Posts: 14,543
Threads: 9,565
Thanks Received: 9,059 in 7,209 posts
Thanks Given: 9,838
Joined: 12 September 18
30 August 19, 08:56
Quote:
Introduction
MRG Effitasis an independent IT security research company, with a heavy focus on applied malware analysis. Besides conventional AV efficacy testing and providing samples to other players in the AV field, we regularly test APT detection appliances and enterprise grade IT security products, simulating realistic attack scenarios. Android devices are used by around 2.3Billion people around the globe. As the overall platform philosophy allows an easy-to-opt-in platform with no mandated central application distribution platform, Android based malware has been on a constant rise since the early Gingerbread days. As a result, the market for Android AVs is heaving with applications that promise loud tag lines with ‘100% security’. A quick search on the Play Store for Antivirus products reveals literally hundreds of results –our test aims to help user decisions with a complex test regime with both in-the-wild and artificially crafted simulator samples and results that reflect a real-life efficacy of our test participants.
Tests Applied
MRG Effitas performed an in-depth test of several Android AV applications. The level of protection provided was measured in real-life scenarios with in-the-wild pieces of malware as well as some benign samples to map the shortcomings of the applied detection mechanisms. This report summarises the results of our efficacy tests. Testing took place on Android 6.0.0 Geny motion emulator images in June and July2019. Though dated, this Android version covers a large portion of user devices in the market. In order to ensure maximum compatibility for samples that contain native ARM code, the ARM Translation package has also been installed on emulator images.In cases where ARM native libraries have been extensively used and the AV application could not be installed or properly run on an x86 emulator, we opted for stock Nexus 5x devices with Android 6.0.0.In order to ensure the cleanliness of testing process, the Play Protect feature has been disabled.Our efforts were focused on the following aspects of the products.
Full PDF Report