Microsoft vows to improve security tools after failed evaluation
AV-Test.org failed two Microsoft products in another round of security software testing
IDG News Service - Microsoft vowed on Wednesday to improve two of its security products after both failed to pass an evaluation by a Germany security software testing organization.
The company's Security Essentials and Forefront Endpoint Protection failed to earn a "certified" status in a latest round of testing by AV-Test to see how effective the products are against malicious software.
AV-Test, which conducts tests every two months at its laboratories in Magdeburg and Leipzig, also failed PC Tools' Internet Security 2012 and AhnLab's V3 Internet Security 8.0. In October, AV-Test failed to give Microsoft certified status for its Security Essentials versions 4.0 and 4.1.
Security software companies have often contested the conditions under which their products are examined by testing organizations following a poor rating, frequently arguing that testing parameters are flawed.
Joe Blackbird, a program manager in Microsoft's Malware Protection Center, softly contested AV-Test's methodology, which involves running the software security against a range of malware.
Blackbird wrote that Microsoft prioritizes how it provides protection based on the prevalence of threats. Many of the malware samples that AV-Test used were never encountered by millions of Microsoft systems, he wrote on a company blog.
In one example, Microsoft detected only 72 pieces of malware out of a sample of 100 pieces of zero-day malware, or attack code for which a detection signature has not been created yet.
But "we know from telemetry from hundreds of millions of systems around the world that 99.997% of our customers hit with any zero-day did not encounter the malware samples tested in this test," Blackbird wrote.
Microsoft did not detect about 9% of 216,000 pieces of "recent" malware in the AV-Test evaluation. But Blackbird wrote that 94% of missed samples were never encountered by the company's customers.
"When we explicitly looked for these files, we could not find them on our customers' machines," according to Blackbird.
Microsoft calculated that .0033% of its customers were impacted by malware that the company did not detect. But Blackbird noted that Microsoft had since added detection for some of those threats. Nonetheless, "we're committed to reducing our 0.0033% margin to zero," Blackbird wrote.
In December, Blackbird wrote that Microsoft processed 20 million new potentially malicious files. The company prioritizes how it blocks those threats, and added protection for four million of those.
"Those 4 million files could have been customer-impacting if we had not prioritized them appropriately," Blackbird wrote.
Send news tips and comments to firstname.lastname@example.org. Follow me on Twitter: @jeremy_kirk
- 15 Non-Certified IT Skills Growing in Demand
- How 19 Tech Titans Target Healthcare
- Twitter Suffering From Growing Pains (and Facebook Comparisons)
- Agile Comes to Data Integration
- Slideshow: 7 security mistakes people make with their mobile device
- iOS vs. Android: Which is more secure?
- 11 sure signs you've been hacked
- Mobile Policy Checklist Here's what to consider when putting together a mobile policy designed to support a highly productive workforce.
- Securing BYOD Mobile computing is becoming so ubiquitous that people no longer bat an eye seeing someone working two devices simultaneously. Individuals and organizations are...
- Gartner Report: A Guide to Gartner's Enterprise Mobile Security Self-Assessment Gartner introduces a model and a Toolkit intended to help mobility and security IT leaders assess their enterprise mobility programs from a security...
- Gartner Report: Containing Mobile Security Risks With the 80/20 Rule IT planners can deliver better mobile protection with higher user satisfaction by segmenting users into risk groups before committing to specific management or...
- Live Webcast On-demand webinar: "Mobility Mayhem: Balancing BYOD with Enterprise Security" Check out this on-demand webinar to hear Sophos senior security expert John Shier deep dive into how BYOD impacts your enterprise security strategy...
- Live Webcast Endpoint Backup & Restore: Protect Everyone, Everywhere Arek Sokol from the bleeding-edge IT team at Genentech/Roche explains how he leverages cross-platform enterprise endpoint backup in the public cloud as part...
- Streamline Software Asset Management, Compose a software Management Symphony Keeping track of your organization's software is easy with effective software management solutions from CDW. View the videos in our software solutions channel
- Druva inSync: Endpoint Data Protection & Governance CLICK HERE to watch this video about protecting corporate data on laptops and mobile devices, sponsored by Druva. All Security White Papers | Webcasts