Does anyone know of a decent reference for virus naming conventions used by different anti-virus software vendors?
To my knowledge, such a thing doesn't exist for cross reference. Each vendor should have their own convention listing such as Symantec's.
http//
To my knowledge, such a thing doesn't exist for cross reference. Each vendor should have their own convention listing such as Symantec's.
http//
www.symantec.com/security_response/virusnaming.jsp
this is the whole problem ..there is no way to cross reference the names between vendors
what also shits me is vendors like Sophos have removed all virus/trojan details from their site and there is no way to find out what other vendors call their viruses.
I didnt want to have to have 5 or six different anti-virus programs installed just to get the reported names from each, I was happy with just 2 or 3.
*waves fist at stupid anti-virus industry*
Yes, and you're not alone in thinking this way. Many vendors will identify what other vendors call the same malware. For instance trojan.mebroot is identified as sinowal on the symantec site, because other vendors refer to it as sinowal. I've unfortunately found that googling the malware name is the best way to cross reference a name because it will identify multiple vendor generated identities.
Sometimes threat expert will cross reference them. There's no need to install 5-6 programs. I simply submit the sample to virustotal to see what other vendors call something.
this is the whole problem ..there is no way to cross reference the names between vendors
There are methods – they may not in wide use, though. One method that seems to be promising is the CME (http//cme.mitre.org/), but it is targeted to 'high-profile threats'.