Anti-Virus Comparative. Factsheet Business Test (August-September 2018) Last revision: 11 th October

Similar documents
Anti-Virus Comparative

RTTL Certification Test - March Language: English. March Last Revision: 8 th April

Performance Test. ESET Endpoint Security. Language: English September Last Revision: 14 th September

Symantec vs. Trend Micro Comparative Aug. 2009

Anti-Virus Comparative Summary Report 2008

Network Performance Test. Business Security Software. Language: English August Last Revision: 11 th October

Whole Product Dynamic Real-World Protection Test (July-November 2017)

Anti-Virus Comparative No.7

Anti-Virus Comparative No.8

Single Product Test. Superna Ransomware Test. Language: English June Last Revision: 4 th July

Anti-Virus Comparative

Anti-Virus Comparative No.1

Whole Product Dynamic Real-World Protection Test (July-November 2018)

Anti-Virus Comparative No.4

Anti-Virus Comparative

FILELESSMALW ARE PROTECTION TEST OCTOBER2017

ENTERPRISE ENDPOINT COMPARATIVE REPORT

AV-Comparatives. Support-Test (Germany) Test of German-Language Telephone Support Services for Windows Consumer Security Software 2016

Anti-Virus Comparative

Anti-Virus Comparative

Safe N Sec Enterprise Pro

MRG Effitas 360 Degree Assessment & Certification Q1 2018

Siemens Industrial SIMATIC. Process Control System PCS 7 Configuration Trend Micro OfficeScan Server XG. Security information 1.

MRG Effitas 360 Degree Assessment & Certification Q4 2017

Anti Virus Comparative Performance Test (Suite Products) May 2012

User Experience Review

Webroot SecureAnywhere Business Endpoint Protection

Single Product Review. escan Internet Security 11. Language: English September 2010 Last revision: 13 nd October

MRG Effitas 360 Assessment & Certification Programme Q4 2015

MRG Effitas Real Time Protection Test Project, First Quarter Q MRG Effitas Real Time Protection Test Project, First Quarter (Q2 2013)

PC SECURITY LABS COMPARATIVE TEST. Microsoft Office. Flash. August Remote code execution exploit. mitigations for popular applications

PassMark S O F T W A R E

JUNE Covering the global threat landscape. VB100 COMPARATIVE REVIEW JUNE 2017 Martijn Grooten

MRG Effitas 360 Degree Assessment & Certification Q MRG Effitas 360 Assessment & Certification Programme Q2 2017

Trend Micro OfficeScan XG

Security Industry Market Share Analysis

Free antivirus software download

Security Industry Market Share Analysis

OCTOBER Covering the global threat landscape VB100 CERTIFICATION REPORT OCTOBER 2018 INTRODUCTION DIVERSITY TEST PRODUCTS & RESULTS

IT Security Survey 2019

China Region Malware Test 2010 May

Avira Test Results 2013

CheckVir anti-virus testing and certification

FEBRUARY Covering the global threat landscape. VB100 COMPARATIVE REVIEW FEBRUARY 2018 Martijn Grooten INTRODUCTION RESULTS

Trend Micro. Apex One as a Service / Apex One. Best Practice Guide for Malware Protection. 1 Best Practice Guide Apex One as a Service / Apex Central

MRG Effitas Trapmine Exploit Test

How To Remove Internet Security Pro Virus. Manually >>>CLICK HERE<<<

protectiontestagainst ransomwarethreats

DECEMBER Covering the global threat landscape. VB100 CERTIFICATION REPORT DECEMBER 2018 Martijn Grooten INTRODUCTION DIVERSITY TEST

COMPARATIVE MALWARE PROTECTION ASSESSMENT

Securing the SMB Cloud Generation

Bitdefender GravityZone. Supreme protection against active threats for the SMB market

MRG Effitas Online Banking / Browser Security Assessment Project Q Results

Trend Micro SMB Endpoint Comparative Report Performed by AV-Test.org

Web Gateway Security Appliances for the Enterprise: Comparison of Malware Blocking Rates

IT Security Survey 2018

360 Degree Assessment & Certification

FEBRUARY Covering the global threat landscape VB100 CERTIFICATION REPORT FEBRUARY 2019 DIVERSITY TEST PRODUCTS & RESULTS THE VB100 SET-UP

JUNE Covering the global threat landscape VB100 CERTIFICATION REPORT JUNE 2018 INTRODUCTION DIVERSITY TEST THE VB100 SET-UP PRODUCTS & RESULTS

CONSUMER REPORT April - June 2016

MRG Effitas Online Banking Browser Security Assessment Project Q Q1 2014

MOST TESTED. MOST AWARDED. KASPERSKY LAB PROTECTION.*

KASPERSKY ENDPOINT SECURITY FOR BUSINESS

Trend Micro SMB Endpoint Comparative Report Performed by AV-Test.org

Discount Bitdefender Security for SharePoint website for free software ]

OUR CUSTOMER TERMS CLOUD SERVICES MCAFEE ENDPOINT PROTECTION ESSENTIAL FOR SMB

How To Remove Personal Antivirus Security Pro Virus

Corporate Product Review: ESET

ESAP Release Notes

PCSL. PCSL IT Consulting Institute. Windows Virus Cleaning Test Report 感染型病毒清除测试报告. Celebrating Technology Innovation

GFI MailSecurity 2011 for Exchange/SMTP. Administration & Configuration Manual

Home Anti-Virus Protection

Home Anti-Virus Protection

SE Labs Test Plan for Q Endpoint Protection : Enterprise, Small Business, and Consumer

How to Identify Advanced Persistent, Targeted Malware Threats with Multidimensional Analysis

BREACH DETECTION SYSTEMS COMPARATIVE ANALYSIS

HOME ANTI- MALWARE PROTECTION

360 Degree Assessment & Certification

Transparency report. Examining the AV-TEST January-February 2018 Results. Prepared by. Windows Defender Research team

Home Anti-Virus Protection

Symantec Antivirus Manual Removal Tool Corporate Edition 10.x

Maximum Security with Minimum Impact : Going Beyond Next Gen

Home Anti-Virus Protection

Annexure E Technical Bid Format

Webroot SecureAnywhere AntiVirus (2015)

ESAP. Release Notes Build. Oct Published. Document Version

SKD Labs Test Report. A Comparative Test on Anti-Malware Products in the China Region

ESAP. Release Notes. Release, Build Published Document Version December

ESAP. Release Notes. Release, Build Published Document Version February

How to Configure ATP in the HTTP Proxy

CONSUMER AV / EPP COMPARATIVE ANALYSIS

Android Malware Detection Test 手机安全软件病毒检测率测试 Mar. Celebrating Technology Innovation

ESAP. Release Notes. Release, Build Published Document Version November

Presentation by Brett Meyer

Trend Micro OfficeScan Client User Guide

GFI product comparison: GFI MailEssentials vs. Trend Micro ScanMail Suite for Microsoft Exchange

Free antivirus software download windows 10

Manually Remove Of Xp Internet Security Protect

Firewall Antivirus For Windows Xp Full Version 2013

Home Anti-Virus Protection

Transcription:

Anti-Virus Comparative Factsheet Business Test Language: English August-September 2018 Last revision: 11 th October 2018 https:// - 1 -

Introduction This is a short fact sheet for our Business Main-Test Series 1, containing the results of the Business Malware Protection Test (September) and Business Real-World Protection Test (August-September). The full report, including the Performance Test and product reviews, will be released in December. To be certified in December as an Approved Business Product by AV-Comparatives, the tested products must score at least 90% in the Malware Protection Test, and at least 90% in the overall Real-World Protection Test (i.e. over the course of 4 months), with zero false alarms on common business software. Tested products must also avoid major performance issues and have fixed all reported bugs in order to gain certification. Tested Products The following products 2 were tested under Windows 10 RS4 64-bit: Vendor Product Version August Version September Avast Business Antivirus Pro Plus 18.5 18.5 Bitdefender Endpoint Security Elite (GravityZone Elite HD) 6.6 6.6 CrowdStrike Endpoint Protection Platform Standard Bundle 4.10 4.11 Emsisoft Anti-Malware & Enterprise Console 2018.7 2018.8 Endgame Endpoint Protection Platform 3.0 3.0 escan Corporate 360 with MDM & Hybrid Network Support 14.0 14.0 ESET Endpoint Security & Remote Administrator 6.6 6.6 FireEye Endpoint Security 4.5 4.5 Fortinet FortiClient with EMS & FortiSandbox 6.0 6.0 Kaspersky Lab Endpoint Security for Business Select 11.0 11.0 McAfee Endpoint Security with ATP and epo Cloud 10.5 10.5 Microsoft Windows Defender for Business with Intune 4.18 4.18 Panda Endpoint Protection Plus on Aether 7.90 7.90 Saint Security MAX Antivirus 1.0 1.0 Trend Micro OfficeScan XG 12.0 12.0 VIPRE Endpoint Security Cloud 10.3 10.3 1 Please note that the results of the Business Main-Test Series cannot be compared with the results of the Consumer Main-Test Series, as the tests are done at different times, with different sets, different settings, etc. 2 Information about additional third-party engines/signatures used by some of the products: Emsisoft, escan, FireEye and VIPRE use the Bitdefender engine. - 2 -

Settings In business environments, and with business products in general, it is usual for products to be configured by the system administrator, in accordance with vendor s guidelines, and so we allowed all vendors to configure their respective products. About half of the vendors provide their products with optimal default settings which are ready to use, and did therefore not change any settings. Cloud and PUA 3 detection have been activated in all products. Below we have listed deviations from default settings (i.e. setting changes applied by the vendors): Bitdefender: HyperDetect disabled, Sandbox enabled. CrowdStrike: everything enabled and set to maximum, i.e. Extra Aggressive. Endgame: Enabled Software and Hardware protection options: Critical API Filtering, Header Protection, Malicious Macros, Stack Memory, Stack Pivot and UNC Path ; Protected Applications: Browser, Microsoft Suite, Java and Adobe. Exploit Protection: On Prevent mode ; Malicious File Configuration: On Protection at File Execution On ; Options: Prevent, Process execution and loaded modules, Malware Detection for created and modified files On ; Aggressive threshold. FireEye: Real-Time Indicator Detection disabled, Exploit Guard and Malware Protection enabled. Fortinet: Real-Time protection, FortiSandbox, Webfilter and Application Firewall (in order to use Detect & Block Exploits) enabled. McAfee: Email attachment scanning enabled; Real Protect enabled and set to high sensitivity, read/write scan of Shadow Copy Volumes disabled. Microsoft: Cloud protection level set to High. Trend Micro: Behaviour monitoring: Monitor news encountered programs downloaded through web enabled; Certified Safe Software Service for Behaviour monitoring enabled; Smart Protection Service Proxy enabled; Use HTTPS for scan queries enabled; Web Reputation Security Level set to Medium; Send queries to Smart Protection Servers disabled; Block pages containing malicious script enabled; Real-Time Scan set to scan All scannable files, Scan compressed files to Maximum layers 6 ; CVE exploit scanning for downloaded files enabled; ActiveAction for probable virus/malware set to Quarantine; Cleanup type set to Advanced cleanup and Run cleanup when probable virus/malware is detected enabled; Block processes commonly associated with ransomware enabled; Anti-Exploit Protection enabled; all Suspicious Connection Settings enabled and set to Block. Avast, Emsisoft, escan, ESET, Kaspersky Lab, Panda, Saint Security, VIPRE: default settings. 3 We currently do not include any PUA in our malware tests. - 3 -

Results Real-World Protection Test (August-September) This fact sheet 4 gives a brief overview of the results of the Business Real-World Protection Test run in August and September 2018. The overall business product reports (each covering four months) will be released in July and December. For more information about this Real-World Protection Test, please read the details available at https://. The results are based on a test set consisting of 599 test cases (such as malicious URLs), tested from the beginning of August till the end of September. Blocked User Compromised PROTECTION RATE False dependent [Blocked % + (User dependent %)/2] 5 Alarms Bitdefender, Kaspersky Lab 599 - - 100% 0 VIPRE 598-1 99.8% 0 Trend Micro 598-1 99.8% 22 Microsoft 597 2-99.8% 38 McAfee 597-2 99.7% 4 Avast 596-3 99.5% 0 FireEye 595-4 99.3% 0 CrowdStrike 595-4 99.3% 1 Panda 595-4 99.3% 4 Endgame 592-7 98.8% 1 ESET 591-8 98.7% 1 escan 590-9 98.5% 2 Emsisoft 589-10 98.3% 0 Fortinet 578-21 96.5% 1 Saint Security 449-150 75.0% 0 4 The full report will be released in December. 5 User-dependent cases are given half credit. For example, if a program blocks 80% by itself, and another 20% of cases are user-dependent, we give half credit for the 20%, i.e. 10%, so it gets 90% altogether. - 4 -

Malware Protection Test The Malware Protection Test assesses a security program s ability to protect a system against infection by malicious files before, during or after execution. The methodology used for each product tested is as follows. Prior to execution, all the test samples are subjected to on-access scans (if this feature is available) by the security program (e.g. while copying the files over the network or from a USB device, or saving from webmail). Any samples that have not been detected by the on-access scanner are then executed on the test system, with Internet/cloud access available, to allow e.g. behavioural detection features to come into play. If a product does not prevent or reverse all the changes made by a particular malware sample within a given time period, that test case is considered to be a miss. For this test, 1,556 recent malware samples were used. False positive (false alarm) test with common business software A false alarm test done with common business software was also performed. As expected, all the tested products had zero false alarms on common business software. The following chart shows the results of the Business Malware Protection Test: - 5 -

Malware Protection Rate False Alarms on common business software Avast, Bitdefender, Emsisoft, McAfee, Trend Micro, VIPRE 100% 0 CrowdStrike, ESET, Microsoft, Panda 99.9% 0 Kaspersky Lab 99.8% 0 FireEye 99.7% 0 escan 99.6% 0 Fortinet 99.5% 0 Endgame 98.8% 0 Saint Security 94.0% 0 In order to better evaluate the products detection accuracy and file detection capabilities (ability to distinguish good files from malicious files), we also performed a false alarm test on non-business software and uncommon files. This is provided mainly just as additional information, especially for organisations which often use uncommon non-business software or their own self-developed software. The results do not affect the overall test score or the Approved Business Product award. The false alarms found were promptly fixed by the respective vendors. FP rate Number of FPs on non-business software Very low 0-10 Low 11 50 High 51 100 Very high 101-500 Remarkably high > 500 FP rate on non-business software Avast, Bitdefender, Emsisoft, Endgame, ESET, Very low FireEye, Fortinet, Kaspersky Lab, Saint Security CrowdStrike, escan, McAfee, Microsoft, Panda, Low Trend Micro, VIPRE - High - Very high - Remarkably high - 6 -

Copyright and Disclaimer This publication is Copyright 2018 by AV-Comparatives. Any use of the results, etc. in whole or in part, is ONLY permitted with the explicit written agreement of the management board of AV- Comparatives, prior to any publication. This report is supported by the participants. AV-Comparatives and its testers cannot be held liable for any damage or loss which might occur as a result of, or in connection with, the use of the information provided in this paper. We take every possible care to ensure the correctness of the basic data, but liability for the correctness of the test results cannot be taken by any representative of AV-Comparatives. We do not give any guarantee of the correctness, completeness, or suitability for a specific purpose of any of the information/content provided at any given time. No-one else involved in creating, producing or delivering test results shall be liable for any indirect, special or consequential damage, or loss of profits, arising out of, or related to, the use (or inability to use), the services provided by the website, test documents or any related data. For more information about AV-Comparatives and the testing methodologies please visit our website. AV-Comparatives (October 2018) - 7 -