Menu
Microsoft vows to improve security suite after failed evaluation

Microsoft vows to improve security suite after failed evaluation

AV-Test.org failed the company again in another round of security software testing

Microsoft vowed on Wednesday to improve two of its security products after both failed to pass an evaluation by a Germany security software testing organization.

The company's Security Essentials and Forefront Endpoint Protection failed to earn a "certified" status in a latest round of testing by AV-Test to see how effective the products are against malicious software.

AV-Test, which conducts tests every two months at its laboratories in Magdeburg and Leipzig, also failed PC Tools' Internet Security 2012 and AhnLab's V3 Internet Security 8.0. In October, AV-Test failed to give Microsoft certified status for its Security Essentials versions 4.0 and 4.1.

Security software companies have often contested the conditions under which their products are examined by testing organizations following a poor rating, frequently arguing that testing parameters are flawed.

Joe Blackbird, a program manager in Microsoft's Malware Protection Center, softly contested AV-Test's methodology, which involves running the software security against a range of malware.

Blackbird wrote that Microsoft prioritizes how it provides protection based on the prevalence of threats. Many of the malware samples that AV-Test used were never encountered by millions of Microsoft systems, he wrote on a company blog.

In one example, Microsoft detected only 72 pieces of malware out of a sample of 100 pieces of zero-day malware, or attack code for which a detection signature has not been created yet.

But "we know from telemetry from hundreds of millions of systems around the world that 99.997 percent of our customers hit with any zero-day did not encounter the malware samples tested in this test," Blackbird wrote.

Microsoft did not detect about 9 percent of 216,000 pieces of "recent" malware in the AV-Test evaluation. But Blackbird wrote that 94 percent of missed samples were never encountered by the company's customers.

"When we explicitly looked for these files, we could not find them on our customers' machines," according to Blackbird.

Microsoft calculated that .0033 percent of its customers were impacted by malware that the company did not detect. But Blackbird noted that Microsoft had since added detection for some of those threats. Nonetheless, "we're committed to reducing our 0.0033 percent margin to zero," Blackbird wrote.

In December, Blackbird wrote that Microsoft processed 20 million new potentially malicious files. The company prioritizes how it blocks those threats, and added protection for four million of those.

"Those 4 million files could have been customer-impacting if we had not prioritized them appropriately," Blackbird wrote.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk

Follow Us

Join the ARN newsletter!

Error: Please check your email address.

Tags intrusionMicrosoftsecurityAV-TestExploits / vulnerabilities

Upcoming

Slideshows

IN PICTURES: VMworld 2015 Asia-Pacific and Japan party (+ 32 photos)

IN PICTURES: VMworld 2015 Asia-Pacific and Japan party (+ 32 photos)

VMware recently held an Asia-Pacific and Japan party for its partners in San Francisco following two days of keynotes and sessions. Whilst mingling and enjoying drinks and finger food, the partners were joined by VMware management who also took the opportunity to let their hair down to have some fun.

IN PICTURES: VMworld 2015 Asia-Pacific and Japan party (+ 32 photos)
IN PICTURES: VMworld 2015 sponsor and partner showcase (+41 photos)

IN PICTURES: VMworld 2015 sponsor and partner showcase (+41 photos)

VMware's sponsors and partners used the opportunity at VMworld 2015 to showcase some of their technologies. At an exhibition hall, these vendors educated those that popped by their stands on these solutions and addressed some of the issues surrounding mobility, datacentres, and the Cloud. SOme of the big names there included f5, Palo Alto Networks, HP, Intel, Samsung, and Symantec.

IN PICTURES: VMworld 2015 sponsor and partner showcase (+41 photos)
IN PICTURES: VMware's VMworld 2015 day 1 (+13 photos)

IN PICTURES: VMware's VMworld 2015 day 1 (+13 photos)

VMware has kicked off VMworld 2015 in San Francisco and the first day saw keynotes from its president and CEO, Carl Eschenbach; executive vice-president and general manager, Bill Fathers; and executive vice-president and general manager of SDDC, Raghu Raghuram; amongst others. VMware also made Cloud-related announcements and demonstrated its latest technology.

IN PICTURES: VMware's VMworld 2015 day 1 (+13 photos)

iasset.com is a channel management ecosystem that automates all major aspects of the entire sales, marketing and service process, including data tracking, integrated learning, knowledge management and product lifecycle management.

Show Comments