Virus Scanning (CPP-007)
| CPP-Identifier | CPP-007 |
| CPP-Label | Virus Scanning |
| Author | Mattias Levlin, Johan Kylander |
| Contributors | Kris Dekeyser |
| Evaluators | Felix Burger, Maria Benauer, Fen Zhang |
| Change history | Comments |
|---|
| Version 1.0.0 - 2025-08-29 | Milestone version |
| Version 1.1.0 - 2025-10-16 | Migration to XML |
| Version 1.2.0 - 2026-07-10 | Added use case on WARC Virus Checker. |
1. Description of the CPP
Information packages are virus checked, with appropriate
facilities for quarantine.
Inputs and outputs
| Input(s) |
|---|
| Data | |
| Documentation/guidance | | Malware signature database(s) | | Guidelines for managing detected threats |
|
| Output(s) |
|---|
| Metadata | |
| Documentation/guidance | |
Definition and scope
Virus scanning is the process of examining Files as proposed for ingestion into
an archive for the presence of malicious software (i.e. malware) such as viruses,
trojans, worms, spyware, and ransomware etc. The primary goal of virus scanning is to
detect and prevent such harmful code from entering the digital archive to safeguard the
integrity and trustworthiness of the preserved content. This security measure protects
not only the archival system itself, but also users or other connected systems that
access or receive content from the archive. Effective virus scanning is a core step of
the ingest process and an essential strategic component in Risk Mitigation
(CPP-012), ensuring that the archive remains a secure and reliable repository for
digital assets. It is a means to mitigate deliberate, human-made threats to digital
preservation.
Virus scanning is first and foremost applied during ingest, acting as a checkpoint before
Files are fully accepted and integrated into a TDA's holdings. In addition, it may
be triggered during preservation (archival storage) or dissemination. This may be done
either to ensure that no viruses have infected the content after ingest, or to make sure
that disseminated content has been checked using up-to-date signature databases.
A TDA must employ virus scanning tools and malware signature databases to ensure
effective and up-to-date threat detection. This includes a process to maintain and
frequently update a malware signature database that is used by the virus scanning tools.
The system must provide secure workspaces and guidelines for managing detected threats,
which typically involves isolating suspicious Files in a staging or quarantine
area to prevent potential harm to the storage. The TDA can reject and remove the
contaminated Files or Information packages during ingest in cases
where decontamination is not a viable option.
All scanning activities, detected threats, and subsequent actions (i.e. quarantine,
rejection, deletion) must be documented as part of the ingest record and preservation
actions as Provenance metadata. This documentation contributes to the audit
trail of the ingested Files and should be incorporated into broader Object
Management Reporting (CPP-013).
Process description
Trigger event(s)
| Trigger Event | CPP-identifier |
|---|
| Periodic quality check of Files | CPP-019 (Data Quality Assessment) |
| Pre-access check of DIPs | CPP-025 (Enabling Access) |
| Ingest | CPP-029 (Ingest) |
Step-by-step description
| No | Supplier | Input | Steps | Output | Customer |
|---|
| sequence |
| 1 | CPP-029 (Ingest) |
SIP(s)
| Receive and Stage Content: Content arrives and is placed
in a temporary, isolated staging area designated for
pre-ingest checks | SIP(s) in the staging area | |
| 2 | CPP-019 (Data Quality Assessment) CPP-025 (Enabling Access) |
AIP(s)
| Select AIP(s) for virus scan and copy their Files to
the staging area for checks | AIP(s) in the staging area | |
| 3 | | File(s) in staging area | Perform Scan: Initiate a comprehensive scan of all Files
within the staged Information packages | Scan report/log (indicating clean Files, and any detected
threats with file paths and malware names) | |
| Configured virus scanners |
| 4 | | Scan report/log | Evaluate Scan Results | All Files reported as clean (step 7) | |
| Any Files reported as infected or suspicious (step 5) | |
| 5 | | Infected/suspicious file(s) | Handling infected or suspicious Files, the TDA conducts a
first analysis | Decontamination recommended: Move the identified File(s)
to a secure quarantine area, isolated from other systems and content
for further analysis and potential disinfection, and inform
dedicated staff members (step 6) | CPP-013 (Object Management Reporting) |
| Scan report | Rejection recommended: Mark the File(s) (or the entire
SIP(s) (as in case of ingest) for rejection. Notify the
producer with reasons, if appropriate and/or defined by policy (end
of the process) | CPP-013 (Object Management Reporting) |
| Guidelines for managing detected threats |
| 6 | | Quarantined file(s) | In-Depth Analysis: The personnel analyses the threat,
leading to multiple potential outcomes | False positive identified: the detected malware does not pose a
threat. Whitelist the threat and move the Files from
quarantine back to the staging (loop back to step 1) | |
| Notification to staff | Decontamination required and possible: The TDA disinfects the
Files and moves the Files from quarantine back to the
staging (loop back to step 1) | |
| Decontamination required but not possible: Notify stakeholders:
The TDA notifies the stakeholders that their content is at risk and
that it most likely must be deleted and re-submitted. The Files
are not moved away from the quarantine area. This is a more likely
outcome for AIP Files that are scanned during the
preservation (triggered by CPP-019). (step 7) | |
| 7 | | Scan report | Record the virus scan and its Outcome as a Preservation EventThis documentation should include:
- Datetime of scan
- Scanner software name
- Virus definition file version/date
- Files scanned
- Outcome for each file (e.g., 'clean', 'infected - [virus_name]',
'quarantined', 'rejected').
- Any additional actions taken
|
Provenance metadata
| CPP-016 (Metadata Ingest and Management) CPP-013 (Object Management Reporting) |
| Actions taken (quarantine, disinfection, rejection) |
| 8 | | Clean File(s) | Proceed with Clean Content or finalise Rejection:
- If content is clean: release Files from the staging area or proceed
with
ingest
- If any relevant content was rejected: Finalise the rejection process
and
archive the documentation
| Clean File(s) passed to the next ingest stage, or
rejection process completed | CPP-013 (Object Management Reporting) |
| Documentation of scan event |
Rationale(s) and worst case(s)
| Rationale | Impact of inaction or failure of the process |
|---|
| Detection of malware in SIP(s) | Ingest of contaminated Files, risking destruction of the entire TDA. |
| Process to handle and potentially reject and delete infected SIP(s) | Ingest of contaminated Files, risking destruction of the entire TDA |
| Processes to maintain up-to-date malware signature databases
and virus scanning tools | Ingest of contaminated Files, risking destruction of the entire TDA |
| Detection of malware in AIP(s) | Risking destruction of the entire TDA. |
2. Dependencies and relationships with other CPPs
Dependencies
| CPP-ID | CPP-Title | Relationship description |
|---|
| CPP-012 | Risk Mitigation | Virus scanning is a direct risk mitigation activity against
threats to content integrity and system security triggered
by CPP-012.
|
Other relations
| Relation | CPP-ID | CPP-Title | Relationship description |
|---|
| Required by | CPP-013 | Object Management Reporting | Reports on virus scanning activities, frequency of threats,
and outcomes of the actions provide essential input for
operational management and risk assessment.
|
| Required by | CPP-019 | Data Quality Assessment | Virus scanning is performed as a step in the overall Data
Quality Assessment process.
|
| Required by | CPP-029 | Ingest | Virus scanning is one of the core processes that must be
performed during ingest.
|
| Affinity with | CPP-003 | Integrity Checking | Both processes aim to ensure the "health" of Files. However,
Integrity Checking focuses on detecting technical corruption
of Files (e.g. bit rot), whereas virus scanning looks to
mitigate human-made risks ( e.g. malicious code).
|
| Not to be confused with | CPP-004 | Data Corruption Management | If a File is detected as infected and cannot be cleaned, it
might be considered "damaged." However, CPP-004 typically
applies to technical corruption or loss, rather than
deliberately human-made damage such as malware-infected
Files. In practice, infected Files are more likely to be
replaced (by the producer) or rejected.
|
| Not to be confused with | CPP-010 | File Format Validation | Both processes scan the Files to ensure that they are
suitable for preservation. File Format Validation checks if
a file conforms to its purported format specification (e.g.
is this a valid PDF/A file?) while Virus Scanning checks for
malware, regardless of format validity.
|
3. Links to frameworks
Certification
| Certification framework | Term used in framework to refer to the CPP | Section |
|---|
| CTS
Link
| | |
| Nestor Seal
Link
| | |
| ISO 16363
Link
| | |
Other frameworks and reference documents
| Reference Document | Term used in framework to refer to the process | Section |
|---|
| OAIS
Link
| Quality Assurance (within Ingest), Security | 4.2.3.34.3.4 |
| PREMIS
Link
| Event (with eventType 'virus check', Agent (the scanning software) | Event EntityAgent EntityeventType Controlled vocabulary (2.2) |
4. Reference implementations
Use cases
Virus Scan as Part of Ingest at CSC
| Institutional background |
|---|
| Institution | CSC – IT Center for Science Ltd., Finland, FI |
| Hyperlink | https://www.clamav.net/ |
| Description |
|---|
| Trigger event | Ingest |
| Problem statement | Files must be scanned for viruses as part of the
ingest pipeline to protect the TDA from viruses
|
| Proposed solution | Python script to detect viruses using ClamAv virus scanner |
WARC Virus Checker and NSFW (Not-Safe-For-Work) Content Detection Tool
| Institutional background |
|---|
| Institution | Bibliothèque nationale de Luxembourg, LU |
| Hyperlink | https://digital.library.unt.edu/ark:/67531/metadc2472470/ |
| Description |
|---|
| Trigger event | Bibliothèque nationale de Luxembourg (BnL) collects and preserves web archives that might contain viruses. These viruses may damage the library's infrastructures or the user's device. |
| Problem statement | Web archives are bundled into WARC containers. BnL needed to extract files from these containers and use an open source virus scanner to identify malware in them. |
| Proposed solution | BnL developed a Python script to extract files from WARC containers and scan them with the ClamAV virus scanner. The tool also detects NSFW ('Not Safe for Work') content with the help of the `nsfwdetection` PyTorch model. It can be used as a command-line tool or as an API. Results are either displayed in the terminal or returned as JSON by the API. WARC containing viruses are ingested, but the user is informed of their presence. |
Publicly available documentation