arXiv · 2610.07931
Where does a rust speedup come from? Language and algorithm effects in sliding window threat scorer
Abstract
Rewriting a hot path from Python into Rust is a common way to speed up security analytics, and large speedups are routinely reported. A rewrite usually changes the language and the algorithm at once, so a single factor can credit the language with a gain that comes from a better algorithm. We study this on a sliding window threat scorer modelled on the traffic light calculator of the SentinelSphere platform. Five implementations, three in Python and two in Rust, produce bit identical scores, confirmed by a shared checksum, and we time them from 100 to one million events in a bounded and a burst regime. The language alone contributes between about 4 and 29 times. Replacing a per event rescan of the window by an incremental update contributes more than 11,000 times in the burst regime, so the end to end factor reaches about 195,000 times when the window keeps filling and levels off near 13,000 times when it does not. A power law fit to the timings reported for the original rewrite gives growth exponents of 1.85 for Python and 0.88 for Rust, the signature of an algorithmic difference. Performance claims for security tooling should therefore report the language and algorithm contributions separately.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Nikolaos D. Tantaroudas, Ilias Karachalios, Andrew J. McCracken. 2026-10-06. Where does a rust speedup come from? Language and algorithm effects in sliding window threat scorer. https://arxiv.org/abs/2610.07931
Cite the original work for its findings. Save a collection to share your selection of sources.