Author Topic: "Spycar" anti-spyware test tool released  (Read 6383 times)

0 Members and 1 Guest are viewing this topic.

Spiritsongs

  • Guest
"Spycar" anti-spyware test tool released
« on: May 09, 2006, 06:37:53 PM »
WASHINGTON, DC.  On Friday, May 5, 2006, Intelguardians (www.intelguardians.com) announced the release of a free anti-spyware testing tool called Spycar.  Spycar is a suite of programs designed to mimic spyware-like behavior, but in a benign form.  "Intelguardians created Spycar so anyone could test the behavior-based defenses of an anti-spyware tool," said Ed Skoudis, co-founder and senior security analyst with Intelguardians. 


Tom Liston of Intelguardians, the lead developer of Spycar, provided further detail, "Many anti-spyware tools focus on signature-based detection.  That is, the vendor detects spyware by including thousands of signatures looking for specific sequences of bits on your hard drive or in memory.  Behavior-based detection, another approach, lets anti-spyware stop malicious software based on its actions, not a specific set of signatures."  Throughout early 2006, Intelguardians tested several enterprise anti-spyware tools, and found that their behavior-based defenses did not stop several spyware-like actions on a machine.  "As long as no signature has been defined for a given piece of spyware, many anti-spyware tools offer virtually no protection," said Liston.  Spycar allows individuals and organizations to evaluate their anti-spyware capabilities with a series of benign tests.


Every change made by Spycar is benign, designed simply to measure whether an anti-spyware tool can block or detect the change.  Furthermore, Spycar includes a scorebot/clean-up application called TowTruck that measures how well an anti-spyware tool defended the system, and automatically undoes every alteration made by Spycar. Spycar, the name, is in homage to the venerable EICAR anti-virus file.  The EICAR group (www.eicar.org) created this file about a decade ago so that anyone could test their anti-virus solution to verify it was working.  In honor of EICAR’s fine work, Intelguardians called its anti-spyware testing tool Spycar.


Spycar can be downloaded for free at www.spycar.org


------


Intelguardians is a Maryland-based information security research and consulting firm.  Founded in 2004, Intelguardians performs comprehensive assessments, architecture reviews, incident handling services, and digital forensics for organizations in the financial services, high-technology, legal, government, and military industries.  Intelguardians Labs performs deep research on topics including spyware and bot-net malicious code, virtual machine environment security implications, and the interstitial points between software and hardware including drivers and firmware.
 
 
 

CharleyO

  • Guest
Re: "Spycar" anti-spyware test tool released
« Reply #1 on: May 09, 2006, 09:55:57 PM »
***

I took this test and Spybot Teatimer blocked most of the changes executed by Spycar. Only 3 or 4 were not blocked.


***

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: "Spycar" anti-spyware test tool released
« Reply #2 on: May 09, 2006, 10:17:26 PM »
MS defender blocked all except the IE tab changes

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9406
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Re: "Spycar" anti-spyware test tool released
« Reply #3 on: May 09, 2006, 10:51:39 PM »
Interesting, though it would be more convenient if merged into just 1 executable.
Visit my webpage Angry Sheep Blog

justin1278

  • Guest
Re: "Spycar" anti-spyware test tool released
« Reply #4 on: May 09, 2006, 11:28:51 PM »
Spyware Doctor blocked none! I will contact PC Tools immediately.

CharleyO

  • Guest
Re: "Spycar" anti-spyware test tool released
« Reply #5 on: May 10, 2006, 12:06:36 AM »
***

MS defender blocked all except the IE tab changes

Yeah ... that is where the 3 or 4 were not blocked by Teatimer.


***