How we tested antimalware

Reviews
Sep 18, 20062 mins

Focusing on gateway products, we primarily looked for the ability to identify and block malware (such as keystroke loggers, browser hijackers, adware, rootkits, dialers, data miners and Trojans).

We collected a suite of 70 malware samples, and vendors gave us some additional samples to test with. We moved the collected material to an isolated, quarantined network. The quarantined network consisted of three subnets. Subnet 1 had 10 client machines with a variety of operating systems, including Windows NT, 98, 2000, ME, XP, Red Hat Linux and Macintosh OS X. Subnet 2 contained three Web servers (Microsoft IIS, Netscape Enterprise Server and Apache), three e-mail servers (Exchange, Notes and Sendmail), two file servers (Windows 2003 Advanced Server and Netware) and two database servers (Oracle 8i and Microsoft SQL Server).

Subnet 3, simulating the “Internet,” had Web, IM and Skype servers and clients containing the malware instances and sporting “bad guy” IP addresses and URLs. Systems on the first two subnets accessed the third subnet as if it were the real Internet.

To measure performance, we used two time-synchronized protocol analyzers on the Internet and local network sides of the gateway device and examined the resulting packet captures to know the time taken by a device to forward or discard each network message.

Each gateway product connected our simulated “Internet” to the other two subnets. Client and server machines started off in a pristine state for each test.

Our clients and servers attempted to download malware from the simulated “Internet.” We noted how well the products identified malware traffic and blocked attempts by the malware to send data back to the source. We gauged success or failure by examining each machine for malware after each test. We looked for running malware processes, new program files (EXE, DLL or OCX, possibly marked with the “Hidden” attribute) and directories as well as Registry and Start Menu changes.


Previous: Still no ‘malware’ definition | Next: FaceTime >