<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Small Blue-Green Blog</title>
	<atom:link href="http://dharley.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://dharley.wordpress.com</link>
	<description>Security bits and pieces, and maybe some personal stuff</description>
	<lastBuildDate>Sat, 19 Sep 2009 19:06:15 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<cloud domain='dharley.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/a3928501ccd73c67742b5582bc549674?s=96&#038;d=http://s.wordpress.com/i/buttonw-com.png</url>
		<title>Small Blue-Green Blog</title>
		<link>http://dharley.wordpress.com</link>
	</image>
			<item>
		<title>Lost in Cyberspace</title>
		<link>http://dharley.wordpress.com/2009/09/19/lost-in-cyberspace/</link>
		<comments>http://dharley.wordpress.com/2009/09/19/lost-in-cyberspace/#comments</comments>
		<pubDate>Sat, 19 Sep 2009 17:39:58 +0000</pubDate>
		<dc:creator>David Harley</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://dharley.wordpress.com/?p=127</guid>
		<description><![CDATA[
       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=dharley.wordpress.com&blog=747988&post=127&subd=dharley&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><a href="http://dharley.files.wordpress.com/2009/09/xkcd1.jpg"><img class="alignleft size-medium wp-image-128" title="xkcd" src="http://dharley.files.wordpress.com/2009/09/xkcd1.jpg?w=300&#038;h=263" alt="xkcd" width="300" height="263" /></a></p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/dharley.wordpress.com/127/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/dharley.wordpress.com/127/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/dharley.wordpress.com/127/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/dharley.wordpress.com/127/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/dharley.wordpress.com/127/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/dharley.wordpress.com/127/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/dharley.wordpress.com/127/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/dharley.wordpress.com/127/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/dharley.wordpress.com/127/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/dharley.wordpress.com/127/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=dharley.wordpress.com&blog=747988&post=127&subd=dharley&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://dharley.wordpress.com/2009/09/19/lost-in-cyberspace/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/87a00d996b23fce4539dbdd792cc5d13?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">dharley</media:title>
		</media:content>

		<media:content url="http://dharley.files.wordpress.com/2009/09/xkcd1.jpg?w=300" medium="image">
			<media:title type="html">xkcd</media:title>
		</media:content>
	</item>
		<item>
		<title>Malware Naming, Shape Shifters &amp; Sympathetic Magic</title>
		<link>http://dharley.wordpress.com/2009/09/19/malware-naming-shape-shifters-sympathetic-magic/</link>
		<comments>http://dharley.wordpress.com/2009/09/19/malware-naming-shape-shifters-sympathetic-magic/#comments</comments>
		<pubDate>Sat, 19 Sep 2009 17:28:53 +0000</pubDate>
		<dc:creator>David Harley</dc:creator>
				<category><![CDATA[Conference papers]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Canterbury]]></category>
		<category><![CDATA[CFET 2009]]></category>
		<category><![CDATA[David Harley]]></category>
		<category><![CDATA[ESET]]></category>
		<category><![CDATA[Naming of Malware]]></category>

		<guid isPermaLink="false">http://dharley.wordpress.com/?p=120</guid>
		<description><![CDATA[This is the paper on malware naming I presented at CFET 2009 in Canterbury: http://www.eset.com/download/whitepapers/cfet2009naming.pdf
Abstract
Once upon a time, one infection by specific malware looked much like another infection, to an antivirus scanner if not to the naked eye. Even back then, virus naming wasn&#8217;t very consistent between vendors, but at least virus encyclopaedias and third-party resources [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=dharley.wordpress.com&blog=747988&post=120&subd=dharley&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>This is the paper on malware naming I presented at CFET 2009 in Canterbury: <a href="http://www.eset.com/download/whitepapers/cfet2009naming.pdf">http://www.eset.com/download/whitepapers/cfet2009naming.pdf</a></p>
<p>Abstract</p>
<p>Once upon a time, one infection by specific malware looked much like another infection, to an antivirus scanner if not to the naked eye. Even back then, virus naming wasn&#8217;t very consistent between vendors, but at least virus encyclopaedias and third-party resources like vgrep made it generally straightforward to map one vendor&#8217;s name for a virus to another vendor&#8217;s name for the same malware.</p>
<p>In 2009, though, the threat landscape looks very different. Viruses and other replicative malware, while far from extinct, pose a comparatively manageable problem compared to other threats with the single common characteristic of malicious intent. Proof-of-Concept code with sophisticated self-replicating mechanisms is of less interest to today&#8217;s malware authors than shape-shifting Trojans that change their appearance frequently to evade detection and are intended to make money for criminals rather than getting adolescent admiration and bragging rights.</p>
<p>Sheer sample glut makes it impossible to categorize and standardize on naming for each and every unique sample out of tens of thousands processed each day.</p>
<p>Detection techniques such as generic signatures, heuristics and sandboxing have also changed the ways in which malware is detected and therefore how it is classified, confounding the old assumptions of a simple one-to-one relationship between a detection label and a malicious program. This presentation will explain how one-to-many, many-to-one, or many-to-many models are at least as likely as the old one-detection-per-variant model, why &#8220;Do you detect Win32/UnpleasantVirus.EG?&#8221; is such a difficult question to answer, and explain why exact indication is not a pre-requisite for detection and remediation of malware, and actually militates against the most effective use of analysis and development time and resources. But what is the information that the end-user or end-site really needs to know about an incoming threat?</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/dharley.wordpress.com/120/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/dharley.wordpress.com/120/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/dharley.wordpress.com/120/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/dharley.wordpress.com/120/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/dharley.wordpress.com/120/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/dharley.wordpress.com/120/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/dharley.wordpress.com/120/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/dharley.wordpress.com/120/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/dharley.wordpress.com/120/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/dharley.wordpress.com/120/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=dharley.wordpress.com&blog=747988&post=120&subd=dharley&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://dharley.wordpress.com/2009/09/19/malware-naming-shape-shifters-sympathetic-magic/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/87a00d996b23fce4539dbdd792cc5d13?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">dharley</media:title>
		</media:content>
	</item>
		<item>
		<title>A Myth Laid to Rest</title>
		<link>http://dharley.wordpress.com/2009/09/19/a-myth-laid-to-rest/</link>
		<comments>http://dharley.wordpress.com/2009/09/19/a-myth-laid-to-rest/#comments</comments>
		<pubDate>Sat, 19 Sep 2009 16:15:37 +0000</pubDate>
		<dc:creator>David Harley</dc:creator>
				<category><![CDATA[Cartoons]]></category>

		<guid isPermaLink="false">http://dharley.wordpress.com/?p=113</guid>
		<description><![CDATA[
       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=dharley.wordpress.com&blog=747988&post=113&subd=dharley&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><a href="http://dharley.files.wordpress.com/2009/09/acme3.jpg"><img class="alignleft size-medium wp-image-112" title="acme3" src="http://dharley.files.wordpress.com/2009/09/acme3.jpg?w=461&#038;h=289" alt="acme3" width="461" height="289" /></a></p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/dharley.wordpress.com/113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/dharley.wordpress.com/113/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/dharley.wordpress.com/113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/dharley.wordpress.com/113/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/dharley.wordpress.com/113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/dharley.wordpress.com/113/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/dharley.wordpress.com/113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/dharley.wordpress.com/113/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/dharley.wordpress.com/113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/dharley.wordpress.com/113/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=dharley.wordpress.com&blog=747988&post=113&subd=dharley&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://dharley.wordpress.com/2009/09/19/a-myth-laid-to-rest/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/87a00d996b23fce4539dbdd792cc5d13?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">dharley</media:title>
		</media:content>

		<media:content url="http://dharley.files.wordpress.com/2009/09/acme3.jpg?w=300" medium="image">
			<media:title type="html">acme3</media:title>
		</media:content>
	</item>
		<item>
		<title>Vikings</title>
		<link>http://dharley.wordpress.com/2009/09/19/vikings/</link>
		<comments>http://dharley.wordpress.com/2009/09/19/vikings/#comments</comments>
		<pubDate>Sat, 19 Sep 2009 15:55:08 +0000</pubDate>
		<dc:creator>David Harley</dc:creator>
				<category><![CDATA[Cartoons]]></category>

		<guid isPermaLink="false">http://dharley.wordpress.com/?p=103</guid>
		<description><![CDATA[
       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=dharley.wordpress.com&blog=747988&post=103&subd=dharley&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><a href="http://dharley.files.wordpress.com/2009/09/viking3.jpg"><img class="alignleft size-medium wp-image-104" title="viking3" src="http://dharley.files.wordpress.com/2009/09/viking3.jpg?w=406&#038;h=219" alt="viking3" width="406" height="219" /></a></p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/dharley.wordpress.com/103/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/dharley.wordpress.com/103/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/dharley.wordpress.com/103/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/dharley.wordpress.com/103/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/dharley.wordpress.com/103/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/dharley.wordpress.com/103/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/dharley.wordpress.com/103/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/dharley.wordpress.com/103/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/dharley.wordpress.com/103/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/dharley.wordpress.com/103/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=dharley.wordpress.com&blog=747988&post=103&subd=dharley&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://dharley.wordpress.com/2009/09/19/vikings/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/87a00d996b23fce4539dbdd792cc5d13?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">dharley</media:title>
		</media:content>

		<media:content url="http://dharley.files.wordpress.com/2009/09/viking3.jpg?w=300" medium="image">
			<media:title type="html">viking3</media:title>
		</media:content>
	</item>
		<item>
		<title>Hats</title>
		<link>http://dharley.wordpress.com/2009/09/19/hats/</link>
		<comments>http://dharley.wordpress.com/2009/09/19/hats/#comments</comments>
		<pubDate>Sat, 19 Sep 2009 14:25:13 +0000</pubDate>
		<dc:creator>David Harley</dc:creator>
				<category><![CDATA[Cartoons]]></category>

		<guid isPermaLink="false">http://dharley.wordpress.com/?p=85</guid>
		<description><![CDATA[ 

I&#8217;m a badass hacker, so of course I wear a black hat

 
 
  
I&#8217;m a good guy who is dedicated to fighting black hats, so I get to wear a white hat 

 
 
 
 
I&#8217;m a good guy who sometimes plays with the bad guys, so I have to wear a grey hat 
 
 I&#8217;m an antivirus guy and I&#8217;m always getting dumped [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=dharley.wordpress.com&blog=747988&post=85&subd=dharley&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><div class="mceTemp"> </div>
<div class="mceTemp"><img class="alignleft size-thumbnail wp-image-94" title="hats1a" src="http://dharley.files.wordpress.com/2009/09/hats1a1.jpg?w=133&#038;h=150" alt="hats1a" width="133" height="150" /></div>
<div class="mceTemp">I&#8217;m a badass hacker, so of course I wear a black hat</div>
<div class="mceTemp mceIEcenter">
<div class="mceTemp"> </div>
<div class="mceTemp"> </div>
<div class="mceTemp"> <img class="size-thumbnail wp-image-86 alignleft" style="border:0;" title="hats2a" src="http://dharley.files.wordpress.com/2009/09/hats2a.jpg?w=115&#038;h=150" alt="I'm a good guy who fights black hats, so I wear a white hat" width="115" height="150" /> </div>
<div class="mceTemp">I&#8217;m a good guy who is dedicated to fighting black hats, so I get to wear a white hat </div>
<p><a href="http://dharley.files.wordpress.com/2009/09/hats3a1.jpg"><img class="size-thumbnail wp-image-88  alignright" style="border:0;" title="hats3a" src="http://dharley.files.wordpress.com/2009/09/hats3a1.jpg?w=116&#038;h=150" alt="I'm a good guy who likes to play with the bad guys, so I wear a grey hat." width="116" height="150" /></a></p>
<p> </p>
<p> </p>
<p> </p></div>
<p style="text-align:left;"> </p>
<p style="text-align:left;">I&#8217;m a good guy who sometimes plays with the bad guys, so I have to wear a grey hat </p>
<p style="text-align:left;"> </p>
<p style="text-align:left;"><a href="http://dharley.files.wordpress.com/2009/09/hats4a1.jpg"><img class="size-thumbnail wp-image-90 alignleft" style="border:0;" title="hats4a" src="http://dharley.files.wordpress.com/2009/09/hats4a1.jpg?w=121&#038;h=150" alt="I'm an antivirus guy and I get dumped on all the time by these other guys, so I wear a hard hat" width="121" height="150" /></a> I&#8217;m an antivirus guy and I&#8217;m always getting dumped on by these other guys, so I wear a hard hat</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/dharley.wordpress.com/85/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/dharley.wordpress.com/85/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/dharley.wordpress.com/85/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/dharley.wordpress.com/85/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/dharley.wordpress.com/85/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/dharley.wordpress.com/85/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/dharley.wordpress.com/85/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/dharley.wordpress.com/85/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/dharley.wordpress.com/85/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/dharley.wordpress.com/85/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=dharley.wordpress.com&blog=747988&post=85&subd=dharley&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://dharley.wordpress.com/2009/09/19/hats/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/87a00d996b23fce4539dbdd792cc5d13?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">dharley</media:title>
		</media:content>

		<media:content url="http://dharley.files.wordpress.com/2009/09/hats1a1.jpg?w=133" medium="image">
			<media:title type="html">hats1a</media:title>
		</media:content>

		<media:content url="http://dharley.files.wordpress.com/2009/09/hats2a.jpg?w=115" medium="image">
			<media:title type="html">hats2a</media:title>
		</media:content>

		<media:content url="http://dharley.files.wordpress.com/2009/09/hats3a1.jpg?w=116" medium="image">
			<media:title type="html">hats3a</media:title>
		</media:content>

		<media:content url="http://dharley.files.wordpress.com/2009/09/hats4a1.jpg?w=121" medium="image">
			<media:title type="html">hats4a</media:title>
		</media:content>
	</item>
		<item>
		<title>Making Sense of Anti-Malware Comparative Testing</title>
		<link>http://dharley.wordpress.com/2009/06/18/making-sense-of-anti-malware-comparative-testing/</link>
		<comments>http://dharley.wordpress.com/2009/06/18/making-sense-of-anti-malware-comparative-testing/#comments</comments>
		<pubDate>Thu, 18 Jun 2009 21:11:22 +0000</pubDate>
		<dc:creator>David Harley</dc:creator>
				<category><![CDATA[Articles]]></category>
		<category><![CDATA[anti-malware testing]]></category>
		<category><![CDATA[anti-malware comparative testing]]></category>
		<category><![CDATA[Elsevier]]></category>
		<category><![CDATA[preprint]]></category>
		<category><![CDATA[testing and evaluation]]></category>

		<guid isPermaLink="false">http://dharley.wordpress.com/?p=79</guid>
		<description><![CDATA[[To return to ESET white papers page click here: http://www.eset.com/threat-center/blog.]
This is an Elsevier article preprint of an article on the main issues around comparative testing of antivirus/antimalware products, made available here by permission of Elsevier.
The fully formatted, proofed and reviewed version is available at http://dx.doi.org/10.1016/j.istr.2009.03.002.
Abstract:
If there’s a single problem illustrating the gulf between the anti-malware industry [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=dharley.wordpress.com&blog=747988&post=79&subd=dharley&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>[To return to ESET white papers page click here: <a href="http://www.eset.com/threat-center/blog">http://www.eset.com/threat-center/blog</a>.]</p>
<p>This is an <a href="http://dharley.files.wordpress.com/2009/06/elsevier-article-preprint.pdf">Elsevier article preprint</a> of an article on the main issues around comparative testing of antivirus/antimalware products, made available here by permission of Elsevier.</p>
<p>The fully formatted, proofed and reviewed version is available at <a href="http://dx.doi.org/10.1016/j.istr.2009.03.002">http://dx.doi.org/10.1016/j.istr.2009.03.002</a>.</p>
<p>Abstract:</p>
<p><em>If there’s a single problem illustrating the gulf between the anti-malware industry and the rest of the online world, it revolves around the difficulties and misunderstandings that plague product testing and evaluation. This article considers these issues and the initiatives taken by the anti-malware and testing sectors to resolve some of them.</em></p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/dharley.wordpress.com/79/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/dharley.wordpress.com/79/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/dharley.wordpress.com/79/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/dharley.wordpress.com/79/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/dharley.wordpress.com/79/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/dharley.wordpress.com/79/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/dharley.wordpress.com/79/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/dharley.wordpress.com/79/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/dharley.wordpress.com/79/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/dharley.wordpress.com/79/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=dharley.wordpress.com&blog=747988&post=79&subd=dharley&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://dharley.wordpress.com/2009/06/18/making-sense-of-anti-malware-comparative-testing/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/87a00d996b23fce4539dbdd792cc5d13?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">dharley</media:title>
		</media:content>
	</item>
		<item>
		<title>Execution Context in Anti-Malware Testing</title>
		<link>http://dharley.wordpress.com/2009/05/15/execution-context-in-anti-malware-testing/</link>
		<comments>http://dharley.wordpress.com/2009/05/15/execution-context-in-anti-malware-testing/#comments</comments>
		<pubDate>Fri, 15 May 2009 16:19:19 +0000</pubDate>
		<dc:creator>David Harley</dc:creator>
				<category><![CDATA[Conference papers]]></category>
		<category><![CDATA[anti-malware testing]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[AMTSO]]></category>
		<category><![CDATA[comparative testing]]></category>
		<category><![CDATA[David Harley]]></category>
		<category><![CDATA[EICAR]]></category>
		<category><![CDATA[ESET]]></category>
		<category><![CDATA[Execution context]]></category>
		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://dharley.wordpress.com/?p=61</guid>
		<description><![CDATA[[Go back to ESET White Papers page.]
[Go back to ESET blog.]
This is one of my most recent papers, presented by Randy Abrams and myself on behalf of ESETat the EICAR 2009 Conference in Berlin.

Abstract 
Anti-malware testing methodology remains a contentious area because many testers are insufficiently aware of the complexities of malware and anti-malware technology. [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=dharley.wordpress.com&blog=747988&post=61&subd=dharley&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>[<a title="ESET white papers" href="http://www.eset.com/download/whitepapers.php" target="_self">Go back to ESET White Papers page.</a>]<br />
[<a title="ESET Threat Blog" href="http://www.eset.com/threat-center/blog/" target="_self">Go back to ESET blog</a>.]</p>
<p>This is one of my most recent papers, presented by Randy Abrams and myself on behalf of ESETat the EICAR 2009 Conference in Berlin.</p>
<p><a href="http://dharley.files.wordpress.com/2009/05/eicar-execution-context-paper-final.pdf"></a></p>
<p><strong>Abstract </strong></p>
<p>Anti-malware testing methodology remains a contentious area because many testers are insufficiently aware of the complexities of malware and anti-malware technology. This results in the frequent publication of comparative test results that are misleading and often totally invalid because they don&#8217;t accurately reflect the detection capability of the products under test. Because many tests are based purely on static testing, where products are tested by using them to scan presumed infected objects passively, those products that use more proactive techniques such as active heuristics, emulation and sandboxing are frequently disadvantaged in such tests, even assuming that sample sets are correctly validated.</p>
<p>Recent examples of misleading published statistical data include the ranking of anti-malware products according to reports returned by multi-scanner sample submission sites, even though the better examples of such sites are clear that this is not an appropriate use of their services, and the use of similar reports to generate other statistical data such as the assumed prevalence of specific malware. These problems, especially when combined with other testing problem areas such as accurate sample validation and classification, introduce major statistical anomalies.</p>
<p>In this paper, it is proposed to review the most common mainstream anti-malware detection techniques (search strings and simple signatures, generic signatures, passive heuristics, active heuristics and behaviour analysis) in the context of anti-malware testing for purposes of single product testing, comparative detection testing, and generation of prevalence and global detection data. Specifically, issues around static and dynamic testing will be examined. Issues with additional impact, such as sample classification and false positives, will be considered &#8211; not only false identification of innocent applications as malware, but also contentious classification issues such as (1) the trapping of samples, especially corrupted or truncated honeypot and honeynet samples intended maliciously but unable to pose a direct threat to target systems (2) use of such criteria as packing and obfuscation status as a primary heuristic for the identification of malware.</p>
<p><a href="http://dharley.files.wordpress.com/2009/05/eicar-execution-context-paper.pdf">EICAR execution context paper</a></p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/dharley.wordpress.com/61/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/dharley.wordpress.com/61/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/dharley.wordpress.com/61/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/dharley.wordpress.com/61/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/dharley.wordpress.com/61/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/dharley.wordpress.com/61/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/dharley.wordpress.com/61/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/dharley.wordpress.com/61/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/dharley.wordpress.com/61/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/dharley.wordpress.com/61/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=dharley.wordpress.com&blog=747988&post=61&subd=dharley&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://dharley.wordpress.com/2009/05/15/execution-context-in-anti-malware-testing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/87a00d996b23fce4539dbdd792cc5d13?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">dharley</media:title>
		</media:content>
	</item>
		<item>
		<title>Phish Phodder: Is User Education Helping or Hindering?</title>
		<link>http://dharley.wordpress.com/2009/04/14/phish-phodder-is-user-education-helping-or-hindering/</link>
		<comments>http://dharley.wordpress.com/2009/04/14/phish-phodder-is-user-education-helping-or-hindering/#comments</comments>
		<pubDate>Tue, 14 Apr 2009 09:40:29 +0000</pubDate>
		<dc:creator>David Harley</dc:creator>
				<category><![CDATA[Conference papers]]></category>
		<category><![CDATA[Andrew Lee]]></category>
		<category><![CDATA[David Harley]]></category>
		<category><![CDATA[ESET]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[phishing quizzes]]></category>
		<category><![CDATA[Small Blue-Green World]]></category>
		<category><![CDATA[user education]]></category>
		<category><![CDATA[Virus Bulletin]]></category>

		<guid isPermaLink="false">http://dharley.wordpress.com/?p=42</guid>
		<description><![CDATA["Phish Phodder" is a paper by David Harley and Andrew Lee on anti-phishing resources and education, written for and presented at the Virus Bulletin conference in 2007.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=dharley.wordpress.com&blog=747988&post=42&subd=dharley&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>[<a title="ESET white papers" href="http://www.eset.com/download/whitepapers.php" target="_self">Go back to ESET White Papers page.</a>]<br />
[<a title="ESET Threat Blog" href="http://www.eset.com/threat-center/blog/" target="_self">Go back to ESET blog</a>.]</p>
<p>David Harley &amp; Andrew Lee, &#8220;Phish Phodder: Is User Education Helping or Hindering?&#8221; (<a href="http://dharley.files.wordpress.com/2009/04/davidharleyandrewleevb2007.pdf">davidharleyandrewleevb2007</a>), September 2007, Virus Bulletin. Copyright is held by Virus Bulletin Ltd, but the document is made available on this site for personal use free of charge by permission of Virus Bulletin.</p>
<p>ABSTRACT<br />
Mostly, security professionals can spot a phish a mile off. If they do err, it’s usually on the side of caution, for instance when real organizations fail to observe best practice and generate phish-like marketing messages. Many sites are now addressing the problem with phishing quizzes, intended to teach the everyday user to distinguish phish from phowl (sorry). Academic papers on why people fall for phishing mails and sites are something of a growth industry. Yet phishing attacks continue to increase, and while accurate and up-to-date figures for financial loss are hard to come by, indications are that losses from phishing and other forms of identity theft continue to climb.</p>
<p>This paper:<br />
1. Evaluates current research on how end users are susceptible to phishing attacks and ID theft.<br />
2. Evaluates a range of web-based educational and informational resources in general and summarizes the pros and cons of the quiz approach in particular.<br />
3. Reviews the shared responsibility of phished institutions and phishing mail targets for reducing the impact of phishing scams. What constitutes best practice for finance-related mail-outs and e-commerce transactions? How far can we rely on detection technology?</p>
<p><a href="http://dharley.files.wordpress.com/2009/04/davidharleyandrewleevb2007.pdf"></a></p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/dharley.wordpress.com/42/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/dharley.wordpress.com/42/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/dharley.wordpress.com/42/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/dharley.wordpress.com/42/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/dharley.wordpress.com/42/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/dharley.wordpress.com/42/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/dharley.wordpress.com/42/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/dharley.wordpress.com/42/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/dharley.wordpress.com/42/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/dharley.wordpress.com/42/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=dharley.wordpress.com&blog=747988&post=42&subd=dharley&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://dharley.wordpress.com/2009/04/14/phish-phodder-is-user-education-helping-or-hindering/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/87a00d996b23fce4539dbdd792cc5d13?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">dharley</media:title>
		</media:content>
	</item>
		<item>
		<title>A Musical Interlude</title>
		<link>http://dharley.wordpress.com/2009/04/11/a-musical-interlude/</link>
		<comments>http://dharley.wordpress.com/2009/04/11/a-musical-interlude/#comments</comments>
		<pubDate>Sat, 11 Apr 2009 14:12:08 +0000</pubDate>
		<dc:creator>David Harley</dc:creator>
				<category><![CDATA[Music]]></category>
		<category><![CDATA[David Harley]]></category>

		<guid isPermaLink="false">http://dharley.wordpress.com/?p=36</guid>
		<description><![CDATA[After only 20 years (well, nearly) of being connected to the Internet, I&#8217;ve finally got around to making some music available that I recorded in the 80s (I did sell some copies at the time, so this isn&#8217;t completely unheard stuff). Although this is studio recorded stuff, I don&#8217;t have access to the master tapes, so [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=dharley.wordpress.com&blog=747988&post=36&subd=dharley&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>After only 20 years (well, nearly) of being connected to the Internet, I&#8217;ve finally got around to making some music available that I recorded in the 80s (I did sell some copies at the time, so this isn&#8217;t completely unheard stuff). Although this is studio recorded stuff, I don&#8217;t have access to the master tapes, so these tracks are taken from cassettes. Still, they sound better than I expected through decent headphones.</p>
<p>Three tracks are from an unreleased album made with Bob Theil, Don MacLeod, Bob Cairns, and Pat Orchard. There are also a handful of tracks from &#8220;Sheer Bravado&#8221; (more to come) and, eventually, there&#8217;ll be more  from &#8220;Scriptwrecked&#8221;. There will also be some more recent stuff eventually: I&#8217;ve got some BOSS recording kit that I&#8217;m dying to do more work with.</p>
<p>The relevant page on the main Small Blue-Green World site is <a title="David Harley recordings" href="http://www.smallblue-greenworld.co.uk/mp3s.htm" target="_blank">here</a>.</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/dharley.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/dharley.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/dharley.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/dharley.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/dharley.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/dharley.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/dharley.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/dharley.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/dharley.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/dharley.wordpress.com/36/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=dharley.wordpress.com&blog=747988&post=36&subd=dharley&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://dharley.wordpress.com/2009/04/11/a-musical-interlude/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/87a00d996b23fce4539dbdd792cc5d13?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">dharley</media:title>
		</media:content>
	</item>
		<item>
		<title>Who Will Test The Testers?</title>
		<link>http://dharley.wordpress.com/2009/04/11/who-will-test-the-testers/</link>
		<comments>http://dharley.wordpress.com/2009/04/11/who-will-test-the-testers/#comments</comments>
		<pubDate>Sat, 11 Apr 2009 13:49:59 +0000</pubDate>
		<dc:creator>David Harley</dc:creator>
				<category><![CDATA[Conference papers]]></category>
		<category><![CDATA[AMTSO]]></category>
		<category><![CDATA[Andrew Lee]]></category>
		<category><![CDATA[anti-malware]]></category>
		<category><![CDATA[comparative testing]]></category>
		<category><![CDATA[David Harley]]></category>

		<guid isPermaLink="false">http://dharley.wordpress.com/?p=33</guid>
		<description><![CDATA[A paper by David Harley and Andrew Lee on making anti-malware testers more accountable to their audiences<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=dharley.wordpress.com&blog=747988&post=33&subd=dharley&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>[<a title="ESET white papers" href="http://www.eset.com/download/whitepapers.php" target="_self">Go back to ESET White Papers page.</a>]<br />
[<a title="ESET Threat Blog" href="http://www.eset.com/threat-center/blog/" target="_self">Go back to ESET blog</a>.]</p>
<p><a title="Who will test the testers?" href="http://dharley.files.wordpress.com/2009/04/harley-lee-vb2008-3.pdf" target="_blank">Who Will Test The Testers?</a> is a paper by myself and Andrew Lee on making anti-malware testers more accountable to their audiences, presented at the Virus Bulletin Conference in 2008 and published in the conference proceedings.</p>
<p>David Harley BA CISSP FBCS CITP &amp; Andrew Lee CISSP, &#8220;Who Will Test The Testers?&#8221;, October 2008, Virus Bulletin. Copyright is held by Virus Bulletin Ltd, but the paper is made available on this site for personal use free of charge by permission of <a title="Virus Bulletin" href="http://www.virusbtn.com" target="_blank">Virus Bulletin</a>.</p>
<p>ABSTRACT</p>
<p>The anti-malware industry has been plagued since its earliest days by one poorly designed comparative test after another. In 2007, some of the best anti-malware researchers, comparative testers and product certification specialists took the first steps towards raising product testing standards with the formation of a group specifically focused on establishing standards and methodologies, educating both consumers and testers in discrimination between good and bad practice, and providing objective analyses of current testing practices. This paper summarizes current initiatives by the Anti-Malware Testing<br />
Standards Organization and other groups, but also considers next steps, going beyond objectifying methodology, educational issues and blowing away the fog of misinformation and fallacy, to the next level. Underlying these vital issues is a question: is it possible to make testers and certifying authorities more accountable for the quality of their testing methods and the accuracy of the conclusions they draw based on that testing?</p>
<p>This paper attempts to answer that question.</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/dharley.wordpress.com/33/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/dharley.wordpress.com/33/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/dharley.wordpress.com/33/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/dharley.wordpress.com/33/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/dharley.wordpress.com/33/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/dharley.wordpress.com/33/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/dharley.wordpress.com/33/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/dharley.wordpress.com/33/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/dharley.wordpress.com/33/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/dharley.wordpress.com/33/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=dharley.wordpress.com&blog=747988&post=33&subd=dharley&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://dharley.wordpress.com/2009/04/11/who-will-test-the-testers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/87a00d996b23fce4539dbdd792cc5d13?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">dharley</media:title>
		</media:content>
	</item>
	</channel>
</rss>