<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>amtso</title>
	<atom:link href="http://amtso.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://amtso.wordpress.com</link>
	<description>The Anti-Malware Testing Standards Organization Blog</description>
	<lastBuildDate>Mon, 09 Jan 2012 13:03:01 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='amtso.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>amtso</title>
		<link>http://amtso.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://amtso.wordpress.com/osd.xml" title="amtso" />
	<atom:link rel='hub' href='http://amtso.wordpress.com/?pushpress=hub'/>
		<item>
		<title>San Mateo meeting</title>
		<link>http://amtso.wordpress.com/2012/01/09/san-mateo-meeting-2/</link>
		<comments>http://amtso.wordpress.com/2012/01/09/san-mateo-meeting-2/#comments</comments>
		<pubDate>Mon, 09 Jan 2012 13:02:58 +0000</pubDate>
		<dc:creator>amtso</dc:creator>
				<category><![CDATA[Agenda]]></category>
		<category><![CDATA[AMTSO Workshop]]></category>
		<category><![CDATA[Anti-Malware Testing Standards Organization]]></category>
		<category><![CDATA[Events]]></category>
		<category><![CDATA[forum]]></category>

		<guid isPermaLink="false">http://amtso.wordpress.com/?p=940</guid>
		<description><![CDATA[Now that the holidays are well and truly behind us, can we remind you that the next AMTSO workshop takes place in San Mateo on the 23rd and 24th February, just before the start of the RSA Conference? Details of the agenda and how to book the hotel at the discounted rate are available on [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=amtso.wordpress.com&amp;blog=10885805&amp;post=940&amp;subd=amtso&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Now that the holidays are well and truly behind us, can we remind you that the next AMTSO workshop takes place in San Mateo on the 23rd and 24th February, just before the start of the RSA Conference?</p>
<p>Details of the agenda and how to book the hotel at the discounted rate are available on the <a href="http://www.amtso.org" target="_blank">AMTSO website</a> in the forum.</p>
<p><strong>AMTSO Board</strong></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/amtso.wordpress.com/940/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/amtso.wordpress.com/940/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/amtso.wordpress.com/940/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/amtso.wordpress.com/940/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/amtso.wordpress.com/940/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/amtso.wordpress.com/940/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/amtso.wordpress.com/940/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/amtso.wordpress.com/940/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/amtso.wordpress.com/940/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/amtso.wordpress.com/940/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/amtso.wordpress.com/940/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/amtso.wordpress.com/940/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/amtso.wordpress.com/940/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/amtso.wordpress.com/940/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=amtso.wordpress.com&amp;blog=10885805&amp;post=940&amp;subd=amtso&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://amtso.wordpress.com/2012/01/09/san-mateo-meeting-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/f8ef0ea742898607a61879509eb7e824?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">amtso</media:title>
		</media:content>
	</item>
		<item>
		<title>FAQs from Dennis Labs</title>
		<link>http://amtso.wordpress.com/2011/12/02/faqs-from-dennis-labs/</link>
		<comments>http://amtso.wordpress.com/2011/12/02/faqs-from-dennis-labs/#comments</comments>
		<pubDate>Fri, 02 Dec 2011 17:31:48 +0000</pubDate>
		<dc:creator>David Harley</dc:creator>
				<category><![CDATA[AMTSO blog]]></category>
		<category><![CDATA[David Harley]]></category>
		<category><![CDATA[Dennis Technology Labs]]></category>
		<category><![CDATA[Simon Edwards]]></category>
		<category><![CDATA[test news]]></category>
		<category><![CDATA[SC Magazine]]></category>

		<guid isPermaLink="false">http://amtso.wordpress.com/?p=935</guid>
		<description><![CDATA[It&#8217;s been a slow few weeks in the world of AV testing, news-wise, though I&#8217;ve just contributed a fairly hefty article on AMTSO to Elsevier for one of their periodicals that will hopefully appear in the New Year. (The article, that is: I&#8217;m sure the periodical will.) However, Simon Edwards has put up an article on [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=amtso.wordpress.com&amp;blog=10885805&amp;post=935&amp;subd=amtso&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s been a slow few weeks in the world of AV testing, news-wise, though I&#8217;ve just contributed a fairly hefty article on AMTSO to Elsevier for one of their periodicals that will hopefully appear in the New Year. (The article, that is: I&#8217;m sure the periodical will.)</p>
<p>However, Simon Edwards has put up an <a href="http://simonedwards.blogspot.com/2011/11/anti-malware-testing-behind-scenes.html" target="_blank">article on his own blog</a> that I can commend to anyone with an interest in product testing. I&#8217;ve already commented at some length in an <a href="http://www.scmagazineus.com/product-testing-and-accountability/article/217937/" target="_blank">SC Magazine article</a>.</p>
<p>I&#8217;m also hoping to prevail upon Simon, who represents his company in AMTSO, to blog here from time to time. It would be good to have someone from the testing side putting their point of view here&#8230;</p>
<p><strong>David Harley CITP FBCS CISSP</strong><br />
<strong>ESET Senior Research Fellow</strong></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/amtso.wordpress.com/935/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/amtso.wordpress.com/935/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/amtso.wordpress.com/935/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/amtso.wordpress.com/935/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/amtso.wordpress.com/935/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/amtso.wordpress.com/935/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/amtso.wordpress.com/935/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/amtso.wordpress.com/935/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/amtso.wordpress.com/935/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/amtso.wordpress.com/935/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/amtso.wordpress.com/935/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/amtso.wordpress.com/935/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/amtso.wordpress.com/935/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/amtso.wordpress.com/935/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=amtso.wordpress.com&amp;blog=10885805&amp;post=935&amp;subd=amtso&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://amtso.wordpress.com/2011/12/02/faqs-from-dennis-labs/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/87a00d996b23fce4539dbdd792cc5d13?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">dharley</media:title>
		</media:content>
	</item>
		<item>
		<title>AV-Test looks at free Android AV</title>
		<link>http://amtso.wordpress.com/2011/11/14/av-test-look-at-free-android-av/</link>
		<comments>http://amtso.wordpress.com/2011/11/14/av-test-look-at-free-android-av/#comments</comments>
		<pubDate>Mon, 14 Nov 2011 15:09:13 +0000</pubDate>
		<dc:creator>David Harley</dc:creator>
				<category><![CDATA[Andreas Marx]]></category>
		<category><![CDATA[AV-Test]]></category>
		<category><![CDATA[David Harley]]></category>
		<category><![CDATA[F-Secure]]></category>
		<category><![CDATA[Kaspersky]]></category>
		<category><![CDATA[mobile security]]></category>
		<category><![CDATA[Neil Rubenking]]></category>

		<guid isPermaLink="false">http://amtso.wordpress.com/?p=918</guid>
		<description><![CDATA[Well-known testers AV-Test recently looked at free AV apps for Android devices. They used a Samsung GalaxyTab GT-P1010 (Android vs. 2.2.1) as a testbed, testing both on-demand and on-access scanning, and using commercial scanners by F-Secure and Kaspersky for comparison. The commercial scanners did a lot better in the on-demand scanning tests (more than 50% detected) against [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=amtso.wordpress.com&amp;blog=10885805&amp;post=918&amp;subd=amtso&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Well-known testers AV-Test <a href="http://www.av-test.org/fileadmin/pdf/avtest_2011-11_free_android_virus_scanner_english.pdf" target="_blank">recently looked at</a> free AV apps for Android devices. They used a Samsung GalaxyTab GT-P1010 (Android vs. 2.2.1) as a testbed, testing both on-demand and on-access scanning, and using commercial scanners by F-Secure and Kaspersky for comparison.</p>
<p>The commercial scanners did a lot better in the on-demand scanning tests (more than 50% detected) against 32% by the best-performing free app and 6% and 1% respectively by the 2nd and 3rd ranked apps. Three other scanners scored zero in the on-demand tests. However, AV-Test did note that some scanners (which was not specified) only scan installed apps, which to me says that static testing of inactive products on an SD card is potentially misleading unless you assume that static scanning on removable media is sine qua non. That&#8217;s probably a debate for another time.</p>
<p>In the on-access (0n-installation) test, F-Secure and Kaspersky scored 100%. Since the test set was ten of the apps most often diagnosed as malicious by the scanners used by AV-Test for validating its Android sample collection, it would probably be somewhat disappointing if they didn&#8217;t. Still, the real shocker here is that while the app that did best in the static test scored 8/10, three of the others only detected 1/10, while the others didn&#8217;t detect any.</p>
<p>Here&#8217;s food for thought. The app with the <a href="http://securitywatch.pcmag.com/security-software/290411-report-most-free-android-antivirus-apps-useless#fbid=aI6jsPicLJp" target="_blank">largest user base</a> (1- 5 million) scored zero in both tests. Given the steady increase in malicious Android apps (the static test used 172 samples, none more than five months old), it might be time for Android users to consider whether they can afford to use a free AV app, or whether they might at least need to see how well their favoured product does in comparative tests. Andreas Marx told <a href="http://www.theregister.co.uk/2011/11/14/android_anti_virus/" target="_blank">The Register</a> that AV-Test will be running further tests of this sort, and I know that other testing and certification agencies are also looking at mobile security testing.</p>
<p><strong>David Harley CITP FBCS CISSP</strong><br />
<strong>ESET Senior Research Fellow</strong></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/amtso.wordpress.com/918/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/amtso.wordpress.com/918/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/amtso.wordpress.com/918/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/amtso.wordpress.com/918/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/amtso.wordpress.com/918/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/amtso.wordpress.com/918/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/amtso.wordpress.com/918/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/amtso.wordpress.com/918/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/amtso.wordpress.com/918/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/amtso.wordpress.com/918/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/amtso.wordpress.com/918/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/amtso.wordpress.com/918/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/amtso.wordpress.com/918/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/amtso.wordpress.com/918/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=amtso.wordpress.com&amp;blog=10885805&amp;post=918&amp;subd=amtso&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://amtso.wordpress.com/2011/11/14/av-test-look-at-free-android-av/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/87a00d996b23fce4539dbdd792cc5d13?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">dharley</media:title>
		</media:content>
	</item>
		<item>
		<title>NIST, the cloud, and certification</title>
		<link>http://amtso.wordpress.com/2011/10/29/nist-the-cloud-and-certification/</link>
		<comments>http://amtso.wordpress.com/2011/10/29/nist-the-cloud-and-certification/#comments</comments>
		<pubDate>Sat, 29 Oct 2011 22:10:11 +0000</pubDate>
		<dc:creator>David Harley</dc:creator>
				<category><![CDATA[David Harley]]></category>
		<category><![CDATA[Guidelines documents]]></category>
		<category><![CDATA[(ISC)2]]></category>
		<category><![CDATA[In the Cloud]]></category>
		<category><![CDATA[Infosecurity Magazine]]></category>
		<category><![CDATA[NIST]]></category>

		<guid isPermaLink="false">http://amtso.wordpress.com/?p=913</guid>
		<description><![CDATA[I&#8217;ve no excuse for not having noticed this before, as it was an entry on the Infosecurity Magazine blog, to which I&#8217;m a contributor. But miss it I did, I&#8217;m afraid, for over a week, even though it&#8217;s testing related. The article &#8220;“Testing the Testers”: Certification and Cloud Computing&#8221; was actually contributed by the (ISC)² U.S. [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=amtso.wordpress.com&amp;blog=10885805&amp;post=913&amp;subd=amtso&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve no excuse for not having noticed this before, as it was an entry on the Infosecurity Magazine blog, to which I&#8217;m a contributor. But miss it I did, I&#8217;m afraid, for over a week, even though it&#8217;s testing related. The article <a href="http://www.infosecurity-magazine.com/blog/2011/10/19/testing-the-testers-certification-and-cloud-computing/433.aspx" target="_blank">&#8220;“Testing the Testers”: Certification and Cloud Computing&#8221;</a> was actually contributed by the <a href="https://www.isc2.org/gabewb/Default.aspx">(ISC)² U.S. Government Advisory Board Executive Writers Bureau</a>. (Coincidentally, I blog for <a href="http://blog.isc2.org/isc2_blog/" target="_blank">(ISC)2</a> as well, butI have nothing to do with the Government Advisory Board AWB.)</p>
<p>Anyway, the blog notes that NIST (the National Institute of Standards and Technology) has just released a <a href="http://collaborate.nist.gov/twiki-cloud-computing/pub/CloudComputing/StandardsRoadmap/NIST_SP_500-291_Jul5A.pdf">Cloud Computing Standards Roadmap</a>, recognizing the complexity of certification of products in the context of the rising demand for cloud services. In particular, the <a href="http://csrc.nist.gov/publications/drafts/nistir-7328/NISTIR_7328-ipdraft.pdf">draft inter-agency advisory report (NISTIR 7328)</a> is about requirements for security assessment providers, in particular those who are offering assessment as a service.</p>
<p>While it&#8217;s a very different document to AMTSO&#8217;s <a href="http://www.amtso.org/amtso---download---amtso-best-practices-for-testing-in-the-cloud-security.html" target="_blank">guidelines</a> for testing in the cloud, it comes from a similar appreciation of the difficulties of this area of testing.</p>
<p><strong>David Harley CITP FBCS CISSP</strong><br />
<strong>ESET Senior Research Fellow</strong></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/amtso.wordpress.com/913/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/amtso.wordpress.com/913/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/amtso.wordpress.com/913/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/amtso.wordpress.com/913/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/amtso.wordpress.com/913/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/amtso.wordpress.com/913/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/amtso.wordpress.com/913/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/amtso.wordpress.com/913/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/amtso.wordpress.com/913/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/amtso.wordpress.com/913/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/amtso.wordpress.com/913/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/amtso.wordpress.com/913/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/amtso.wordpress.com/913/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/amtso.wordpress.com/913/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=amtso.wordpress.com&amp;blog=10885805&amp;post=913&amp;subd=amtso&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://amtso.wordpress.com/2011/10/29/nist-the-cloud-and-certification/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/87a00d996b23fce4539dbdd792cc5d13?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">dharley</media:title>
		</media:content>
	</item>
		<item>
		<title>Testing: the Knight&#8217;s Tale</title>
		<link>http://amtso.wordpress.com/2011/10/19/testing-the-knights-tale/</link>
		<comments>http://amtso.wordpress.com/2011/10/19/testing-the-knights-tale/#comments</comments>
		<pubDate>Wed, 19 Oct 2011 15:50:34 +0000</pubDate>
		<dc:creator>David Harley</dc:creator>
				<category><![CDATA[AMTSO Workshop]]></category>
		<category><![CDATA[David Harley]]></category>
		<category><![CDATA[Kaspersky]]></category>
		<category><![CDATA[Don Quixote]]></category>
		<category><![CDATA[Eugene Kaspersky]]></category>
		<category><![CDATA[Monty Python]]></category>
		<category><![CDATA[the Holy Grail]]></category>

		<guid isPermaLink="false">http://amtso.wordpress.com/?p=906</guid>
		<description><![CDATA[Strange how the whole AV testing issue seems to attract metaphors and analogies harking  back in some sense to mediaeval romance. For the past few days I&#8217;ve been muttering grimly about tilting at windmills, having recently come across an unhappy example of a test apparently relying on a simulation. (You&#8217;ll probably hear more from me [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=amtso.wordpress.com&amp;blog=10885805&amp;post=906&amp;subd=amtso&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Strange how the whole AV testing issue seems to attract metaphors and analogies harking  back in some sense to mediaeval romance. For the past few days I&#8217;ve been muttering grimly about tilting at windmills, having recently come across an unhappy example of a test apparently relying on a simulation. (You&#8217;ll probably hear more from me on that, though I won&#8217;t necessarily be performing my impersonations of Don Quixote on this blog) .</p>
<p>And now I&#8217;ve come across a recent blog by Eugene Kaspersky in which he talks about <a href="http://eugene.kaspersky.com/2011/10/18/the-holy-grail-of-av-testing-and-why-it-will-never-be-found/" target="_blank">The Holy Grail of AV Testing, and Why It Will Never Be Found</a>: in fact, making a plea for something that sounds very similar to &#8220;<a href="http://www.amtso.org/amtso---download---whole-product-testing-guidelines.html" target="_blank">whole product testing</a>&#8221; as defined by AMTSO (which features strongly in his argument), and building on another of his <a href="http://eugene.kaspersky.com/2011/09/30/benchmarking-without-weightings-like-a-burger-without-a-bun/" target="_blank">articles</a>, as I previously mentioned <a href="http://amtso.wordpress.com/2011/09/30/two-excellent-testing-articles/" target="_blank">here</a>. Essentially, he comes to the depressing conclusion that &#8220;&#8230;sadly, proper results from proper tests are these days simply nowhere to be found, despite their Holy Grail status.&#8221;</p>
<p>&#8220;Nowhere&#8221; might be a little harsh, but I have to admit that I&#8217;ve heard a lot of similar sentiments expressed recently. Yet here I am at yet another AMTSO workshop, halfway through a gruelling schedule of meetings. We&#8217;re still here, and still trying to establish some form of chivalric code. Please keep any mutterings about honour among thieves to yourself: after many years in or on the fringes of the AV industry, I&#8217;ve heard it all, but I haven&#8217;t lost faith in the ability of the vendor and tester communities to put personal differences and vested interests aside for the protection of the end user. Flashbacks to Monty Python notwithstanding.</p>
<p><strong>David Harley CITP FBCS CISSP</strong><br />
<strong>ESET Senior Research Fellow</strong></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/amtso.wordpress.com/906/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/amtso.wordpress.com/906/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/amtso.wordpress.com/906/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/amtso.wordpress.com/906/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/amtso.wordpress.com/906/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/amtso.wordpress.com/906/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/amtso.wordpress.com/906/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/amtso.wordpress.com/906/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/amtso.wordpress.com/906/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/amtso.wordpress.com/906/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/amtso.wordpress.com/906/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/amtso.wordpress.com/906/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/amtso.wordpress.com/906/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/amtso.wordpress.com/906/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=amtso.wordpress.com&amp;blog=10885805&amp;post=906&amp;subd=amtso&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://amtso.wordpress.com/2011/10/19/testing-the-knights-tale/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/87a00d996b23fce4539dbdd792cc5d13?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">dharley</media:title>
		</media:content>
	</item>
		<item>
		<title>VB presentation: whine tasting</title>
		<link>http://amtso.wordpress.com/2011/10/13/vb-presentation-whine-tasting/</link>
		<comments>http://amtso.wordpress.com/2011/10/13/vb-presentation-whine-tasting/#comments</comments>
		<pubDate>Thu, 13 Oct 2011 14:17:34 +0000</pubDate>
		<dc:creator>David Harley</dc:creator>
				<category><![CDATA[AVG]]></category>
		<category><![CDATA[David Harley]]></category>
		<category><![CDATA[ESET]]></category>
		<category><![CDATA[Larry Bridwell]]></category>
		<category><![CDATA[Virus Bulletin]]></category>

		<guid isPermaLink="false">http://amtso.wordpress.com/?p=896</guid>
		<description><![CDATA[The presentation Larry Bridwell and I delivered at Virus Bulletin last week based on our paper Daze of Whine and Neuroses (but Testing is FINE) is now posted on the Virus Bulletin web site, along with a selection of other presentations from the technical and corporate streams, plus some last minute presentations. That presentation is in [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=amtso.wordpress.com&amp;blog=10885805&amp;post=896&amp;subd=amtso&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>The <a href="http://amtso.wordpress.com/2011/10/08/daze-of-whine-and-neuroses/" target="_blank">presentation</a> Larry Bridwell and I delivered at Virus Bulletin last week based on our paper <a href="http://go.eset.com/us/resources/white-papers/VB2011-HarleyBridwell.pdf" target="_blank">Daze of Whine and Neuroses (but Testing is FINE)</a> is now <a href="http://www.virusbtn.com/pdf/conference_slides/2011/Harley-Bridwell-VB2011.pdf" target="_blank">posted</a> on the Virus Bulletin web site, along with <a href="http://www.virusbtn.com/conference/vb2011/slides/index" target="_blank">a selection of other presentations</a> from the technical and corporate streams, plus some last minute presentations.</p>
<p>That <a href="http://www.virusbtn.com/pdf/conference_slides/2011/Harley-Bridwell-VB2011.pdf" target="_blank">presentation</a> is in PDF form and doesn&#8217;t include the speaker notes, but I&#8217;m working on that.</p>
<p><strong>David Harley CITP FBCS CISSP</strong><br />
<strong>Small Blue-Green World</strong><br />
<strong>ESET Senior Research Fellow</strong></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/amtso.wordpress.com/896/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/amtso.wordpress.com/896/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/amtso.wordpress.com/896/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/amtso.wordpress.com/896/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/amtso.wordpress.com/896/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/amtso.wordpress.com/896/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/amtso.wordpress.com/896/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/amtso.wordpress.com/896/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/amtso.wordpress.com/896/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/amtso.wordpress.com/896/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/amtso.wordpress.com/896/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/amtso.wordpress.com/896/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/amtso.wordpress.com/896/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/amtso.wordpress.com/896/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=amtso.wordpress.com&amp;blog=10885805&amp;post=896&amp;subd=amtso&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://amtso.wordpress.com/2011/10/13/vb-presentation-whine-tasting/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/87a00d996b23fce4539dbdd792cc5d13?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">dharley</media:title>
		</media:content>
	</item>
		<item>
		<title>Two old codgers&#8230;</title>
		<link>http://amtso.wordpress.com/2011/10/10/two-old-codgers/</link>
		<comments>http://amtso.wordpress.com/2011/10/10/two-old-codgers/#comments</comments>
		<pubDate>Mon, 10 Oct 2011 12:10:24 +0000</pubDate>
		<dc:creator>David Harley</dc:creator>
				<category><![CDATA[AVG]]></category>
		<category><![CDATA[AVIRA]]></category>
		<category><![CDATA[David Harley]]></category>
		<category><![CDATA[ESET]]></category>
		<category><![CDATA[Larry Bridwell]]></category>
		<category><![CDATA[Sorin Mustaca]]></category>

		<guid isPermaLink="false">http://amtso.wordpress.com/?p=889</guid>
		<description><![CDATA[&#8230;whining about the state of testing&#8230; That&#8217;s me on the left trying to hide behind the podium, and co-presenter Larry Bridwell (AVG) on the right. Picture by Sorin Mustaca of Avira. David Harley CITP FBCS CISSP ESET Senior Research Fellow<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=amtso.wordpress.com&amp;blog=10885805&amp;post=889&amp;subd=amtso&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>&#8230;whining about the <a href="http://amtso.wordpress.com/2011/10/08/daze-of-whine-and-neuroses/" target="_blank">state of testing&#8230;</a></p>
<p><img class="aligncenter size-medium wp-image-890" title="larry-david2" src="http://amtso.files.wordpress.com/2011/10/larry-david2.jpg?w=287&#038;h=300" alt="" width="287" height="300" /></p>
<p>That&#8217;s me on the left trying to hide behind the podium, and co-presenter Larry Bridwell (<a href="http://blogs.avg.com/" target="_blank">AVG</a>) on the right.</p>
<p>Picture by Sorin Mustaca of <a href="http://techblog.avira.com/en/" target="_blank">Avira</a>.</p>
<p><strong>David Harley CITP FBCS CISSP</strong><br />
<strong><a href="http://blog.eset.com/" target="_blank">ESET</a> Senior Research Fellow</strong></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/amtso.wordpress.com/889/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/amtso.wordpress.com/889/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/amtso.wordpress.com/889/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/amtso.wordpress.com/889/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/amtso.wordpress.com/889/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/amtso.wordpress.com/889/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/amtso.wordpress.com/889/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/amtso.wordpress.com/889/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/amtso.wordpress.com/889/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/amtso.wordpress.com/889/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/amtso.wordpress.com/889/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/amtso.wordpress.com/889/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/amtso.wordpress.com/889/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/amtso.wordpress.com/889/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=amtso.wordpress.com&amp;blog=10885805&amp;post=889&amp;subd=amtso&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://amtso.wordpress.com/2011/10/10/two-old-codgers/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/87a00d996b23fce4539dbdd792cc5d13?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">dharley</media:title>
		</media:content>

		<media:content url="http://amtso.files.wordpress.com/2011/10/larry-david2.jpg?w=287" medium="image">
			<media:title type="html">larry-david2</media:title>
		</media:content>
	</item>
		<item>
		<title>Daze of Whine and Neuroses&#8230;</title>
		<link>http://amtso.wordpress.com/2011/10/08/daze-of-whine-and-neuroses/</link>
		<comments>http://amtso.wordpress.com/2011/10/08/daze-of-whine-and-neuroses/#comments</comments>
		<pubDate>Sat, 08 Oct 2011 05:53:58 +0000</pubDate>
		<dc:creator>David Harley</dc:creator>
				<category><![CDATA[AVG]]></category>
		<category><![CDATA[David Harley]]></category>
		<category><![CDATA[ESET]]></category>
		<category><![CDATA[Larry Bridwell]]></category>
		<category><![CDATA[Testing Papers]]></category>
		<category><![CDATA[Virus Bulletin]]></category>

		<guid isPermaLink="false">http://amtso.wordpress.com/?p=879</guid>
		<description><![CDATA[&#8230;is the title of a presentation AVG&#8216;s Larry Bridwell and I did at Virus Bulletin recently. The paper is now up (by kind permission of Virus Bulletin) on the ESET white papers page as Daze of Whine and Neuroses.  Abstract: Daze of whine and neuroses (but testing is FINE)  According to Aerosmith (not to mention The [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=amtso.wordpress.com&amp;blog=10885805&amp;post=879&amp;subd=amtso&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>&#8230;is the title of a presentation <a href="http://www.avg.com/" target="_blank">AVG</a>&#8216;s Larry Bridwell and I did at <a href="http://www.virusbtn.com/index" target="_blank">Virus Bulletin</a> recently. The paper is now up (by kind permission of Virus Bulletin) on the <a href="http://go.eset.com/us/documentation/white-papers" target="_blank">ESET white papers</a> page as <a href="http://go.eset.com/us/resources/white-papers/VB2011-HarleyBridwell.pdf" target="_blank">Daze of Whine and Neuroses</a>. </p>
<p><strong>Abstract</strong>:</p>
<p><em>Daze of whine and neuroses (but testing is FINE)</em> </p>
<p>According to Aerosmith (not to mention The Italian Job), FINE is an acronym for (in its politer version) Freaked out, Insecure, Neurotic and Emotional. We could (and probably will) offer alternatives, but there&#8217;s no doubting that anti-malware testing inspires all those reactions.</p>
<p>Sometimes it seems that AMTSO has become a dumping ground for the rest of the world&#8217;s misgivings about the AV industry, even though it originated in a coalition with some of the testers who are monitoring that industry&#8217;s performance with the most assiduous professionalism: indeed, that coalition has in itself inspired mistrust. And recently, it has become plain that even within AMTSO both testers and vendors sometimes find the alliance problematical.</p>
<p> AMTSO&#8217;s purpose is simple to state, but much harder to achieve. It represents a realization by professional testers and security vendors that the quality of anti-malware testing was so variable that it was at best confusing for people who need guidance on how to select the best product for their needs. Perhaps testing has improved more in the past few years than it would have without AMTSO&#8217;s presence, and discussions and generation of material in a single forum has accelerated a much-needed move away from static testing towards dynamic testing.</p>
<p>But it&#8217;s time to ask (and attempt to answer) a number of tough but critical questions.</p>
<ul>
<li>Looking over the historical evolution of testing before and since AMTSO, is that move towards dynamic testing enough to set the testing world to rights?</li>
<li>Are the aims of testers and vendors close enough to allow continued cooperation within AMTSO?</li>
<li>Has AMTSO already outlived its usefulness?</li>
<li>If not, what should it do next?</li>
<li>What is the future of comparative detection testing?</li>
</ul>
<p><strong>David Harley CITP FBCS CISSP</strong><br />
<strong>ESET Senior Research Fellow</strong></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/amtso.wordpress.com/879/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/amtso.wordpress.com/879/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/amtso.wordpress.com/879/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/amtso.wordpress.com/879/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/amtso.wordpress.com/879/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/amtso.wordpress.com/879/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/amtso.wordpress.com/879/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/amtso.wordpress.com/879/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/amtso.wordpress.com/879/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/amtso.wordpress.com/879/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/amtso.wordpress.com/879/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/amtso.wordpress.com/879/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/amtso.wordpress.com/879/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/amtso.wordpress.com/879/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=amtso.wordpress.com&amp;blog=10885805&amp;post=879&amp;subd=amtso&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://amtso.wordpress.com/2011/10/08/daze-of-whine-and-neuroses/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/87a00d996b23fce4539dbdd792cc5d13?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">dharley</media:title>
		</media:content>
	</item>
		<item>
		<title>Another good testing article</title>
		<link>http://amtso.wordpress.com/2011/10/04/another-good-testing-article/</link>
		<comments>http://amtso.wordpress.com/2011/10/04/another-good-testing-article/#comments</comments>
		<pubDate>Tue, 04 Oct 2011 11:52:30 +0000</pubDate>
		<dc:creator>David Harley</dc:creator>
				<category><![CDATA[David Harley]]></category>
		<category><![CDATA[Dennis Technology Labs]]></category>
		<category><![CDATA[Media]]></category>
		<category><![CDATA[Media mentions]]></category>
		<category><![CDATA[Simon Edwards]]></category>

		<guid isPermaLink="false">http://amtso.wordpress.com/?p=868</guid>
		<description><![CDATA[This would naturally belong with the blog I put up recently as Two excellent testing articles, but somehow I missed Simon Edwards&#8217; blog on Anti-malware testing discussions. So I&#8217;m a couple of weeks late on pointing it out, but it&#8217;s certainly worth your time to take a look. Which actually reminds me another point. You may have [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=amtso.wordpress.com&amp;blog=10885805&amp;post=868&amp;subd=amtso&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>This would naturally belong with the blog I put up recently as <a title="Permanent Link to Two excellent testing articles" href="http://amtso.wordpress.com/2011/09/30/two-excellent-testing-articles/" rel="bookmark">Two excellent testing articles</a>, but somehow I missed Simon Edwards&#8217; blog on <a href="http://simonedwards.blogspot.com/2011/09/anti-malware-testing-discussions.html" target="_blank">Anti-malware testing discussions</a>. So I&#8217;m a couple of weeks late on pointing it out, but it&#8217;s certainly worth your time to take a look.</p>
<p>Which actually reminds me another point. You may have noticed that there haven&#8217;t been any recent updates to the &#8220;<a href="http://amtso.wordpress.com/amtso-in-the-media/" target="_blank">AMTSO in the media</a>&#8221; page. That isn&#8217;t because there hasn&#8217;t been any mention of us anywhere since June 2011 &#8211; though I have to admit that it <em>is</em> hard to interest the media in stuff that even testing geeks get bored with and there hasn&#8217;t been the sensational and/or controversial press that we saw a year or two ago - but because of resource starvation.  So I&#8217;m not abandoning the page altogether, but there&#8217;s no guarantee that it&#8217;s up to date, and I&#8217;m definitely not going to be looking for every mention of AMTSO in the media from June till now in the hope of catching up.</p>
<p>David Harley CITP FBCS CISSP<br />
AMTSO Board member<br />
ESET Senior Research Fellow</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/amtso.wordpress.com/868/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/amtso.wordpress.com/868/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/amtso.wordpress.com/868/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/amtso.wordpress.com/868/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/amtso.wordpress.com/868/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/amtso.wordpress.com/868/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/amtso.wordpress.com/868/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/amtso.wordpress.com/868/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/amtso.wordpress.com/868/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/amtso.wordpress.com/868/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/amtso.wordpress.com/868/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/amtso.wordpress.com/868/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/amtso.wordpress.com/868/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/amtso.wordpress.com/868/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=amtso.wordpress.com&amp;blog=10885805&amp;post=868&amp;subd=amtso&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://amtso.wordpress.com/2011/10/04/another-good-testing-article/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/87a00d996b23fce4539dbdd792cc5d13?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">dharley</media:title>
		</media:content>
	</item>
		<item>
		<title>Two excellent testing articles</title>
		<link>http://amtso.wordpress.com/2011/09/30/two-excellent-testing-articles/</link>
		<comments>http://amtso.wordpress.com/2011/09/30/two-excellent-testing-articles/#comments</comments>
		<pubDate>Fri, 30 Sep 2011 17:41:27 +0000</pubDate>
		<dc:creator>David Harley</dc:creator>
				<category><![CDATA[David Harley]]></category>
		<category><![CDATA[Lysa Myers]]></category>
		<category><![CDATA[Virus Bulletin]]></category>
		<category><![CDATA[West Coast Labs]]></category>
		<category><![CDATA[Eugene Kaspersky]]></category>

		<guid isPermaLink="false">http://amtso.wordpress.com/?p=863</guid>
		<description><![CDATA[One by Eugene Kaspersky (yes, that Kaspersky) on &#8220;Benchmarking Without Weightings: Like a Burger Without a Bun&#8221; (hat tip to Larry Bridwell for drawing my attention to it.) Memorable extract: &#8220;Alas, practically all benchmarking tests don’t bother with weightings, bunching apples and oranges, and pears and peaches – and bananas and hamsters – all together [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=amtso.wordpress.com&amp;blog=10885805&amp;post=863&amp;subd=amtso&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>One by Eugene Kaspersky (yes, <em>that </em>Kaspersky) on &#8220;<a href="http://eugene.kaspersky.com/2011/09/30/benchmarking-without-weightings-like-a-burger-without-a-bun/" target="_blank">Benchmarking Without Weightings: Like a Burger Without a Bun</a>&#8221; (hat tip to Larry Bridwell for drawing my attention to it.)</p>
<p>Memorable extract: &#8220;Alas, practically all benchmarking tests don’t bother with weightings, bunching apples and oranges, and pears and peaches – and bananas and hamsters – all together as being the same.&#8221; His conclusion is that no-one can authoritatively measure the quality of an anti-virus solution: &#8220;there really <em>isn’t a test like that</em> – one that I could unambiguously recommend as the best indicator.&#8221;</p>
<p>And Lysa Myers, of West Coast Labs, has a comment piece in October&#8217;s Virus Bulletin about &#8220;<a href="http://www.virusbtn.com/virusbulletin/archive/2011/10/vb201110-comment" target="_blank">Why there&#8217;s no one test to  rule them all,</a>&#8221; with a somewhat similar conclusion: &#8220;Because every product has strengths and weaknesses, having a variety of different tests is essential.&#8221; Unfortunately, you&#8217;ll need to be a subscriber to read it.</p>
<p><strong>David Harley CITP FBCS CISSP</strong><br />
<strong>ESET Senior Research Fellow</strong></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/amtso.wordpress.com/863/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/amtso.wordpress.com/863/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/amtso.wordpress.com/863/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/amtso.wordpress.com/863/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/amtso.wordpress.com/863/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/amtso.wordpress.com/863/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/amtso.wordpress.com/863/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/amtso.wordpress.com/863/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/amtso.wordpress.com/863/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/amtso.wordpress.com/863/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/amtso.wordpress.com/863/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/amtso.wordpress.com/863/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/amtso.wordpress.com/863/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/amtso.wordpress.com/863/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=amtso.wordpress.com&amp;blog=10885805&amp;post=863&amp;subd=amtso&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://amtso.wordpress.com/2011/09/30/two-excellent-testing-articles/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/87a00d996b23fce4539dbdd792cc5d13?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">dharley</media:title>
		</media:content>
	</item>
	</channel>
</rss>
