AMTSO meets again to discuss better testing

Posted by   Virus Bulletin on   Feb 4, 2009

Further documents developed at Cupertino meeting.

This week has seen another meeting of the Anti-Malware Testing Standards Organization, AMTSO, hosted by security giant Symantec in its HQ town of Cupertino, California. The meeting was attended as usual by representatives of most of the major industry players and numerous testing bodies, as well as representatives from the worlds of academia and publishing.

The meeting covered a range matters, including the formation of a board of advisors for the group, the adoption of a new logo, the setting up of a review process to debate the quality of tests, and further work on several documents first proposed and discussed in the previous meeting, which took place in Oxford, UK last October.

Topics covered included gathering and handling malicious samples, the ethics of creating new samples, and how to properly test the full range of functionality in products, with a separate document covering 'in-the-cloud' technologies. These latest documents will support the official guidelines already ratified and published by the body, the central principles of testing and a best-practices document on running dynamic testing, both ratified at the Oxford meeting.

VB representatives were unable to attend the meeting, but played an active role in the creation of the in-the-cloud document, and look forward to helping get these latest documents finalized at the next meeting, which is due to take place in Budapest in early May.

More details on the meeting are blogged by AMTSO board member Stuart Taylor on the SophosLabs blog here and advisory board member Neil J. Rubenking here and here.

Posted on 04 February 2009 by Virus Bulletin



Latest posts:

Standalone product test: FireEye Endpoint

Virus Bulletin ran a standalone test on FireEye's Endpoint Security solution.

VB2017 video: Consequences of bad security in health care

Jelena Milosevic, a nurse with a passion for IT security, is uniquely placed to witness poor security practices in the health care sector, and to fully understand the consequences. Today, we publish the recording of a presentation given by Jelena at…

Vulnerabilities play only a tiny role in the security risks that come with mobile phones

Both bad news (all devices were pwnd) and good news (pwning is increasingly difficult) came from the most recent mobile Pwn2Own competition. But the practical security risks that come with using mobile phones have little to do with vulnerabilities.

VB2017 paper: The (testing) world turned upside down

At VB2017 in Madrid, industry veteran and ESET Senior Research Fellow David Harley presented a paper on the state of security software testing. Today we publish David's paper in both HTML and PDF format.

VB2017 video: Turning Trickbot: decoding an encrypted command-and-control channel

Trickbot, a banking trojan which appeared this year, seems to be a new, more modular, and more extensible malware descendant of the notorious Dyre botnet trojan. At VB2017, Symantec researcher Andrew Brandt presented a walkthrough of a typical…