Logo image
SHOCK: A worst-case ensured sub-linear time pattern matching algorithm for inline anti-virus scanning
Conference paper

SHOCK: A worst-case ensured sub-linear time pattern matching algorithm for inline anti-virus scanning

Nen-Fu Huang and Wen-Yen Tsai
IEEE International Conference on Communications, 5501986
2010

Abstract

Computer viruses Network security String matching
To detect viruses, worms and, malware in the multi-gigabit environment, it is crucial for modern content-aware network security appliances to have a fast virus scanning scheme. Signature based multi-pattern matching algorithm is the core technology to enable fast virus scanning accurately and quickly. This paper proposes a multi-pattern matching algorithm with a simple shift/hash technique and a novel heuristic by inspecting overlaps between pairs of patterns to ensure both average and worst-case performance. Experimental results show that our algorithm performs 600Mbps to 1.4Gbps faster than the ClamAV AC and BM-based algorithms and achieves a maximum of 3.8Gbps throughput in inline virus scanning while the memory consumption is nearly the same. ©2010 IEEE.

Metrics

1 Record Views

Details

Logo image