http://weblog.av-comparatives.org/proactive-protection-wannacry-ransomware/
http://tinyurl.com/lbz658q
AV-C也做了21款防毒的测试,
防毒程式和病毒数据库的版本锁在5/12日,WannaCry出现之前,
也就是各家防毒的数据库尚未有WannaCry的病毒定义,
仅靠特征分析等主动式防御来抵御未知的病毒威胁.
在虚拟机里断网直接执行WannaCry的样本测试,
但是未公布各家防毒的详细设定.
测试结果:
Adaware Pro Security Protected
Avast Free Antivirus Protected
AVG Free Antivirus Protected
AVIRA Antivirus Pro Protected
Bitdefender Internet Security Protected
BullGuard Internet Security Protected
CrowdStrike Falcon Prevent Protected
Emsisoft Anti-Malware Protected
eScan Corporate 360 Protected
ESET Internet Security Not protected
F-Secure SAFE Protected
Fortinet FortiClient Not protected
Kaspersky Internet Security Protected
McAfee Internet Security Not protected
Microsoft Security Essentials Not protected
Panda Free Antivirus Protected
Seqrite Endpoint Security Protected
Tencent PC Manager Protected
Symantec Norton Security Protected
Trend Micro Internet Security Protected
VIPRE Advanced Security for HomeProtected
如上所述,这个测试是直接执行样本测试,
没有测试防火墙是否能够抵御SMB的漏洞入侵
(没有SMB的漏洞入侵,就不会发生后续主动的WannaCry感染),
同时后来WannaCry有多个变种,本测试也没有说明对变种的抵御效果.