• 0

What happens if Webroot SecureAnywhere misses a virus?


Question



In this video Webroot purposely infect a machine running Webroot SecureAnywhere. They even disable the behaviour shield to replicate what would happen if a threat was missed and it executed on your PC.

We estimate there to be somewhere in the region of 50,000 new strains of malware every single day, so it's frankly impossible for the legacy signature-based approaches to keep up with the vast volume of threats.

Webroot SecureAnywhere adopts a new cloud-driven approach, ensuring that users always have access the the latest security "definitions" without needing to download any updates. This, coupled with a 700Kb agent, ensures optimal performance and enhanced security.

Webroot also recognise that the ever-rising volume of malware means that they'll miss threats, too. While they do have industry leading detection rates (See: http://www.av-test.o...er/mayjun-2012/) they have introduced unique protection against information-stealing malware, so even if they do miss something, the data that you really care about cannot be tampered with.

Recommended Posts

  • 0

Hello,

Not to complain about AV-Test, since this is more of a general issue facing all testers, but as I am sure you are aware, in any kind of sample set containing files not specifically verified by a human being there can be files which are incorrectly identified as malicious code when, in fact, they do not contain any executable code at all, or contain code that does not perform a threatening action, even though the behavior may initially be diagnosed as malicious (for example, a license key mechanism that injects the key into a runtime executable or library). While rare, reports of "false 'false positives'" can occur in tests involving samples, and investigating and balancing out those cases can be labor-intensive for both the tester and the testee.

Regards,

Aryeh Goretsky

Hi Yorak,

I would certainly be happy to work with you to personally address your false positive issues.

The problem with video reviews is that they can only over show the results of a sample-set which is statistically insignificant. Will we generate false positives? Absolutely, but I'd also like to think that our cloud-powered heuristics should generate less false positives versus the traditional approach.

Let's take a look at the latest AV-Test results: http://www.av-test.o...rt_no%5D=121849 (I hate these tests in general, but that's a whole other topic!)

Out of a sample of 661,176 we generated 4 false positives. Eset NOD32 generated 1 false positive out of the same sample, but they also missed a lot more threats, so it's always a bit of a trade-off.

As our community has grown, the quality of our security intelligence has improved, so we've seen a massive decline in the number of false positives compared to the early days.

Give it another whirl and if you still have problems send your keycode to wfletcher[at]webroot.com and I'll take a look for you.

  • 0

I haven't tried Webroot nor do I know anyone personally that runs it. I've been using Nod 32 for many of years. I get great results with Nod 32 overall but am not adverse to switching to Webroot.

What advantages does Webroot have over Nod 32, specifically in the real-time protection?

Gimme a key and I'll give you a cookie. :D

Hi Marshall,

Webroot SecureAnywhere and NOD32 work very differently to eachother. NOD32 is an excellent product and it wouldn't be fair for me to provide competitive analysis on this thread. Make sure you do a review of the market when your renewal is due and pick the best product! :-)

  • 0

Hello,

Not to complain about AV-Test, since this is more of a general issue facing all testers, but as I am sure you are aware, in any kind of sample set containing files not specifically verified by a human being there can be files which are incorrectly identified as malicious code when, in fact, they do not contain any executable code at all, or contain code that does not perform a threatening action, even though the behavior may initially be diagnosed as malicious (for example, a license key mechanism that injects the key into a runtime executable or library). While rare, reports of "false 'false positives'" can occur in tests involving samples, and investigating and balancing out those cases can be labor-intensive for both the tester and the testee.

Regards,

Aryeh Goretsky

Hi Goretsky,

I completely agree.

In my opinion, these tests are not representative of reality, but they can be useful as long as the reader understands the data. I remember a few months ago we absolutely bombed one of these tests because we generated hundreds of false positives. The tester installed us on a machine with thousands of infections and we (rightfully, in my opinion) automatically ramped up the heuristics to maximum, so we started to treat every file on the PC with maximum suspicion. Of course we generated lots of false positives and they trashed the product! In the real world, if one of our customers installed us on a machine with thousands of infections, the last thing they'll be concerned about is a false positive! Not to mention it would be pretty much impossible to get a PC into that state with Webroot SecureAnywhere installed!

One of the biggest problems I have with these tests is that the testers have to manually update the signature definitions before testing their sample malware. In the real-world, we don't get the luxury of updating our definitions the second before an infection strikes. With ~50,000 new threats every day, there's a huge window of exposure between updates which is not accounted for in the tests.

The 0-day tests they perform are also very weak. They tend to scan the virus and if the security vendor fails to detect it, the virus will be executed. If the virus is then running in memory, the security vendor is assumed to have failed. They don't take into consideration the monitoring capability of Webroot SecureAnywhere and the fact that the endpoint is protected from the threat, even though it's running (as you can see in the video in the OP).

The performance tests they perform can be very useful, though. :-)

  • 0

Hi Marshall,

Webroot SecureAnywhere and NOD32 work very differently to eachother. NOD32 is an excellent product and it wouldn't be fair for me to provide competitive analysis on this thread. Make sure you do a review of the market when your renewal is due and pick the best product! :-)

I don't know about that Will, I think it may be very entertaining.....

but I do agree, do your own homework on the product and pick the best one for you.

  • 0

Hi Goretsky,

The 0-day tests they perform are also very weak. They tend to scan the virus and if the security vendor fails to detect it, the virus will be executed. If the virus is then running in memory, the security vendor is assumed to have failed. They don't take into consideration the monitoring capability of Webroot SecureAnywhere and the fact that the endpoint is protected from the threat, even though it's running (as you can see in the video in the OP).

Complete success would be that it doesn't execute. If it doesn't execute it isn't taking up processor cycles. If it doesn't take processor cycles, it isn't going to take any part of it away from applications or other system processes. While the endpoint isn't going to allow the application/service to communication to the internet in essence it has failed to keep the machine clean and free from infection. It has given the end user the illusion that they are malware free because it stopped malware-x from communicating. So in my point of view it has failed from doing its job properly.

  • 0

Hi Marshall,

Webroot SecureAnywhere and NOD32 work very differently to eachother. NOD32 is an excellent product and it wouldn't be fair for me to provide competitive analysis on this thread. Make sure you do a review of the market when your renewal is due and pick the best product! :-)

Do you or could you offer a 30-day trial period? I see no option for this on your website.

  • 0

Do you or could you offer a 30-day trial period? I see no option for this on your website.

Here you go: http://www.webroot.com/En_US/consumer-trials.html

The home products are Webroot SecureAnywhere Complete, Essentials and Antivirus. The business product comes with a much more advanced management console.

  • 0

I've downloaded and am currently using your product, however I have one problem. Why is it I get no notification pop-up when an executable containing malicious code is blocked? I have to manually open the Webroot program and go to the quarantine to see this.

Every malicious test file that I've downloaded has been successfully blocked by Webroot, but I'd like be notified instantly of the block. I see no option in the settings to allow this to happen, am I overlooking it?

Thanks for your time.

  • 0

I've downloaded and am currently using your product, however I have one problem. Why is it I get no notification pop-up when an executable containing malicious code is blocked? I have to manually open the Webroot program and go to the quarantine to see this.

Every malicious test file that I've downloaded has been successfully blocked by Webroot, but I'd like be notified instantly of the block. I see no option in the settings to allow this to happen, am I overlooking it?

Thanks for your time.

Hi Marshall,

I'm just wondering if you may have downloaded our business product instead of the home user product(s)?

If the latter, I'll have a member of our consumer support team reach out to you, because you should be at least alerted by default.

  • 0

I have a comment on the video then I have a question.

Comment : Thank you for turning off Animations and fades during recording. Most people don't do that and it makes the machine feel sluggish so props for that.

Question

1) I really liked the rollback feature I saw in the video and have a question about it. What if it monitors an unknown file that the user installs. This unknown file is some sort of safe free word processor that the user uses. Then at some point in time the file is accidentally flagged as malware and the user goes to clean up the infection by following webroots instructions. Would all of the data the user created with that program be removed during the removal process?

If so, can you undo an undo?

Thanks

Adam.

  • Like 2
  • 0

I have a comment on the video then I have a question.

Comment : Thank you for turning off Animations and fades during recording. Most people don't do that and it makes the machine feel sluggish so props for that.

Question

1) I really liked the rollback feature I saw in the video and have a question about it. What if it monitors an unknown file that the user installs. This unknown file is some sort of safe free word processor that the user uses. Then at some point in time the file is accidentally flagged as malware and the user goes to clean up the infection by following webroots instructions. Would all of the data the user created with that program be removed during the removal process?

If so, can you undo an undo?

Thanks

Adam.

Hi warwagon,

I'll start by saying the scenario you describe should be super rare (and will probably never happen to you), but the answer is yes. All of the content that is removed by the journaling and rollback feature can be restored if needed.

In fact, you'll be able to see exactly what has been rolled-back in the quarantine section, so if you needed to restore a specific document you can do so.

Let me know if you have any more questions!

  • 0

I've experienced multiple issues, mainly the detection rates. I visit a lot of dodgy sites (those of you who are subscribers or mods know why) so I willingly subject myself to malicious content. I've been infected with multiple trojans and malware during my experience with webroot. Never did I have an infiltration when using Nod32 for the few years I've been using it.

I've since uninstalled Webroot and reinstalled Nod32 for peace of mind. Your cloud based AV is headed in the right direction, it just doesn't get the job done.

  • 0

It's very light on resources, more so than Nod32. You never know it's there, including when the real-time protection doesn't notify you of a threat or infestation.. :D

Like I said, Webroot is headed in the right direction, but in terms of detection of viruses, it is sub-par.

  • 0

"Webroot SecureAnywhere adopts a new cloud-driven approach"

That's great and all...until malware kills your internet connection.

Also, is it just me or does the "article" read like an ad?

Panda Cloud Antivirus is actually fantastic. I'd pay for it, but I don't really care enough to change from MSE.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Personally, I’ve found that it’s usually worth investing in the infrastructure you don’t want to replace later, especially cabling. Running Cat6A (or better, depending on your needs) during an upgrade is relatively inexpensive compared to having to re-cable a few years down the road. For switches I try to balance current specs with realistic growth. If my budget allows it Ill choose switches with higher uplink speeds which leaves room for expanding later on, but I don’t necessarily overspend on access ports if the endpoints won’t benefit from them anytime soon. One lesson I’ve learned is that planning for scalability pays off. It’s much easier to add devices, VLANs, or higher-bandwidth workloads when your network infrastructure already supports it than to replace hardware later.  What is your budget like?
    • I hate the term, "future-proof." We saw it back in the 90's / 2000's, if not before. You cannot future-proof anything, since there is no definition of how far into the future you plan on prepping for. Best idea is to tell us what you currently have and what its use is at the moment, and we can then offer ideas about some areas that might need an upgrade and other areas that can be left alone.
    • I can agree that it is being used in a small capacity. I worked for a company where their engineers still used XP, and when asked why it was because their sensor software wasn't compatible with newer operating systems and the software was discontinued so they couldn't upgrade the software. Given that the sensors were still in use by companies, they had to continue using XP to support the sensor, otherwise the price to the company would have gone into the millions or billions. Our response was simple: Ok, you can keep the XP machine. But we're removing it from the network. "But then it can't access the Internet or folder shares!" Yup, kinda the point. If someone wants to continue using an unsecure OS they can do, I have no problem with that. But it should be isolated. Simple. I had a fight with a guy in the engineering department for weeks before he finally relented. But we digress.   What do I plan on doing to commemorate the anniversary? Nothing. I have fond memories of the OS, but at the end of the day it's just an OS. If I had some time I might see if I could install it on my Raspberry Pi for a laugh. But my reflex memory with today's OS ideas would probably get me frustrated and I'd uninstall it after 5 mins.
    • Shutter Encoder 20.2 by Razvan Serea Shutter Encoder is one of the best video converter software and image, audio available today. It has been designed by video editors in order to be as accessible and efficient as possible. It is one of the few free professional tools. Based on FFmpeg, it has the largest codec library available. You can thus convert your files into many different formats. Complete settings for the most advanced Shutter Encoder has a panel containing a large number of settings, in order to define your own choices based on your files and perfect your video or audio output. Well-thought-out settings, with parameters predefined to create files quickly and easily. List of functions Without conversion: Cut without re-encoding, Replace audio, Rewrap, Conform, Merge, Extract, Subtitling, Video inserts Sound conversions: WAV, AIFF, FLAC, MP3, AAC, AC3, OPUS, OGG Editing codecs: DNxHD, DNxHR, Apple ProRes, QT Animation, GoPro CineForm, Uncompressed YUV Output codecs: H.264, H.265, VP9, AV1, OGV Broadcast codecs XDCAM HD422, AVC-Intra 100, XAVC, HAP....and much more. Shutter Encoder 20.2 changelog: Added "Intel Quick Sync" hardware acceleration for Linux Added 'Identify speakers' option for "Audio transcription" function Improved installer package Improved video player performance Improved timecode display with drop-frame videos Improved naming convention for surround audio files Fixed splash screen freeze Fixed bug with file hanging Fixed bugs with presets loading Fixed bugs with video player's buffer Fixed bug with 'Total length of file' option Fixed bugs with 'Record screen/device' option Fixed bug with "XAVC" & "XAVC Long GOP" functions Rollback to XPDF tool for PDF conversion Removed unused binary architecture for Mac Various corrections Various improvements Download: Shutter Encoder 20.2 | 166.0 MB (Open Source) Download: Shutter Encoder Portable | 185.0 MB Links: Shutter Encoder Home Page | FAQ / Tips | macOS | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • did you give it permission to do so? its probably on the ToS. After that South Park episode I'm paying attention to them lol
  • Recent Achievements

    • Reacting Well
      NovaEdgeX earned a badge
      Reacting Well
    • Week One Done
      NovaEdgeX earned a badge
      Week One Done
    • One Year In
      BA the Curmudgeon earned a badge
      One Year In
    • Conversation Starter
      rosiecharles earned a badge
      Conversation Starter
    • First Post
      KMilenkoski1202 earned a badge
      First Post
  • Popular Contributors

    1. 1
      +primortal
      534
    2. 2
      +Edouard
      265
    3. 3
      PsYcHoKiLLa
      152
    4. 4
      Steven P.
      99
    5. 5
      macoman
      66
  • Tell a friend

    Love Neowin? Tell a friend!