Virus Scanning (CPP-007)

CPP-IdentifierCPP-007
CPP-LabelVirus Scanning
AuthorMattias Levlin, Johan Kylander
ContributorsKris Dekeyser
EvaluatorsFelix Burger, Maria Benauer, Fen Zhang
Change historyComments
Version 1.0.0 - 2025-08-29Milestone version
Version 1.1.0 - 2025-10-16Migration to XML
Version 1.2.0 - 2026-07-10Added use case on WARC Virus Checker.

1. Description of the CPP

Information packages are virus checked, with appropriate facilities for quarantine.

Inputs and outputs

Input(s)
Data
Information package(s)
Documentation/guidance
Malware signature database(s)
Guidelines for managing detected threats
Output(s)
Metadata
Provenance metadata
Documentation/guidance
Scan report

Definition and scope

Virus scanning is the process of examining Files as proposed for ingestion into an archive for the presence of malicious software (i.e. malware) such as viruses, trojans, worms, spyware, and ransomware etc. The primary goal of virus scanning is to detect and prevent such harmful code from entering the digital archive to safeguard the integrity and trustworthiness of the preserved content. This security measure protects not only the archival system itself, but also users or other connected systems that access or receive content from the archive. Effective virus scanning is a core step of the ingest process and an essential strategic component in Risk Mitigation (CPP-012), ensuring that the archive remains a secure and reliable repository for digital assets. It is a means to mitigate deliberate, human-made threats to digital preservation.

Virus scanning is first and foremost applied during ingest, acting as a checkpoint before Files are fully accepted and integrated into a TDA's holdings. In addition, it may be triggered during preservation (archival storage) or dissemination. This may be done either to ensure that no viruses have infected the content after ingest, or to make sure that disseminated content has been checked using up-to-date signature databases.

A TDA must employ virus scanning tools and malware signature databases to ensure effective and up-to-date threat detection. This includes a process to maintain and frequently update a malware signature database that is used by the virus scanning tools. The system must provide secure workspaces and guidelines for managing detected threats, which typically involves isolating suspicious Files in a staging or quarantine area to prevent potential harm to the storage. The TDA can reject and remove the contaminated Files or Information packages during ingest in cases where decontamination is not a viable option.

All scanning activities, detected threats, and subsequent actions (i.e. quarantine, rejection, deletion) must be documented as part of the ingest record and preservation actions as Provenance metadata. This documentation contributes to the audit trail of the ingested Files and should be incorporated into broader Object Management Reporting (CPP-013).

Process description

Trigger event(s)

Trigger EventCPP-identifier
Periodic quality check of FilesCPP-019 (Data Quality Assessment)
Pre-access check of DIPsCPP-025 (Enabling Access)
IngestCPP-029 (Ingest)

Step-by-step description

NoSupplierInputStepsOutputCustomer
 sequence
1CPP-029 (Ingest) SIP(s) Receive and Stage Content: Content arrives and is placed in a temporary, isolated staging area designated for pre-ingest checksSIP(s) in the staging area
2CPP-019 (Data Quality Assessment)
CPP-025 (Enabling Access)
AIP(s) Select AIP(s) for virus scan and copy their Files to the staging area for checksAIP(s) in the staging area
3File(s) in staging areaPerform Scan: Initiate a comprehensive scan of all Files within the staged Information packagesScan report/log (indicating clean Files, and any detected threats with file paths and malware names)
Configured virus scanners
4Scan report/logEvaluate Scan ResultsAll Files reported as clean (step 7)
Any Files reported as infected or suspicious (step 5)
5Infected/suspicious file(s)Handling infected or suspicious Files, the TDA conducts a first analysisDecontamination recommended: Move the identified File(s) to a secure quarantine area, isolated from other systems and content for further analysis and potential disinfection, and inform dedicated staff members (step 6)CPP-013 (Object Management Reporting)
Scan reportRejection recommended: Mark the File(s) (or the entire SIP(s) (as in case of ingest) for rejection. Notify the producer with reasons, if appropriate and/or defined by policy (end of the process)CPP-013 (Object Management Reporting)
Guidelines for managing detected threats
6Quarantined file(s)In-Depth Analysis: The personnel analyses the threat, leading to multiple potential outcomesFalse positive identified: the detected malware does not pose a threat. Whitelist the threat and move the Files from quarantine back to the staging (loop back to step 1)
Notification to staffDecontamination required and possible: The TDA disinfects the Files and moves the Files from quarantine back to the staging (loop back to step 1)
Decontamination required but not possible: Notify stakeholders: The TDA notifies the stakeholders that their content is at risk and that it most likely must be deleted and re-submitted. The Files are not moved away from the quarantine area. This is a more likely outcome for AIP Files that are scanned during the preservation (triggered by CPP-019). (step 7)
7Scan reportRecord the virus scan and its Outcome as a Preservation EventThis documentation should include:
  • Datetime of scan
  • Scanner software name
  • Virus definition file version/date
  • Files scanned
  • Outcome for each file (e.g., 'clean', 'infected - [virus_name]', 'quarantined', 'rejected').
  • Any additional actions taken
Provenance metadata CPP-016 (Metadata Ingest and Management)
CPP-013 (Object Management Reporting)
Actions taken (quarantine, disinfection, rejection)
8Clean File(s)Proceed with Clean Content or finalise Rejection:
  • If content is clean: release Files from the staging area or proceed with ingest
  • If any relevant content was rejected: Finalise the rejection process and archive the documentation
Clean File(s) passed to the next ingest stage, or rejection process completedCPP-013 (Object Management Reporting)
Documentation of scan event

Rationale(s) and worst case(s)

RationaleImpact of inaction or failure of the process
Detection of malware in SIP(s)Ingest of contaminated Files, risking destruction of the entire TDA.
Process to handle and potentially reject and delete infected SIP(s)Ingest of contaminated Files, risking destruction of the entire TDA
Processes to maintain up-to-date malware signature databases and virus scanning toolsIngest of contaminated Files, risking destruction of the entire TDA
Detection of malware in AIP(s)Risking destruction of the entire TDA.

2. Dependencies and relationships with other CPPs

Dependencies

CPP-IDCPP-TitleRelationship description
CPP-012Risk MitigationVirus scanning is a direct risk mitigation activity against threats to content integrity and system security triggered by CPP-012.

Other relations

RelationCPP-IDCPP-TitleRelationship description
Required byCPP-013Object Management ReportingReports on virus scanning activities, frequency of threats, and outcomes of the actions provide essential input for operational management and risk assessment.
Required byCPP-019Data Quality AssessmentVirus scanning is performed as a step in the overall Data Quality Assessment process.
Required byCPP-029IngestVirus scanning is one of the core processes that must be performed during ingest.
Affinity withCPP-003Integrity CheckingBoth processes aim to ensure the "health" of Files. However, Integrity Checking focuses on detecting technical corruption of Files (e.g. bit rot), whereas virus scanning looks to mitigate human-made risks ( e.g. malicious code).
Not to be confused withCPP-004Data Corruption ManagementIf a File is detected as infected and cannot be cleaned, it might be considered "damaged." However, CPP-004 typically applies to technical corruption or loss, rather than deliberately human-made damage such as malware-infected Files. In practice, infected Files are more likely to be replaced (by the producer) or rejected.
Not to be confused withCPP-010File Format ValidationBoth processes scan the Files to ensure that they are suitable for preservation. File Format Validation checks if a file conforms to its purported format specification (e.g. is this a valid PDF/A file?) while Virus Scanning checks for malware, regardless of format validity.

4. Reference implementations

Use cases

Virus Scan as Part of Ingest at CSC

Institutional background
InstitutionCSC – IT Center for Science Ltd., Finland, FI
Hyperlinkhttps://www.clamav.net/
Description
Trigger eventIngest
Problem statementFiles must be scanned for viruses as part of the ingest pipeline to protect the TDA from viruses
Proposed solutionPython script to detect viruses using ClamAv virus scanner

WARC Virus Checker and NSFW (Not-Safe-For-Work) Content Detection Tool

Institutional background
InstitutionBibliothèque nationale de Luxembourg, LU
Hyperlinkhttps://digital.library.unt.edu/ark:/67531/metadc2472470/
Description
Trigger eventBibliothèque nationale de Luxembourg (BnL) collects and preserves web archives that might contain viruses. These viruses may damage the library's infrastructures or the user's device.
Problem statementWeb archives are bundled into WARC containers. BnL needed to extract files from these containers and use an open source virus scanner to identify malware in them.
Proposed solutionBnL developed a Python script to extract files from WARC containers and scan them with the ClamAV virus scanner. The tool also detects NSFW ('Not Safe for Work') content with the help of the `nsfwdetection` PyTorch model. It can be used as a command-line tool or as an API. Results are either displayed in the terminal or returned as JSON by the API. WARC containing viruses are ingested, but the user is informed of their presence.

Publicly available documentation

InstitutionOrganisation typeLanguageHyperlink
TIB – Leibniz Information Centre for Science and Technology and University Library, DENational library
Non-commercial digital preservation service
Research infrastructure
Research performing organisation
English https://wiki.tib.eu/confluence/spaces/lza/pages/93608618/Ingest
CSC – IT Center for Science Ltd., FINon-commercial digital preservation serviceEnglish https://digitalpreservation.fi/en/services/quality_reports/2024
(Monitoring of the Digital Preservation Services: "Up-to-date status of the virus check database" )
Archivematica, CADigital preservation systemEnglish https://www.archivematica.org/en/docs/archivematica-1.14/user-manual/transfer/scan-for-viruses/#scan-for-viruses
DANS (Data Archiving and Networked Services), Netherlands, NLCommercial digital preservation service
Discipline-specific data repository
Discipline-agnostic data repository
English https://www.coretrustseal.org/wp-content/uploads/2018/04/DANS-Electronic-Archiving-SYstem-EASY-.pdf
("Virus-scans are performed periodically for ingest by the web interface and standard for all other ingest ways (like SWORD)." )