http://weblog.av-comparatives.org/proactive-protection-wannacry-ransomware/
http://tinyurl.com/lbz658q
AV-C也做了21款防毒的測試,
防毒程式和病毒資料庫的版本鎖在5/12日,WannaCry出現之前,
也就是各家防毒的資料庫尚未有WannaCry的病毒定義,
僅靠特徵分析等主動式防禦來抵禦未知的病毒威脅.
在虛擬機裡斷網直接執行WannaCry的樣本測試,
但是未公布各家防毒的詳細設定.
測試結果:
Adaware Pro Security Protected
Avast Free Antivirus Protected
AVG Free Antivirus Protected
AVIRA Antivirus Pro Protected
Bitdefender Internet Security Protected
BullGuard Internet Security Protected
CrowdStrike Falcon Prevent Protected
Emsisoft Anti-Malware Protected
eScan Corporate 360 Protected
ESET Internet Security Not protected
F-Secure SAFE Protected
Fortinet FortiClient Not protected
Kaspersky Internet Security Protected
McAfee Internet Security Not protected
Microsoft Security Essentials Not protected
Panda Free Antivirus Protected
Seqrite Endpoint Security Protected
Tencent PC Manager Protected
Symantec Norton Security Protected
Trend Micro Internet Security Protected
VIPRE Advanced Security for HomeProtected
如上所述,這個測試是直接執行樣本測試,
沒有測試防火牆是否能夠抵禦SMB的漏洞入侵
(沒有SMB的漏洞入侵,就不會發生後續主動的WannaCry感染),
同時後來WannaCry有多個變種,本測試也沒有說明對變種的抵禦效果.