Q3 Consumer Endpoint Protection Jul-Sep 2020
Total Page:16
File Type:pdf, Size:1020Kb
HOME ANTI- MALWARE PROTECTION JUL - SEP 2020 selabs.uk [email protected] @SELabsUK www.facebook.com/selabsuk blog.selabs.uk SE Labs tested a variety of anti-malware (aka ‘anti-virus’; aka ‘endpoint security’) products from a range of well-known vendors in an effort to judge which were the most effective. Each product was exposed to the same threats, which were a mixture of targeted attacks using well-established techniques and public email and web-based threats that were found to be live on the internet at the time of the test. The results indicate how effectively the products were at detecting and/or protecting against those threats in real time. 2 Home Anti-Malware Protection July - September 2020 MANAGEMENT Chief Executive Officer Simon Edwards CONTENTS Chief Operations Officer Marc Briggs Chief Human Resources Officer Magdalena Jurenko Chief Technical Officer Stefan Dumitrascu Introduction 04 TEstING TEAM Executive Summary 05 Nikki Albesa Zaynab Bawa 1. Total Accuracy Ratings 06 Thomas Bean Solandra Brewster Home Anti-Malware Protection Awards 07 Liam Fisher Gia Gorbold Joseph Pike 2. Threat Responses 08 Dave Togneri Jake Warren 3. Protection Ratings 10 Stephen Withey 4. Protection Scores 12 IT SUPPORT Danny King-Smith 5. Protection Details 13 Chris Short 6. Legitimate Software Ratings 14 PUBLICatION Sara Claridge 6.1 Interaction Ratings 15 Colin Mackleworth 6.2 Prevalence Ratings 16 Website selabs.uk Twitter @SELabsUK 6.3 Accuracy Ratings 16 Email [email protected] Facebook www.facebook.com/selabsuk 6.4 Distribution of Impact Categories 17 Blog blog.selabs.uk Phone +44 (0)203 875 5000 7. Conclusions 17 Post SE Labs Ltd, 55A High Street, Wimbledon, SW19 5BA, UK Appendix A: Terms Used 18 SE Labs is ISO/IEC 27001 : 2013 certified and Appendix B: FAQs 18 BS EN ISO 9001 : 2015 certified for The Provision of IT Security Product Testing. Appendix C: Product Versions 19 SE Labs is a member of the Microsoft Virus Information Alliance (VIA); the Anti-Malware Testing Standards Appendix D: Attack Types 20 Organization (AMTSO); and the Messaging, Malware and Mobile Anti-Abuse Working Group (M3AAWG). AMTSO Standard Reference: selabs.uk/amtso20q3 Document version 1.0 Written 15th October 2020; 1.1 Updated ESET results © 2020 SE Labs Ltd 1.2 Corrected results 26th October 2020 3 Home Anti-Malware Protection July - September 2020 INTRODUCTION Hands up, who’s been hacked? Get ahead in the game that never ends Have you ever been hacked? You, personally, or your business? If your a number of times on the have i been pwned website, too. So clearly answer is, “no” it would be interesting to know how you can be so sure. other companies with my personal data have been hacked too. I once spoke to a marketing manager at a global anti-malware company Game of Threats who claimed that his PC had never been infected by malware, despite him I’ve nearly fallen foul of SMS phishing at least once this year, and only not using anti-virus. How would he know? Not all malware announces its failed to enter my credit card details because I didn’t have my wallet presence as clearly as, say ransomware. “I just would,” he claimed. with me at the time. I’m looking out for this stuff and I still get tricked if you catch me on an off day. The general public will be falling for these Why does it matter? tricks all the time. The proof is that attackers are running the same Years later I asked a management team at a very large media company if scams over and over again. they had ever been breached. The head of IT claimed not. Definitely not. His lower-ranking colleague more realistically said, “probably” while the Keeping your wits about you is essential, but you can’t do it all on your own. CFO responded with, “does it matter?” That’s why a good (anti-malware) endpoint protection solution is an essential basis for your online protection. I hope this report helps you or Companies and individuals sometimes think that they don’t have anything your business get ahead in the game that never ends. valuable of interest to attackers. But if your business holds any personal details of staff or customers then being breached can bring heavy fines. If you spot a detail in this report that you don’t understand, or would like And if your personal PC is hacked, you can expect at best inconvenience to discuss, please contact us via our Twitter or Facebook accounts. SE Labs as your computer misbehaves and shows you annoying adverts, and at uses current threat intelligence to make our tests as realistic as possible. worst what amounts to a bank robbery that will have your bank looking at To learn more about how we test, how we define ‘threat intelligence’ and you with considerable suspicion. how we use it to improve our tests please visit our website and follow us on Twitter. I have personally been hacked (at least) twice. I’m certain of this because in the first case I could see abnormal amounts of network traffic leaving This test report was funded by post-test consultation services provided by my system and, because I am familiar with how computers work under the SE Labs to security vendors. Vendors of all products included in this report hood, I was then able to spot the rootkit that was hiding on my Linux server. were able to request early access to results and the ability to dispute details Yes, there is malware for Linux, despite what you might have heard. for free. SE Labs has submitted the testing process behind this report for compliance with the AMTSO Testing Protocol Standard v1.3. To verify its The second time was less direct, and I only found out that my British Airways compliance please check the AMTSO reference link at the bottom of page account had been breached when I tried to use it. My personal email is found three of this report or here. 4 Home Anti-Malware Protection July - September 2020 Executive Summary Product Names It is good practice to stay up to date with the latest version of your chosen endpoint ● The security software products were generally effective security product. We made best efforts to ensure that each product tested was the very at handling general threats from cyber criminals… latest version running with the most recent updates to give the best possible outcome. Most products were largely capable of handling public web-based threats such as those used by criminals to For specific build numbers, see Appendix C: Product Versions on page 19. attack Windows PCs, tricking users into running malicious files or running scripts that download and run malicious files. But only one was completely effective. ● .. and targeted attacks were prevented in most cases. EXECUTIVE SUMMARY All but one of the products were competent at blocking more targeted, exploit-based attacks. This was an unusually strong Protection Accuracy Legitimate Accuracy Total Accuracy Products Tested Rating (%) Rating (%) Rating (%) result for the vendors involved. However, one was less than Kaspersky Internet Security 100% 100% 100% 50 per cent effective in this area. ESET Internet Security 97% 100% 99% Avast Free Antivirus 97% 99% 98% ● False positives were not a serious issue for most products. AVG Antivirus Free Edition 96% 99% 98% Most of the products were good at correctly classifying McAfee Internet Security 95% 100% 98% legitimate applications and websites. The majority made at least one mistake, though. Trend Micro Internet Security 96% 99% 98% Avira Free Security Suite 90% 100% 97% ● Which products were the most effective? Microsoft Defender Antivirus (consumer) 91% 100% 97% Kaspersky’s product extremely good results due to a Norton LifeLock Security 96% 97% 97% combination of its ability to block malicious URLs, handle F-Secure Safe 90% 97% 95% exploits and correctly classify legitimate applications and Comodo Internet Security 83% 98% 93% websites. Others from ESET, Avast, AVG, McAfee and Trend Sophos Home Premium 88% 96% 93% Micro were also exceptional. Webroot Antivirus 89% 95% 93% Malwarebytes Premium 49% 94% 78% Products highlighted in green were the most accurate, scoring 85 per cent or more for Total Accuracy. Those in yellow scored less than 85 but 75 or more. Products shown in red scored less than 75 per cent. For exact percentages, see 1. Total Accuracy Ratings on page 6. 5 Home Anti-Malware Protection July - September 2020 1. Total Accuracy Ratings TOtaL ACCURACY RATINGS Judging the effectiveness of an endpoint security Product Total Accuracy Rating Total Accuracy (%) Award product is a subtle art, and many factors are at play Kaspersky Internet Security 1,146 100% AAA when assessing how well it performs. To make things ESET Internet Security 1,135 99% AAA McAfee Internet Security 1,125 98% AAA easier we’ve combined all the different results from this Avast Free Antivirus 1,124 98% AAA report into one easy-to-understand graph. Trend Micro Internet Security 1,123 98% AAA AVG Antivirus Free Edition 1,120 98% AAA The graph below takes into account not only each Microsoft Defender Antivirus (consumer) 1,109 97% AAA product’s ability to detect and protect against threats, Avira Free Security Suite 1,108 97% AAA but also its handling of non-malicious objects such as Norton LifeLock Security 1,106.5 97% AAA web addresses (URLs) and applications. F-Secure Safe 1,088 95% AAA Webroot Antivirus 1,067 93% AA Not all protections, or detections for that matter, are Sophos Home Premium 1,065 93% AA equal.