Re: Using linux command "find" to get m odified files list for scan

neel roy via clamav-users <[email protected]>
Newsgroups gmane.comp.security.virus.clamav.user
Message-ID <1733718887.S.10974.autosave.drafts.1733719852.13315@webmail.rediffmail.com>
Hello Masaru,

You wrote:

&gt; In &nbsp;short, Using the find command to specify files can make the ClamAV
&gt; scanning process inefficient. ClamAV is designed to effectively scan
&gt; entire directories and specific file types, so there is no need to
&gt; filter the list generated by find command.

When I ran clamdscan with &quot;-m&quot; on 4 vCPU Linux EL9 VM very small server with about only 5,50,000 (or 550,000) relevant files.

first time: 4 m 18 seconds
second time: 2 m 25 seconds (time reduces a lot because of caching)

Without &quot;-m&quot; option it would go about ~16 min.

Command &quot;&nbsp;echo&gt;./find.out;echo &quot;./find.out&quot;;cat ./find.out;date;find / -type f -ctime -1 -not -path &quot;/proc/*&quot; -not -path &quot;/sys/*&quot; -not -path &quot;/dev/*&quot; -not -path &quot;/boot/*&quot;&gt;./find.out;date;cat ./find.out|wc -l&quot; gave me 84 files.

clamdscan with or without scan, with &quot;-f&quot; option finished in 3 seconds.

I used clamdscan because I can take advantage of caching. But I want to use clamscan which means it would always take ~16 minutes with full system scan.

Of course this is a _very_ stale server, with almost no change. With lots of change, this will change.

**However** my question is this: whenever anti virus does scan, in this case, clamav, they do NOT find changed files, even (on linux) very efficient utility such as &quot;find&quot; exists. There must be a reason. What that reason could be?

Thanks in advance,
-Neel.





From: Masaru Nomiya via clamav-users &lt;[email protected]&gt;
Sent: Mon, 09 Dec 2024 09:36:09
To: [email protected]
Cc: Masaru Nomiya &lt;[email protected]&gt;
Subject: Re: [clamav-users] Using linux command &quot;find&quot; to get modified files list for scan

Hello,

In the Message;

&nbsp;Subject &nbsp; &nbsp;: [clamav-users] Using linux command &quot;find&quot; to get modified files list for scan
&nbsp;Message-ID :&nbsp;&lt;1733715472.S.23081.autosave.drafts.1733715610.1219@webmail.rediffmail.com&gt;
&nbsp;Date &amp; Time: 9 Dec 2024 03:40:10 -0000

[RN] == neel roy via clamav-users &lt;[email protected]&gt; has written:

R[...]
RN&gt; &nbsp;Is there a reason why find should not be used to get list of
RN&gt; files modified and scan them?

In &nbsp;short, Using the find command to specify files can make the ClamAV
scanning process inefficient. ClamAV is designed to effectively scan
entire directories and specific file types, so there is no need to
filter the list generated by find command.

Best Regards.

---
$B(.(,(,(/WD(B &nbsp; &nbsp; Masaru Nomiya &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; mail-to: nomiya @ lake.dti.ne.jp
$B(-!@!?WD(B
$B(1(,(,(0(B &nbsp; &nbsp; &nbsp; &quot; Reading widely about things that don&#39;t seem immediately or
&nbsp;&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; practically useful, in the hope that what you learn now may prove
&nbsp;&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; meaningful later$B!=(Bthat&#39;s pretty much the definition of a liberal-
&nbsp;&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; arts education. Who knew that one of its best defenders would turn
&nbsp;&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; out to be a computer scientist? &quot;
&nbsp;&nbsp;&nbsp; &nbsp; &nbsp; &nbsp;
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;-- &quot;What Does It Really Mean to Learn?&quot; THE NEW YORKER --
_______________________________________________

Manage your clamav-users mailing list subscription / unsubscribe:
https://lists.clamav.net/mailman/listinfo/clamav-users


Help us build a comprehensive ClamAV guide:
https://github.com/Cisco-Talos/clamav-documentation

https://docs.clamav.net/#mailing-lists-and-chat

_______________________________________________

Manage your clamav-users mailing list subscription / unsubscribe:
https://lists.clamav.net/mailman/listinfo/clamav-users


Help us build a comprehensive ClamAV guide:
https://github.com/Cisco-Talos/clamav-documentation

https://docs.clamav.net/#mailing-lists-and-chat
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.