issue85:securite
Différences
Ci-dessous, les différences entre deux révisions de la page.
Les deux révisions précédentesRévision précédenteProchaine révision | Révision précédente | ||
issue85:securite [2014/12/04 21:05] – d52fr | issue85:securite [2014/12/05 17:17] (Version actuelle) – auntiee | ||
---|---|---|---|
Ligne 5: | Ligne 5: | ||
De Brian Hall : | De Brian Hall : | ||
- | Même après avoir essayé de chercher de l' | + | Même après avoir essayé de chercher de l' |
+ | |||
+ | MB : La question est intéressante à plusieurs titres : nous les humains nous aimons comparer les produits. Après, nous essayons de prendre une décision sur le meilleur choix pour nous. Dans le cas des outils de détection des logiciels malveillants, | ||
**In case of anti-virus tools, it’s important to consider the threats you are trying to protect against. If the tool is used for scanning a mail server, each intercepted e-mail with malware is a win. Ones that are not picked up, well, end up in the user’s mailbox, and hopefully don’t get opened, or are properly detected by a local on-access virus scanner. In the case of an on-access scanner for surfing the web, you’d rather have a much higher detection rate. | **In case of anti-virus tools, it’s important to consider the threats you are trying to protect against. If the tool is used for scanning a mail server, each intercepted e-mail with malware is a win. Ones that are not picked up, well, end up in the user’s mailbox, and hopefully don’t get opened, or are properly detected by a local on-access virus scanner. In the case of an on-access scanner for surfing the web, you’d rather have a much higher detection rate. | ||
Back to ClamAV.. ClamAV uses a core database, with a daily addition to it. This smaller daily database (daily.cvd) is regularly updated during the day. However, that doesn’t say much about the detection rate. This is where professional comparison tests come into play. Unfortunately ClamAV often is not included in tests, because it’s not commercial or not focused mainly on Windows.** | Back to ClamAV.. ClamAV uses a core database, with a daily addition to it. This smaller daily database (daily.cvd) is regularly updated during the day. However, that doesn’t say much about the detection rate. This is where professional comparison tests come into play. Unfortunately ClamAV often is not included in tests, because it’s not commercial or not focused mainly on Windows.** | ||
+ | |||
+ | Dans le cas d' | ||
+ | |||
+ | Retour sur Clamav... Clamav utilise une base de données principale, complétée quotidiennement. Cette plus petite base de données quotidienne (daily.cvd) est régulièrement mise à jour dans la journée. Cependant, ça ne renseigne pas beaucoup sur le taux de détection. C'est là que les tests comparatifs professionnels entrent en jeu. Malheureusement, | ||
**However, there is no need to think ClamAV is not good due to lack of evidence. Because the project is community driven, and many people provide samples they discover, it shouldn’t take long for ClamAV to protect against new threats. Sometimes this occurs because another malware tool (correctly) discovered a new threat. Other vendors, including ClamAV, then include a signature to their database as well. | **However, there is no need to think ClamAV is not good due to lack of evidence. Because the project is community driven, and many people provide samples they discover, it shouldn’t take long for ClamAV to protect against new threats. Sometimes this occurs because another malware tool (correctly) discovered a new threat. Other vendors, including ClamAV, then include a signature to their database as well. | ||
One of the best examples for “community driven malware detection”, | One of the best examples for “community driven malware detection”, | ||
+ | |||
+ | Cependant, il n'est pas nécessaire de penser, par manque de preuves, que Clamav n'est pas bon. Parce que c'est un projet communautaire, | ||
+ | |||
+ | Le site VirusTotal est un des meilleurs exemples pour la « détection de logiciels malveillants piloté par une communauté ». Tous les exemples sont analysés et les résultats sont partagés entre tous les distributeurs participants. Aussi, si vous découvrez un échantillon de logiciel malveillant et le téléversez, | ||
**Even if the ClamAV database is less comprehensive than from other vendors, it depends on your use of the tool. With information security, we should never rely on just a single defense, but build a fortress of layers. Using a community driven tool is just one of the possible layers we could add. From my personal experience, I can tell it helped many of my customers and their mailboxes. I’m sure it didn’t detect every threat, but no single other software tool would be able to do that either.** | **Even if the ClamAV database is less comprehensive than from other vendors, it depends on your use of the tool. With information security, we should never rely on just a single defense, but build a fortress of layers. Using a community driven tool is just one of the possible layers we could add. From my personal experience, I can tell it helped many of my customers and their mailboxes. I’m sure it didn’t detect every threat, but no single other software tool would be able to do that either.** | ||
+ | |||
+ | Même si la base de données Clamav est moins complète que celles d' |
issue85/securite.1417723507.txt.gz · Dernière modification : 2014/12/04 21:05 de d52fr