PC Anti-Virus Protection 2011
Total Page:16
File Type:pdf, Size:1020Kb
PC Anti-Virus Protection 2011 12 POPULAR ANTI-VIRUS PROGRAMS COMPARED FOR EFFECTIVENESS Dennis Technology Labs, 03/08/2010 www.DennisTechnologyLabs.com This test aims to compare the effectiveness of the most recent releases of popular anti-virus software1. The products include those from Kaspersky, McAfee, Microsoft, Norton (Symantec) and Trend Micro, as well as free versions from Avast, AVG and Avira. Other products include those from BitDefender, ESET, G-Data and K7. The tests were conducted between 07/07/2010 and 22/07/2010 using the most up to date versions of the software available. A total of 12 products were exposed to genuine internet threats that real customers could have encountered during the test period. Crucially, this exposure was carried out in a realistic way, reflecting a customer’s experience as closely as possible. For example, each test system visited real, infected websites that significant numbers of internet users were encountering at the time of the test. These results reflect what would have happened if those users were using one of the seven products tested. EXECUTIVE SUMMARY Q Products that block attacks early tended to protect the system more fully The nature of web-based attacks means that the longer malware has access to a system, the more chances it has of downloading and installing further threats. Products that blocked the malicious and infected websites from the start reduced the risk of compromise by secondary and further downloads. Q 100 per cent protection is rare This test recorded an average protection rate of 87.5 per cent. New threats appear online frequently and it is inevitable that there will be times when specific security products are unable to protect from some of these threats. Q The products rarely blocked the installation of legitimate applications There were a number of cases in which the anti-virus programs warned against allowing legitimate applications full access to the system and the network. However, they rarely blocked these applications from installing . Simon Edwards, Dennis Technology Labs 1 The latest available products were used in the test: Avast! Free AntiVirus 5 K7 Total Security 10 AVG Anti-Virus Free Edition 9 Kaspersky Internet Security 2011 Avira Personal - Free Antivirus 10 McAfee Internet Security 2010 BitDefender Internet Security 2010 Microsoft Security Essentials ESET Smart Security 4 Norton Internet Security 2011 G Data InternetSecurity 2011 Trend Micro Internet Security 2010 PC Anti-Virus Protection 2011 Page 1 of 60 CONTENTS Executive summary ........................................................................................................................................ 1 Contents ......................................................................................................................................................... 2 1. Overall Accuracy ........................................................................................................................................ 3 2. Overall Protection ...................................................................................................................................... 5 3. Protection Details ....................................................................................................................................... 7 4. False Positives ............................................................................................................................................. 9 5. The tests ................................................................................................................................................... 14 6. Test details ................................................................................................................................................ 16 7. Conclusions .............................................................................................................................................. 20 Appendix A: Terms ...................................................................................................................................... 21 Appendix B: Legitimate Samples .................................................................................................................. 22 Appendix C: Threat report .......................................................................................................................... 26 Appendix D: Tools ....................................................................................................................................... 59 Appendix E: Terms of the test ..................................................................................................................... 60 PC Anti-Virus Protection 2011 Page 2 of 60 1. OVERALL ACCURACY Each product has been scored for its accuracy in detecting and handling malware. We awarded two points for defending against a threat, one for neutralizing it and deducted two points every time a product allowed the system to be compromised. The reason behind this score weighting is to give credit to products that deny malware an opportunity to tamper with the system and to penalize those that allow malware to damage it. In some of our test cases a compromised system was made unstable, or even unusable without expert knowledge. Even if active malware was removed, we considered such damaged systems to count as being compromised. The Norton product defended against all threats so it scores a full 80 marks. It was the only product to avoid being compromised by the internet threats. Kaspersky's product came a close second, losing points due to neutralizing two threats and being compromised by one. Accuracy Scores 80 70 60 50 40 30 20 10 0 The Symantec (Norton) product was the only one to protect against all the internet threats used. PC Anti-Virus Protection 2011 Page 3 of 60 ACCURACY SCORES Target Target Target Overall Product Defended Neutralized Compromised Accuracy Norton Internet Security 2011 40 0 0 80 Kaspersky Internet Security 2011 37 2 1 74 ESET Smart Security 4 34 4 2 68 Avast! Free AntiVirus 5 35 2 3 66 G Data InternetSecurity 2011 32 3 5 57 Avira Personal - Free Antivirus 10 29 4 7 48 Trend Micro Internet Security 2010 23 11 6 45 AVG Anti-Virus Free Edition 9 23 11 6 45 BitDefender Internet Security 2010 29 2 9 42 McAfee Internet Security 23 6 11 30 Microsoft Security Essentials 22 4 14 20 K7 Total Security 10 20 5 15 15 PC Anti-Virus Protection 2011 Page 4 of 60 2. OVERALL PROTECTION The following illustrates the general level of protection provided by each of the security products, combining the defended and neutralized incidents into an overall figure. This figure is not weighted with an arbitrary scoring system as it was in 1. Overall accuracy. The average protection levels afforded by the tested products, when exposed to the threats used in this test, was 87.5 per cent. Above average products included those from Symantec (Norton), Kaspersky, ESET, Avast! And G Data. Only one of these was free (Avast). Overall Protection Scores 40 30 20 10 0 The only free product that performed above average was Avast! Free AntiVirus 5. PC Anti-Virus Protection 2011 Page 5 of 60 OVERALL PROTECTION SCORES Product Protected Incidents Percentage of incidents Norton Internet Security 2011 40 100% Kaspersky Internet Security 2011 39 98% ESET Smart Security 4 38 95% Avast! Free AntiVirus 5 37 93% G Data InternetSecurity 2011 35 88% AVG Anti-Virus Free Edition 9 34 85% Trend Micro Internet Security 2010 34 85% Avira Personal - Free Antivirus 10 33 83% BitDefender Internet Security 2010 31 78% McAfee Internet Security 29 73% Microsoft Security Essentials 26 65% K7 Total Security 10 25 63% (Average: 87.5 per cent) PC Anti-Virus Protection 2011 Page 6 of 60 3. PROTECTION DETAILS The security products provided different levels of protection. When a product defended against a threat, it prevented the malware from gaining a foothold on the target system. A threat might have been able to infect the system and, in some cases, the product neutralized it later. When it couldn’t, the system was compromised. The graph below shows that the most successful products tended to defend, rather than neutralize, the threats. Between them the top five products only neutralized 11 threats, while they defended a total of 178. They were compromised 11 times. The five least effective products, on the other hand, neutralized 21 threats and defended just 123. They were compromised a total of 56 times. Protection Details 40 35 30 25 20 15 10 5 0 Target Compromised Target Neutralized Target Defended The most successful products tended to defend rather than neutralize, blocking the threats early in the attack. PC Anti-Virus Protection 2011 Page 7 of 60 PROTECTION DETAILS Product Target Defended Target Neutralized Target Compromised Norton Internet Security 2011 40 0 0 Kaspersky Internet Security 37 2 1 2011 ESET Smart Security 4 34 4 2 Avast! Free AntiVirus 5 35 2 3 G Data InternetSecurity 2011 32 3 5 AVG Anti-Virus Free Edition 23 11 6 9 Trend Micro Internet Security 23 11 6 2010 Avira Personal - Free 29 4 7 Antivirus 10 BitDefender Internet Security 29 2 9 2010 McAfee Internet Security 23 6 11 Microsoft Security Essentials 22 4 14 K7 Total Security 10 20 5 15 PC Anti-Virus Protection 2011 Page 8 of 60 P Whenlegitimate work properly. productneedstobeableprotectthesystem A security levels 4.1 Falsepositive 4. into twomaingroupsbecausetheprod The graph below includes the number and type and includesthenumber The graphbelow This