Prevx Malware Research and Competitive Detection Analysis
We take each sample that we have already determined as spyware or malware and scan it with up to date versions of the security products from the top 5 security vendors to measure their ability to detect it. At the end of each day we summarize the number of samples tested and show the results of each product's detection on the graph displayed on our home page.
Would you like access to our daily statistics?
Since July 2007, we have offered free access to the details behind our daily graphs shown on our home page. We offer this feature to our competitors, IT Security Professionals, Industry Analysts and large enterprises with significant security operations. This free access allows you to see the details on each sample used in the test, including specific results of the detection by each of the top five vendors. You can also run daily comparisons of any two products for any day since July 2007. The charts even provide you with access to the real time scores of today's samples that will be used to generate tomorrow's home page report.
To gain access to this feature please register with the simple form below:
Interpreting The Home Page Analysis
We display this information to heighten awareness of the sheer volume of new spyware and malware infections which are undetected by major security products every day. The chart is a measure of each products' ability to detect new threats first seen by Prevx in the preceeding 24 hours. So what can we learn from this analysis?
On average the chart shows an analysis of somewhere between 1,200 and 2,500 new samples every day. We could use every new malicious sample but this would be both misleading and unfair. We deliberately filter out from our tests unusually high volumes of samples for any particular malware family, for example a polymorphic worm which might create thousands of unique copies of the infection.
Taking the information literally it is hard to conclude that any end-point security product from the top five vendors can offer anything close to total protection from these threats. Ignoring the fact that these were Prevx collected samples the comparison of each vendor's detections with the other four highlights huge differences in detections. Even if all of these products were to be used to protect one PC at the same time they would fail to detect more than 90% of the new threats. Why is this?
Malware has evolved massively over the last 3 years. In contrast, security technologies have evolved at a much slower pace. We are moving to a world where each new infection will be by a unique program custom built to each PC it infects. As this trend gathers momentum the volumes of unique malware samples that security vendors need to analyse increases geometrically while the protection created by determining each sample diminishes. It is possible that the sample will never be seen again and consequently that any signature protection developed from it will have zero benefit.
Automated Malware Research
Our malware research center processes information on more than 250,000 new software programs every day. Fortunately, many of these, about 40%, are totally safe. However, about 4% of these programs, some 10,000 are added to our spyware and malware list based on our observations of their behavior. The rest, more than 50% continue to be monitored going forward, but are probably benign and have little identifiable behavior.
Our products and services are a direct reflection of our automated malware research capabilities. Our end-point detection, remediation and protection products all feed our malware research with valuable information and in return they offer better detection, remediation and protection. We are the only security vendor to work in this way.
More than 5,000 new spyware and malware samples every day
Our research shows that there are more than 5,000 new spyware or malware programs infecting PCs every day and this number is increasing day after day.
20,000 new Prevx CSI users feeding our database every day
Some twenty thousand or more new Prevx users download and run our FREE CSI malware scanner every day. Prevx CSI checks their PCs for active spyware and malware infections and feeds our database with information regarding new and prevalent threats. As part of this process we collect samples of several thousand new infections every day. We add detection and protection for these instantly.
Measuring Other Products' Detections
We take each sample that we have already determined as spyware or malware and scan it with up to date versions of the security products from the top 5 security vendors to measure their ability to detect it. At the end of each day we summarize the number of samples tested and show the results of each product's detection on the graph displayed on our home page.
