.00.00
12345
Rated: 100% (1 votes)
Loading ... Loading ...

Previous Post | Next Post

 
 
Comments

Comment by Franchise Whale - May 15, 2008 on 3:53 pm

Really enjoyed it, I wanted to click out and
you kept pulling me back in! Many thanks
and keep up the great work!

Make a comment

* required

* required

We stop spam using reCaptcha.
Type the words below and click Submit Comment.

   
Tag cloud

data Energy virtualisation Notebooks Experiment books Windows Phone 7 Series scan ISP App Mafia Obama patent rootkits Top 10 web hacker snooping Ballmer hoax Beta YouTube Flash Supercomputer PS3 Military payments search Data Centre web 2.0 Cisco MessageLabs iPod DNS InfoSec Netbook virtual world world of warcraft HPC network Blogging students Kill Switch work Firefox development documentation nightmare Gadget Hack Space Conference Recall computing security worm Health Software worker smartphone man-in-the-middle Dell ISPA MiniBook Google Earth Twitter storage code carbon copy ROFL encryption USA Networks teleworking NASA Acer Backlash size fool Texas Instruments Advertising technology Apple Nexus campaign malware statistics AMD Research Licensing Windows Palm earth hour Video Russia Top 500 help news Rumour Gartner Sony SMS Android hardware desktop family credit card fraud Sex banks transactional security crime mobile dumb remote working Eee PC broadband christmas Blog theft RATM symantec The Federation Olympics Kindle Internet Explorer museum Big Brother data protection iPhone 3GS EU law Election standards VPN iPhone Review iPhone 3G tech banking debian Children OS ecommerce Spotify Battery privacy Rant library Mars environment console acquisition Madness Education Patents global xmas archiving Europe productivity linkedin Geeks Browser e-commerce Study Tesco eBook Kaspersky Death Texting BSI chips compromise hubdub Project Digg biometrics App Store betting payment server spending Press Retail NBC Silverlight Digital Footprint tax Application GSM memory phishing Internet ID Theft Employment workplace IBM VM Microchip Psion universe Facebook President recession Finjan Zango virus graphics credit crunch Paris Hilton e service Deal email remote Architecture trust MSNBC stupidity Guardian services report Addiction science stupid HP RAM Mobile Phone terrorism Banned scareware printing disclosure FBI botnet Web Development lawsuit cloud millions management fraud IT computer innovation Marketing social networking Intel OCR Apps migration digitise CAPTCHA Trousers GMail office Performance computing Johnny Depp Porn Eee economics staffing Jobs fun games Trojan Programming ASUS Meh outsourcing admin black hat gaming Michael Jackson spam Business Browsers Palm Pre Parenting Pirate open source virtual machine poll copyright hacking MSN hypervisor Harry Potter home Developers politics Mobile Phones scam Google holidays monetisation Game Opinion Media exploit China mail VeriSign avatar money Nintendo Vista fake shopping patch management Steve Jobs IDC prison IP Gateway Amazon McKinnon Steve Ballmer Army second life sick green Bill Gates Funny Noro XP Adobe Windows 7 Music policy Voice meme Enterprise Microsoft Psychic economy information Jesus Phone survey Lotus Government SSL BOFH Yahoo surveys adware wifi School Linux
Advertisement
Advertisement