First of all, Kaspersky achieved a 99.97% protection level against 10k malware samples and only missed 3, and that is honestly impressive. Nice work, Kaspersky.
And to clarify, what I’m asking here is, what exactly does a 0.003 compromise score mean for the average Kaspersky user that relies on the security product to correct any mistakes he might make during his daily activities, such as checking emails, playing video games, and downloading necessary programs?
Should he be concerned about the compromise score?
AV-Comparatives tested Kaspersky Premium, version 21.24, using more than 10,000 malware samples.
Do the malware that breached Kaspersky’s factory settings on the AV comparative test system include sophisticated or zero-day variants?
And theoretically speaking, do you think that maybe the default deny/trusted application mode fills the gap of the excellent 99.97% protection score?
I get that if you intentionally run ten thousand pieces of malware on your computer all at once, even an antivirus made by God would not survive. Still, it might be best to get input from more knowledgeable users about the matter.
Thank you very much for helpful answers.
What the 0.003 compromise score means
A compromise score of 0.003 generally means that a very small number of test systems were considered compromised during that particular test. It does not mean that every Kaspersky user has a 0.3% chance of being compromised, nor that Kaspersky will block 99.97% of all malware encountered in real-world use.
The result is specific to:
- The malware samples selected by AV-Comparatives
- The test operating system and configuration
- Kaspersky’s tested version and settings
- The actions performed during the test
- The time at which the test was conducted
If the result represents three failures out of approximately 10,000 samples, that is an excellent result. However, three samples are still important because they demonstrate that protection is not absolute. The result should be interpreted as a comparative laboratory measurement, not as an individual risk prediction.
Does this mean the average user should be concerned?
There is no reason to become alarmed based on this score alone. A user running a fully updated system with Kaspersky configured normally, automatic updates enabled, and sensible browsing habits is receiving a high level of protection according to that test.
The remaining risk is best reduced through layered practices:
- Keep Windows, browsers, applications, and Kaspersky updated.
- Avoid pirated software, cracks, keygens, and suspicious download portals.
- Do not bypass warnings merely to run an unknown file.
- Use a standard user account where practical.
- Maintain current offline or otherwise protected backups.
- Submit suspicious files to VirusTotal or a reputable security vendor for additional analysis.
An antivirus product is an important safety layer, but it cannot reliably compensate for every decision made by a user, particularly when a user explicitly allows an unknown program to run or disables a protection feature.
Were the missed samples sophisticated or zero-day malware?
That cannot be determined from the protection percentage or compromise score alone. Unless AV-Comparatives identifies the individual samples, their discovery dates, and their exploitation methods, it would be speculation to call them sophisticated, zero-day, or especially advanced.
A malware test set may contain a mixture of prevalent threats, newer samples, variants, and samples designed to test different protection layers. “Missed” also does not necessarily mean that the sample was completely invisible to every Kaspersky component. It may have been detected later, blocked after execution, prevented from causing significant damage, or classified as a compromise according to the test methodology.
The full AV-Comparatives report and methodology are needed to understand exactly what happened with each failed case.
Does Default Deny or Trusted Applications mode fill the gap?
A properly configured application-control or default-deny mechanism can reduce the chance that an undetected executable will run. It is therefore a useful additional layer, but it should not be considered a complete replacement for malware detection.
Its effectiveness depends on details such as:
- Whether unknown applications are blocked or merely shown a prompt
- How trusted applications and digitally signed files are classified
- Whether scripts, document macros, installers, drivers, and child processes are controlled
- Whether the user is allowed to approve the unknown program
- Whether malware abuses an already trusted or vulnerable application
Strict default-deny configurations can also produce compatibility problems and false positives. A prompt-based mode may provide much less protection if the user routinely permits unknown applications.
Application control also cannot prevent every attack. Malware may exploit a vulnerability before an executable-control decision is made, abuse a legitimate signed program, use a trusted browser or script interpreter, steal credentials, or rely on the user voluntarily approving an action.
Overall assessment
The test result indicates very strong protection under AV-Comparatives’ conditions, while the compromise score reminds us that no security product blocks every threat. The score should not be converted into a personal infection probability, and there is insufficient information to characterize the missed samples as zero-days or highly sophisticated threats.
For most users, keeping Kaspersky and the operating system updated, leaving protective components enabled, avoiding deliberate overrides, and maintaining reliable backups are more valuable than switching to an overly restrictive configuration. Application control can provide extra protection for users who understand and can manage its prompts, but it should be regarded as an additional layer rather than a guarantee.