Hybrid Algorithm for Backward Hashing and Automation Tracking For Virus Scanning
Panchal Mital K, Bakul Panchal · Zenodo (CERN European Organization for Nuclear Research) · 2015
Virus scanning involves computationally intensive string matching against a large number of signatures of different characteristics. Matching a variety of signatures challenges the selection of matching algorithms. We propose a hybrid approach that partitions the signatures into long and short ones in the open-source ClamAV for virus scanning. By improving and enhancing the Wu-Manber algorithm, the new algorithm called as the Backward Hashing algorithm which is dependable for only long patterns to extend the average skip distance. There is one more algorithm which takes care of short patterns is Aho-Corasick algorithm. It scans only short patterns to reduce the automation sizes. Algorithm we have discussed first uses the bad-block heuristic to develop long shift distance and thus decreasing the verification rate of recurrence. In that way it is much faster than the original WM implementation in ClamAV open source antivirus software. Algorithm we have stated later increases the AC performance by around 50 percent due to better cache locality. We also rank the factors to indicate their importance for the string matching performance.