AMTSO meets again to discuss better testing

Posted by   Virus Bulletin on   Feb 4, 2009

Further documents developed at Cupertino meeting.

This week has seen another meeting of the Anti-Malware Testing Standards Organization, AMTSO, hosted by security giant Symantec in its HQ town of Cupertino, California. The meeting was attended as usual by representatives of most of the major industry players and numerous testing bodies, as well as representatives from the worlds of academia and publishing.

The meeting covered a range matters, including the formation of a board of advisors for the group, the adoption of a new logo, the setting up of a review process to debate the quality of tests, and further work on several documents first proposed and discussed in the previous meeting, which took place in Oxford, UK last October.

Topics covered included gathering and handling malicious samples, the ethics of creating new samples, and how to properly test the full range of functionality in products, with a separate document covering 'in-the-cloud' technologies. These latest documents will support the official guidelines already ratified and published by the body, the central principles of testing and a best-practices document on running dynamic testing, both ratified at the Oxford meeting.

VB representatives were unable to attend the meeting, but played an active role in the creation of the in-the-cloud document, and look forward to helping get these latest documents finalized at the next meeting, which is due to take place in Budapest in early May.

More details on the meeting are blogged by AMTSO board member Stuart Taylor on the SophosLabs blog here and advisory board member Neil J. Rubenking here and here.

Posted on 04 February 2009 by Virus Bulletin

twitter.png
fb.png
linkedin.png
hackernews.png
reddit.png

 

Latest posts:

In memoriam: Prof. Ross Anderson

We were very sorry to learn of the passing of Professor Ross Anderson a few days ago.

In memoriam: Dr Alan Solomon

We were very sorry to learn of the passing of industry pioneer Dr Alan Solomon earlier this week.

New paper: Nexus Android banking botnet – compromising C&C panels and dissecting mobile AppInjects

In a new paper, researchers Aditya K Sood and Rohit Bansal provide details of a security vulnerability in the Nexus Android botnet C&C panel that was exploited in order to gather threat intelligence, and present a model of mobile AppInjects.

New paper: Collector-stealer: a Russian origin credential and information extractor

In a new paper, F5 researchers Aditya K Sood and Rohit Chaturvedi present a 360 analysis of Collector-stealer, a Russian-origin credential and information extractor.

VB2021 localhost videos available on YouTube

VB has made all VB2021 localhost presentations available on the VB YouTube channel, so you can now watch - and share - any part of the conference freely and without registration.

We have placed cookies on your device in order to improve the functionality of this site, as outlined in our cookies policy. However, you may delete and block all cookies from this site and your use of the site will be unaffected. By continuing to browse this site, you are agreeing to Virus Bulletin's use of data as outlined in our privacy policy.