Igor Muttik and James Vignoles McAfee
download slides (PDF)
This presentation discusses several aspects related to testing the ability of security products to detect malware. The complexity of malware and of the security solutions go up really quickly and we present arguments as to why we believe that comprehensive QA is no longer viable and why a switch to a more statistical approach is in order.
We look into the problem of compiling a representative 'next-generation' sample test set:
We present a topological and percolation model of malware distribution and present arguments as to why the user profile should be part of the test.
We discuss potential solutions to QA problems: