Pattern Matching in YARA: Improved Aho-Corasick Algorithm
The result's identifiers
Result code in IS VaVaI
<a href="https://www.isvavai.cz/riv?ss=detail&h=RIV%2F00216305%3A26230%2F21%3APU140744" target="_blank" >RIV/00216305:26230/21:PU140744 - isvavai.cz</a>
Result on the web
<a href="https://ieeexplore.ieee.org/document/9410267" target="_blank" >https://ieeexplore.ieee.org/document/9410267</a>
DOI - Digital Object Identifier
<a href="http://dx.doi.org/10.1109/ACCESS.2021.3074801" target="_blank" >10.1109/ACCESS.2021.3074801</a>
Alternative languages
Result language
angličtina
Original language name
Pattern Matching in YARA: Improved Aho-Corasick Algorithm
Original language description
YARA is a tool for pattern matching used by malware analysts all over the world. YARA can scan files, as well as process memory. It allows us to define sequences of symbols as text strings, hexadecimal strings, and regular expressions. However, the use of regular expressions is limited because of the concern that it can slow down the scanning process. In this paper, we analyze the true nature of regular expressions in YARA and its implementation. We discovered several reasons regular expressions can, in a fact, slow down scanning based on the nature of the used algorithm, Aho-Corasick. We proposed a new version of this algorithm and we implemented it in the original version of this tool. The experiments are presented, proving the speed of pattern matching with regular expressions can be indeed improved.
Czech name
—
Czech description
—
Classification
Type
J<sub>imp</sub> - Article in a specialist periodical, which is included in the Web of Science database
CEP classification
—
OECD FORD branch
10201 - Computer sciences, information science, bioinformathics (hardware development to be 2.2, social aspect to be 5.8)
Result continuities
Project
—
Continuities
S - Specificky vyzkum na vysokych skolach
Others
Publication year
2021
Confidentiality
S - Úplné a pravdivé údaje o projektu nepodléhají ochraně podle zvláštních právních předpisů
Data specific for result type
Name of the periodical
IEEE Access
ISSN
2169-3536
e-ISSN
—
Volume of the periodical
9
Issue of the periodical within the volume
1
Country of publishing house
US - UNITED STATES
Number of pages
10
Pages from-to
62857-62866
UT code for WoS article
000645857100001
EID of the result in the Scopus database
2-s2.0-85104574203