Anti-Phishing Test August 2015



Similar documents
Anti Phishing Test July 2013

Anti-Virus Comparative

Anti-Virus Comparative

Anti-Virus Comparative

Anti-Virus Comparative

Anti-Virus Comparative No.22

Anti-Virus Comparative

How To Test For Performance On A 64 Bit Computer (64 Bit)

Anti-Virus Comparative

AV-Comparatives. Support-Test (UK) Test of English-Language Telephone Support Services for Windows Consumer Security Software 2016

Firewall Test. Firewall protection in public networks. Commissioned by CHIP. Language: English. Last Revision: 11 th April 2014

Whole Product Dynamic Real-World Protection Test (February-June 2016)

Whole Product Dynamic Real-World Protection Test (March-June 2015)

Anti-Virus Comparative

Whole Product Dynamic Real-World Protection Test (March-June 2014)

Anti-Virus Comparative - Performance Test (AV Products) May 2014

IT Security Survey 2015

Anti-Virus Comparative

Anti-Spam Test. Anti-Spam Test. (Consumer Products) Language: English. March 2016 Last Revision: 20 th April

IT Security Survey 2014

Anti-Virus Comparative

Anti-Virus Comparative

KASPERSKY LAB PROVIDES BEST IN THE INDUSTRY PROTECTION*

ENTERPRISE EPP COMPARATIVE REPORT

Whole Product Real World Dynamic Protection Test (August November) 2011

Anti-Virus Comparative

How to Determine the Performance of a Computer System

KASPERSKY LAB PROVIDES BEST IN THE INDUSTRY PROTECTION*

Anti Virus Comparative Performance Test (AV Products) October 2012

Parental Control Single Product Test

Whole Product Dynamic Real-World Protection Test (August-November 2013)

DON T BE FOOLED BY SPAM FREE GUIDE. Provided by: Don t Be Fooled by Spam FREE GUIDE. December 2014 Oliver James Enterprise

Security Industry Market Share Analysis

Performance test November 2014 / 1 INTRODUCTION... 1 TESTED PROGRAM VERSIONS..2 WHAT AND HOW WE TESTED. 3 OTHER PRINCIPLES...

Anti-Virus Comparative

AV-Comparatives. Mobile Security Test. Language: English. February 2015 Last revision: 30 th March

Monitoring mobile communication network, how does it work? How to prevent such thing about that?

PCSL. PCSL IT Consulting Institute 机 安 全 软 件 病 毒 检 测 率 测 试

IT Security Survey 2016

Whole Product Dynamic Real World Protection Test (March June 2013)

Parental Control Single Product Test

Anti-Virus Comparative - Proactive/retrospective test May 2009

How to Identify Phishing s

Single Product Review - Bitdefender Security for Virtualized Environments - November 2012

Anti Virus Comparative Performance Test (AV Products) November 2011

Phishing Scams Security Update Best Practices for General User

IT Security Survey 2012

MRG Effitas Online Banking / Browser Security Assessment Project Q Results

Anti Virus Comparative Performance Test (Suite Products) May 2012

ENTERPRISE EPP COMPARATIVE ANALYSIS

Global Antivirus Software Package Market

AV-Comparatives. F-Secure Freedome. Language: English. November 2014 Last revision: 20. November

WEB ATTACKS AND COUNTERMEASURES

Fraud Detection and Prevention. Timothy P. Minahan Vice President Government Banking TD Bank

Security Industry Market Share Analysis

Windows Updates vs. Web Threats

Conducting an Phishing Campaign

26 Protection Programs Undergo Our First Test Using Windows 8

A Secure Login Process Using USB for Various Phishing Prevention System

Online Banking and Endpoint Security Report October 2012

Android Malware Detection Test 手 机 安 全 软 件 病 毒 检 测 率 测 试 Dec. Celebrating Technology Innovation

Everyone s online, but not everyone s secure. It s up to you to make sure that your family is.

Understanding Security Threats in the Cyber World. Beth Chancellor, Chief Information Security Officer

Mobile Security Apps. Hendrik Pilz Director Technical Lab / Mobile Security hpilz@av-test.de

The Security Rule of The Health Insurance Portability and Accountability Act (HIPAA) Security Training

Can Consumer AV Products Protect Against Critical Microsoft Vulnerabilities?

Real World and Vulnerability Protection, Performance and Remediation Report

Privacy PC SECURITY LABS. False Positive COMPARATIVES Power Consumption. Android 4.x Malware Detection Test. Mobile Security

Ad-Aware Total Security [Firewall] (3.x) Ad-Aware Total Security [Firewall] (3.x)

Phoenix Information Technology Services. Julio Cardenas

Mobility Security Product Test and Certificate.

E-Business, E-Commerce

Shield Your Business - Combat Phishing Attacks. A Phishnix White Paper

Laura Royer, Extension Faculty, University of Florida/IFAS Osceola County Extension Services

Cisco Identity Services Engine Supported Windows AV/AS and Patch Management Products Compliance Module Version

The SMB Cyber Security Survival Guide

Comparing Antivirus Business Solutions. A small business running 25 work stations and 2 servers require an antivirus solution that

Online Banking Security Test June 2011

Portal Administration. Administrator Guide

Online Payments Threats

Phishing Past, Present and Future

OIG Fraud Alert Phishing

WHITEPAPER. V12 Group West Front Street, Suite 410 Red Bank, NJ

RESEARCHBRIEF. Beyond Online Gaming Cybercrime: Revisiting the Chinese Underground Market

KASPERSKY ENDPOINT SECURITY FOR BUSINESS: TECHNOLOGY IN ACTION

Single Product Review: Kaspersky Small Office Security 4

Chapter 4 Copyright Statement

ESET Endpoint Security 6 ESET Endpoint Antivirus 6 for Windows

Anti-Virus Protection and Performance

Symantec Endpoint Protection Integration Component 7.5 Release Notes

Fully supported Antivirus software (Managed Antivirus)

How To Protect Your Online Banking From Fraud

Mobility Security Product Test and Certificate

Anti-Phishing Training Modules Teach employees to recognize and avoid phishing and spear phishing attacks

Corporate Account Takeover & Information Security Awareness

MRG Effitas 360 Assessment & Certification Programme Q4 2014

Supplementary Report to the File Detection Test of September Language: English September 2015 Last Revision: 12 th November 2015

THE HOME LOAN SAVINGS BANK. Corporate Account Takeover & Information Security Awareness

Anti-Virus Comparative

Transcription:

Anti-Phishing Test August 2015 Language: English August 2015 Last revision: 10 th August 2015-1 -

Introduction What is Phishing? Taken from Wikipedia 1 : Phishing is a way of attempting to acquire sensitive information such as usernames, passwords and credit card details by masquerading as a trustworthy entity in an electronic communication. This is similar to Fishing, where the fisherman puts a bait at the hook, thus, pretending to be a genuine food for fish. But the hook inside it takes the complete fish out of the lake. Communications purporting to be from popular social web sites, auction sites, online payment processors or IT administrators are commonly used to lure the unsuspecting public. Phishing is typically carried out by e-mail spoofing or instant messaging and it often directs users to enter details at a fake website whose look and feel are almost identical to the legitimate one. Phishing is an example of social engineering techniques used to deceive users, and exploits the poor usability of current web security technologies. For more information about how not to get hooked by a phishing scam, please have a look at e.g. http://www.onguardonline.gov/phishing (provided by the United States Homeland Security). Test procedure In our test scenario, we simulate the common situation where users rely on the anti-phishing protection provided by their security products while browsing the web (and/or checking their webmail accounts; anti-spam features are not considered, as they are not within the scope of this test). The test was done using Windows 7 Professional 64-Bit and Internet Explorer 11 (without its built-in phishing blocker, in order to get browser-independent results). All security products were tested with default settings and in parallel, at the same time and on the same URLs. Test set The test took place between the 29 th July and 3 rd August 2015. Phishing URLs were tested as soon as we discovered them. All phishing URLs had to be active/online at time of testing and attempt to get personal information. After removing all invalid, offline and duplicate (sites hosted on same server/ip) testcases, 245 valid phishing URLs remained. The phishing campaigns targeted various types of personal data, including login credentials etc. for PayPal, online banking & credit cards, e-mail accounts, Dropbox, ebay, social networks, online games and other online services. 1 http://en.wikipedia.org/wiki/phishing - 2 -

Tested products The tested product versions are the ones that were available at the time of testing. The following ten vendors chose to have their anti-phishing protection publicly tested: Baidu Antivirus 5.4.3 (English) Bitdefender Internet Security 2015 BullGuard Internet Security 15.1 Emsisoft Anti-Malware 10.0 ESET Smart Security 8.0 Fortinet FortiClient 5.2.3 F-Secure Internet Security 2015 Kaspersky Internet Security 2016 Lavasoft Ad-Aware Pro 17.6 Trend Micro Internet Security 2015 Anti-Phishing False Alarm Test For the Anti-Phishing False-Alarm Test we selected 500 popular banking sites (all of them using HTTPS and showing a login form) from all over the world, and checked if any of the various security products blocked these legitimate online banking sites. Wrongly blocking such sites is a serious mistake. Of the products tested, only F-Secure had 1 false alarm on the tested 500 legitimate online banking sites. Ranking system The awards are decided and given by the testers based on the observed test results (after consulting statistical models). The ranking system for this year s Anti-Phishing Test is as follows: Anti-Phishing Anti-Phishing Anti-Phishing Anti-Phishing Ranking system Protection under 50% Protection Cluster 3 Protection Cluster 2 Protection Cluster 1 Zero FPs Tested Standard Advanced Advanced+ 1 to 2 FPs Tested Tested Standard Advanced 3 to 4 FPs Tested Tested Tested Standard More than 4 FPs Tested Tested Tested Tested - 3 -

Anti-Phishing Test August 2015 Test results Below you can see the percentages of blocked phishing websites (size of test set: 245 phishing URLs). 1. 2. 3. 4. Kaspersky Lab 98% Fortinet 92% Bitdefender, Trend Micro 91% ESET 90% 5. BullGuard, F-Secure 6. Emsisoft, Lavasoft 84% 71% 7. Baidu 52% The map below shows where the phishing websites used were hosted, based on their IP addresses. -4-

Award levels reached in this test The following awards 2 are for the results reached in this Anti-Phishing Test: AWARD LEVELS PRODUCTS Kaspersky Lab Fortinet Bitdefender Trend Micro ESET BullGuard F-Secure* Emsisoft Lavasoft Baidu - * downgraded by one rank due to a false alarm; see page 3 2 Please note that although we have used our usual awards scheme for this test, the results will not be included in the ratings for Product of the Year Award. - 5 -

Copyright and Disclaimer This publication is Copyright 2015 by AV-Comparatives. Any use of the results, etc. in whole or in part, is ONLY permitted with the explicit written agreement of the management board of AV- Comparatives, prior to any publication. AV-Comparatives and its testers cannot be held liable for any damage or loss, which might occur as a result of, or in connection with, the use of the information provided in this paper. We take every possible care to ensure the correctness of the basic data, but liability for the correctness of the test results cannot be taken by any representative of AV-Comparatives. We do not give any guarantee of the correctness, completeness, or suitability for a specific purpose of any of the information/content provided at any given time. No-one else involved in creating, producing or delivering test results shall be liable for any indirect, special or consequential damage, or loss of profits, arising out of, or related to, the use (or inability to use), the services provided by the website, test documents or any related data. For more information about AV-Comparatives and the testing methodologies please visit our website. AV-Comparatives (August 2015) - 6 -