THE WILDLIST IS DEAD, LONG LIVE THE WILDLIST!

Andreas Marx, Frank Dessmann · 2007

For a very long time, the WildList was the accepted standard for all kinds of anti-malware software test. However, today’s real challenges – like targeted attacks and zero-day exploits, as well as adware and spyware – are not covered by the WildList. Traditionally, the WildList has only focused on self-replicating malware such as viruses and worms, but in today’s world these malware types have almost died out and been replaced by Trojan horses with keyloggers and options to steal PIN and TAN codes for online banking. (The malware world has gone commercial and some of the bad guys are making more money than traditional AV companies!) Besides this, the WildList is usually published two to three months after the reporting period, so it is outdated when released. This paper will focus on the current problems with the WildList and suggest methods to increase its usefulness again – to ensure not only that all of today’s malware types are covered, but also that the WildList will always be current when published on a more regular basis. This includes an analysis of all required processes, better reporting methods and automation techniques which must be used to avoid delays in publication.

Read the paper · More papers on PaperTik