Constructing A Stream-based Mail Virus Scanner System with Hardware-Accelerated Content Inspection

碩士 === 中華大學 === 資訊工程學系(所) === 96 === As information science and technology flourishes today, information systems are bringing convenient functions; the subject of information security has already received attention from most enterprises and personal customers. Among them, the computer virus is the m...

Full description

Bibliographic Details
Main Authors: WU. TUNG-MING, 吳東名
Other Authors: YU.KUN-MING
Format: Others
Language:zh-TW
Published: 2008
Online Access:http://ndltd.ncl.edu.tw/handle/02180454194678076222
id ndltd-TW-096CHPI5392014
record_format oai_dc
spelling ndltd-TW-096CHPI53920142015-10-13T13:11:50Z http://ndltd.ncl.edu.tw/handle/02180454194678076222 Constructing A Stream-based Mail Virus Scanner System with Hardware-Accelerated Content Inspection 建構一個以串流為基礎具有硬體加速內容檢查的郵件病毒掃描系統 WU. TUNG-MING 吳東名 碩士 中華大學 資訊工程學系(所) 96 As information science and technology flourishes today, information systems are bringing convenient functions; the subject of information security has already received attention from most enterprises and personal customers. Among them, the computer virus is the most common problem for network security. On existing anti-virus systems, we can see the advantages of anti-virus mail gateway on center-controls and prevent viruses from invading internal networks in advance. However, these traditional anti-virus mail gateways scan for viruses after the backup. Because lots of system resources and temporary space is needed by the anti-virus gateway in order to match the function of the system, meaning that there are more system resources, the better system effect we can get and the more temporary space, the more files can be scanned. Therefore, we construct a Hardware-Accelerated Mail Scanner System (HAMSS) to solve these problems. The temporary space is not needed in HAMSS and HAMSS also can minimize the system memory needed to carry out the defensive function. Another feature of HAMSS is to reduce the CPU utilization. When HAMSS executes content inspection for viruses, it just needs to hand over the job to the hardware, so that the CPU can be assigned to run other jobs while the mail virus-scanner system inspects attachments in the mail. For verifying the performance of the proposed architecture, we implemented HAMSS and compared it to other anti-virus systems. Form the experimental results, we can find that HAMSS runs 6 times faster than the storage-based system and 2 times faster than the stream-based system. When the attachment of the mail is compressed, HAMSS was also respectively 6 times and 3 times faster compared to the two other systems. For the usage of system memory, it keeps the memory constant for each connection. In addition, HAMSS also has less CPU utilization than the two other systems. YU.KUN-MING 游坤明 2008 學位論文 ; thesis 52 zh-TW
collection NDLTD
language zh-TW
format Others
sources NDLTD
description 碩士 === 中華大學 === 資訊工程學系(所) === 96 === As information science and technology flourishes today, information systems are bringing convenient functions; the subject of information security has already received attention from most enterprises and personal customers. Among them, the computer virus is the most common problem for network security. On existing anti-virus systems, we can see the advantages of anti-virus mail gateway on center-controls and prevent viruses from invading internal networks in advance. However, these traditional anti-virus mail gateways scan for viruses after the backup. Because lots of system resources and temporary space is needed by the anti-virus gateway in order to match the function of the system, meaning that there are more system resources, the better system effect we can get and the more temporary space, the more files can be scanned. Therefore, we construct a Hardware-Accelerated Mail Scanner System (HAMSS) to solve these problems. The temporary space is not needed in HAMSS and HAMSS also can minimize the system memory needed to carry out the defensive function. Another feature of HAMSS is to reduce the CPU utilization. When HAMSS executes content inspection for viruses, it just needs to hand over the job to the hardware, so that the CPU can be assigned to run other jobs while the mail virus-scanner system inspects attachments in the mail. For verifying the performance of the proposed architecture, we implemented HAMSS and compared it to other anti-virus systems. Form the experimental results, we can find that HAMSS runs 6 times faster than the storage-based system and 2 times faster than the stream-based system. When the attachment of the mail is compressed, HAMSS was also respectively 6 times and 3 times faster compared to the two other systems. For the usage of system memory, it keeps the memory constant for each connection. In addition, HAMSS also has less CPU utilization than the two other systems.
author2 YU.KUN-MING
author_facet YU.KUN-MING
WU. TUNG-MING
吳東名
author WU. TUNG-MING
吳東名
spellingShingle WU. TUNG-MING
吳東名
Constructing A Stream-based Mail Virus Scanner System with Hardware-Accelerated Content Inspection
author_sort WU. TUNG-MING
title Constructing A Stream-based Mail Virus Scanner System with Hardware-Accelerated Content Inspection
title_short Constructing A Stream-based Mail Virus Scanner System with Hardware-Accelerated Content Inspection
title_full Constructing A Stream-based Mail Virus Scanner System with Hardware-Accelerated Content Inspection
title_fullStr Constructing A Stream-based Mail Virus Scanner System with Hardware-Accelerated Content Inspection
title_full_unstemmed Constructing A Stream-based Mail Virus Scanner System with Hardware-Accelerated Content Inspection
title_sort constructing a stream-based mail virus scanner system with hardware-accelerated content inspection
publishDate 2008
url http://ndltd.ncl.edu.tw/handle/02180454194678076222
work_keys_str_mv AT wutungming constructingastreambasedmailvirusscannersystemwithhardwareacceleratedcontentinspection
AT wúdōngmíng constructingastreambasedmailvirusscannersystemwithhardwareacceleratedcontentinspection
AT wutungming jiàngòuyīgèyǐchuànliúwèijīchǔjùyǒuyìngtǐjiāsùnèiróngjiǎnchádeyóujiànbìngdúsǎomiáoxìtǒng
AT wúdōngmíng jiàngòuyīgèyǐchuànliúwèijīchǔjùyǒuyìngtǐjiāsùnèiróngjiǎnchádeyóujiànbìngdúsǎomiáoxìtǒng
_version_ 1717734026078322688