OPSWAT · Product

MetaDefender Core

Check files before they enter your business workflows.

OPSWAT

File security · Application integration

Application

A control point between incoming files and your application

MetaDefender Core is an OPSWAT product for analysing file-borne threats. It combines multiple scanning engines with content processing technologies, including Deep CDR. Applications can integrate with it through a REST API.

It provides a starting point for security teams and administrators designing checks on documents received from customers, partners or other systems. The control point should reflect the actual flow of data.

Key capabilities

Multiscanning

Analysing a file with multiple anti-malware engines reduces reliance on a single detection mechanism. Individual engine results provide information for assessing the file.

Deep CDR

Content Disarm and Reconstruction processes supported documents, removes potentially dangerous elements and rebuilds content. Acceptable changes to documents should be agreed with their recipients.

REST API integration

Applications can submit files for analysis and retrieve results. How they act on the response should form part of the integration design.

Available engines, modules and capabilities depend on the licence and product version. The scope is confirmed before deployment.

Integration example

From document upload to an application decision

This sequence illustrates a proposed control point in an application that accepts attachments. It is an integration design example, rather than a ready-made configuration for every deployment.

  1. Receive the file

    The application accepts the document into a separate area. The intended recipient does not receive it until the checks are complete.

  2. Submit for analysis

    The integration sends the file to Core and keeps the analysis identifier. It uses that identifier to retrieve processing status and results.

  3. Interpret the result

    The application distinguishes completed analysis, processing in progress and an error. A missing response should not be treated as confirmation that a file is safe.

  4. Apply the next action

    An agreed policy determines whether to release the document, refer it for further assessment or reject it. The decision and result should be associated with the operation identifier.

Where to plan file checks

Customer portal

Attachments to applications and service requests can be checked before staff receive them. The design should account for user messages and waiting time.

Partner document exchange

A shared analysis point can help standardise incoming file handling. Ownership of documents held for investigation must be agreed.

Automated workflows

Checks can be included before further processing of incoming files. Retries, timeouts and service unavailability require particular attention.

Integration and service availability

When distributing traffic between Core instances, results must remain associated with the instance processing the analysis. OPSWAT documentation describes session persistence for application-layer load balancing.

A deployment design should also define monitoring, updates, maintenance ownership and error handling. Hardware requirements should follow the workload and configuration, rather than assuming the same throughput for every environment.

Questions to resolve before deployment

Questions to resolve before deployment
AreaDesign question
File trafficWhat file types, sizes, volumes and peak loads should be expected?
Response timeDoes the user wait for a result, or can the process run asynchronously?
Document processingAre changes through CDR acceptable, and how will document usability be checked?
IntegrationWhich system receives the result and decides how the file is used?
AvailabilityHow will the application handle errors, timeouts and maintenance windows?
MaintenanceWho owns updates, monitoring, permissions and data retention?

RAMS DATA

Start with your file workflow

In a discussion with RAMS DATA, we can examine the control point, integration requirements and deployment scope. A description of the current process and example document types will help. The scope of implementation and maintenance will be agreed for your environment.

  • Define the objective and integration point.
  • Agree test scenarios and acceptance criteria.
  • Discuss deployment and ongoing maintenance.

Which files enter your organisation?

Describe your application and how it receives documents. This is a useful starting point for a discussion about MetaDefender Core.

Discuss your deployment