

Images courtesy of http://www.wilderssecurity.com/showpost.php?p=1270399&postcount=21
I know a lot of people are suspicious about products from China, but it can't be denied that there are many excellent security products from China these days, such as HIPS like
ProSecurity,
EqSecure and
PowerShadow (similar to
Returnil ).
But what about antiviruses? Everyone is familiar with the big 3 in antiviruses,
AVG,
Antivir and
AVAST! They are free products that provide real-time protection though they lack many features of their fully featured big brothers. In particular, Antivir which has the best reputation and best test scores, lacks many features such as web shield (Http scanner) and antispyware protection.
But what if i told you there was a free product that had exactly the same features as the paid version? Crazy? That would be
Rising Antivirus .
Well that's not a big deal, if the full paid version had very few features to begin with, but let's take a look at these set of features
"Active Defense Technology Rising’s Active Defense Technology is designed to prevent the execution of malicious programs. It provides more open rules for advanced user customization, which enables the user to define unique defense rules depending upon the special circumstances of his/her own system, thus maximizing the system’s protection.
Patented Scanning Technology for Unknown Viruses
Rising's scanning technology for unknown viruses is protected by patents in the United States of America and Europe. This technology protects your personal computer before new virus definitions are available. Unknown Virus Scan&Clean(Patent No.:ZL 01 1 17726.8)
Patented Fully Automatic SmartUpdate
Rising's Automatic SmartUpdate Technology enables Rising software automatically detect the latest version and automatically updates. RISING Virus Lab provides updates at least three times per day with instant updates. Fully Automatic SmartUpdate(Patent No.:ZL 01 1 42155.X)
Smart Virtual Machine with Behaviour & Packing Pattern Recognition
RISING Antivirus comes with an integrated smart virtual machine, which is used for virus scanning and malware recognition. RISING's proprietary smart virtual machine technology provides the additional safety for your computer without slowing down your system. Suspected code and program can be run in this virtual machine for RISING Antivirus to check for potential malicious behaviour. RISING's Behaviour & Packing Pattern Recognition allows to test such potential malware thoroughly without influencing the performance of your PC and protects your system against new viruses and unknown viruses.
Application Protection
Application Protection can protect specified applications from attack by malicious programs. A user can apply rules to game software, instant messenger, etc. to customize protection. Rising Anti-Virus 2008 provides users with eight rules: Anti-DLL Injection, Anti-CodeInjection, Anti-Memory Modification, Anti-Memory Read, Prevent Suspension, Prevent Termination, Anti-Simulated Sending, and Anti-Simulated Key.
<<>
Self-Protection
Previous versions have not offered complete protection to Rising products themselves, resulting in damage to Rising products by specific viruses such as Orange August. The spread of such viruses has prevented users from running Rising products or to browse the Rising website. We now employ Active Defense Technology to address this omission.
Application Access Control
Application Access Control monitors suspicious programs to limit their access to computer resources.
Program Startup Control
Program Startup Control allows users to monitor the startup process of programs, thus being able to intercept and prevent the execution of unknown malicious programs as well as detecting any modification of applications
Malicious Behavior Detection
Malicious Behavior Detection monitors programs running in the system to detect and report the behavior patterns of malicious code, optionally allowing the user to authorize or reject suspicious activity.
Hidden Process Detection
Hidden Process Detection can detect processes that cannot be seen in the Windows Task Manager that may contain malicious code, including rootkits.
Computer Security Check
The Computer Security Check function informs the user of the current security level and guides him/her in strengthening it to prevent intrusions.
Security Tool Integration Platform
The Security Tool Integration platform provides the following tools: Other Embedded Scan, Registration Wizard, Latest Installation Creation Tool, Application Protection Wizard, Vulnerability Check, and View Quarantine."
Granted though most of this sounds impressive , they are just very detailed explainations of technical features most antivirus has (also it doesn't offer webshields that the free versions of AVAST! and AVG does) . But what is most exciting to me is that it has a full fledged HIPS (see headings under "application protection", application access control", "program startup control", "malicious behavior detection").


Images courtesy of http://www.wilderssecurity.com/showpost.php?p=1270399&postcount=21
Being feature rich is good, but this is after all an Antivirus so how is it's detection rate. It is somewhat interesting to note that despite being in the internet age, antiviruses are stronger in regions where their main user base is (if their users are mostly in china, they will tend to be alerted to malware that is "popular" in china), so given that most readers to this blog are not from china, there might be concerns on how good the detection rate is.
First good news, it Checkmark certified by Westcoast labs.
The Bad news is it is not rated regularly by av-comparatives because it does not meet the minimum standard (though the last test to determine this was in Jan 2007 where it scored 71% it might have improved since then) .
It has being tested twice so far on VB100% and failed twice (needs free registration).
The lastest virus.gr test June 2008 (note the testing methodology of this test has being disputed because the test-bed quality is uncertain, in particular "samples were choosen by using those products: Kaspersky, F-Prot, Nod32, Dr.Web, BitDefender and McAfee;" which gives these products a big advantage of course see also) gives it 85.87% , AVG 94.85%, Antivir 94.85%, and Avast! 93.78%.
OITC stats based on scanning using Virustotal (note this testing methodology is not the best) currently shows Rising with 17%, compared to AVG 37%, Antivir 68% AVAST 27%.
Other tests here and here tell the same story.
The basic story one gets is that Rising is still not very strong on the detection front. It should be noted that the tests here rely on on-demand scans, but do not include the HIPS features of Rising AV which should improve results quite a bit (also relies on user knowledge of course).
So should one use this to replace one's antivirus given the relatively poor performance in tests? Currently it is unclear, but one interesting approach is to turn off the real time Antivirus, but use the HIPS features!