|
BluePoint is one of a number of vendors who have appeared on the scene, presenting their solution to ensure our safety in the face of the dramatic increase in malware volumes we face. It is estimated that currently, approximately 37,000 new pieces of malware emerge each day, so in 2009, security vendors can expect to encounter some 13.5 Million new samples. One vendor cataloged a total of 18 Million samples since their foundation in 1988, but has seen that number rise by 60% this year alone and now records over 30 million in total. Vendors generally have to receive malware samples in order to analyze it and then defend against it, however, with the current volumes of malware being as high as they are, they are unable to keep up - malware is appearing at a rate higher than their capacity to capture and process it, so therefore, their customers are at risk. Vendors such as Prevx and Panda are possibly two of the most well known vendors who use cloud technology in an attempt to keep up with rise in malware. These cloud AVs use heard or collective intelligence techniques to detect new malware, analyze it and protect their users in a much reduced timescale. Cloud technology can allow vendors to protect users against new threats found in their community within minutes, drastically reducing the window of opportunity for malware to infect a system. BluePoint Security uses its own proprietary cloud engine and so should be able to protect against new threats very rapidly, however, in addition to this, it has another security feature. BluePoint intercepts (temporarily blocks)all attempts to execute code on the system and checks it against a white list. If the code is found to be on the white list (and is therefore known to be good) it will then allow it to execute. If the code is not on the white list, the user is asked if they want to run the code / application. Bluepoint can be set so it does not give the user the option to decide and under this setting, theoretically, it is impossible for malware to execute on the system. Bluepoint Security caught our attention a few weeks ago and we have been looking at it since then and decided to put it to the test.
Reviewing process had three stages:
1. On Demand scan on 50.000 samples of malware (June,July,August and September) 2. Self Protection test where we used various tools with which we tried to disable BluePoint Security and its services. 3. System Protection test - BluePoint Security was tested in Real Time against various most dangerous malware samples (better known as System Killers)
Result of our reviewing process:
1. On Demand scan test - BluePoint Security failed to detect only 122 samples of malware out of 50.000, scoring a detection rate of 99.76%.
2. Self Protection Test - BluePoint Security successfully blocked all 10 attempts to disable it and its services.
3. System Protection Test - BluePoint Security successfully detected and blocked all 15 System Killers leaving the system unharmed and fully operational.
Conclusion:
BluePoint Security may be a new product but it is able to provide a very high level of protection. Installation is fast, configuration is very simple so that even the lesser experienced users will not have any problems with settings. Alert windows are small and show detailed information on possible threats. We were very pleased with BluePoint's ability to defend the system, we only hope that in upcoming versions we will see a few more features especially in scanning settings (right-click scan for example).
We will continue to evaluate this product in our upcoming tests.
Malware Research Group
_________________ Malware Research Group Internet Security & Solutions
|