Affiliation:
1. Informatics Department, Federal University of Paraná (UFPR-BR), Porto Alegre - RS, Brazil
2. Federal University of Paraná (UFPR-BR), Curitiba - PR, Brazil
Abstract
AntiViruses (AVs) are essential to face the myriad of malware threatening Internet users. AVs operate in two modes: on-demand checks and real-time verification. Software-based real-time AVs intercept system and function calls to execute AV’s inspection routines, resulting in significant performance penalties as the monitoring code runs among the suspicious code. Simultaneously, dark silicon problems push the industry to add more specialized accelerators inside the processor to mitigate these integration problems. In this article, we propose
Terminator
, an AV-specific coprocessor to assist software AVs by outsourcing their matching procedures to the hardware, thus saving CPU cycles and mitigating performance degradation. We designed
Terminator
to be flexible and compatible with existing AVs by using
YARA
and
ClamAV
rules. Our experiments show that our approach can save up to 70 million CPU cycles per rule when outsourcing on-demand checks for matching typical, unmodified
YARA
rules against a dataset of 30 thousand in-the-wild malware samples. Our proposal eliminates the AV’s need for blocking the CPU to perform full system checks, which can now occur in parallel. We also designed a new inspection breakpoint mechanism that signals to the coprocessor the beginning of a monitored region, allowing it to scan the regions in parallel with their execution. Overall, our mechanism mitigated up to 44% of the overhead imposed to execute and monitor the SPEC benchmark applications in the most challenging scenario.
Funder
Brazilian National Counsel of Technological and Scientific Development
Serrapilheira Institute
Publisher
Association for Computing Machinery (ACM)
Subject
Safety, Risk, Reliability and Quality,General Computer Science
Reference63 articles.
1. A novel reconfigurable co-processor architecture
2. Accelerating the local outlier factor algorithm on a GPU for intrusion detection systems
3. SiNUCA: A Validated Micro-Architecture Simulator
4. Windows 7 most hit by wannacry ransomware;Arghire Ionut;http://www.securityweek.com/windows-7-most-hit-wannacry-ransomware,2017
5. YaraMod;https://engineering.avast.io/yaramod-inspect-analyze-and-modify-your-yara-rules-with-ease/,2019
Cited by
1 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献
1. Enhancing Incident Management by an Improved Understanding of Data Exfiltration: Definition, Evaluation, Review;Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering;2024