DocumentCode
1456803
Title
SplitScreen: Enabling efficient, distributed malware detection
Author
Cha, Sang Kil ; Moraru, Iulian ; Jang, Jiyong ; Truelove, John ; Brumley, David ; Andersen, David G.
Author_Institution
Electr. & Comput. Eng. Dept., Carnegie Mellon Univ., Pittsburgh, PA, USA
Volume
13
Issue
2
fYear
2011
fDate
4/1/2011 12:00:00 AM
Firstpage
187
Lastpage
200
Abstract
We present the design and implementation of a novel anti-malware system called SplitScreen. SplitScreen performs an additional screening step prior to the signature matching phase found in existing approaches. The screening step filters out most non-infected files (90%) and also identifies malware signatures that are not of interest (99%). The screening step significantly improves end-to-end performance because safe files are quickly identified and are not processed further, and malware files can subsequently be scanned using only the signatures that are necessary. Our approach naturally leads to a network-based anti-malware solution in which clients only receive signatures they needed, not every malware signature ever created as with current approaches. We have implemented SplitScreen as an extension to ClamAV, the most popular open source anti-malware software. For the current number of signatures, our implementation is 2x faster and requires 2x less memory than the original ClamAV. These gaps widen as the number of signatures grows.
Keywords
digital signatures; distributed processing; file organisation; invasive software; ClamAV; SplitScreen; antimalware system; distributed malware detection; malware files; malware signature; network-based antimalware solution; noninfected files; open source antimalware software; safe files; screening step; signature matching phase; Computers; Databases; Malware; Memory management; Pattern matching; Servers; Vectors; Anti-malware; bloom filter; signature matching;
fLanguage
English
Journal_Title
Communications and Networks, Journal of
Publisher
ieee
ISSN
1229-2370
Type
jour
DOI
10.1109/JCN.2011.6157418
Filename
6157418
Link To Document