OPSWAT · Product

MetaDefender ICAP Server

Control files at a network-flow checkpoint before content reaches a user or target system.

OPSWAT

ICAP integration · File inspection

Application

A control layer for ICAP-enabled traffic

MetaDefender ICAP Server connects file analysis with devices and services that support the ICAP protocol. This allows the control point to work with an existing proxy, repository or security gateway.

We design the decision around the actual flow: what should be inspected, when a result is required and how the source system should behave in an error or timeout condition.

Key capabilities

ICAP integration

The service can receive requests from ICAP clients and return a result according to the agreed policy.

Content inspection

Files can be submitted to multi-engine analysis and selected content sanitisation mechanisms.

Decision in the flow

The result can determine whether a file is released, held or sent for additional processing.

The exact behaviour depends on the ICAP client, queue configuration and service-availability requirements.

How a file is inspected

The process should be adapted to the system that initiates the ICAP request.

  1. Request from a system

    A proxy, repository or other service sends the file to the inspection point.

  2. Submit for analysis

    The ICAP Server directs the content to the selected inspection mechanisms.

  3. Evaluate the response

    The source system receives the result and applies its release or block rule.

  4. Record the event

    The result, operation identifier and decision can be connected with process logs.

Typical use cases

Web proxies

Downloaded files can be assessed before they are made available to a user.

Document repositories

Inspection can take place before new content is saved in a file system or repository.

System-to-system exchange

ICAP can complement processes where files move between zones with different trust levels.

Integration design

The main decisions concern synchronous or asynchronous processing, size limits, response time and behaviour when the scanner is unavailable.

Before launch, we also test file types, response handling, errors and the impact of inspection on the performance of the existing flow.

RAMS DATA

Find the right ICAP control point

We will review your proxies, repositories and file flows to identify an integration point without unnecessarily redesigning the environment.

  • Describe the systems that initiate requests.
  • Define release and block policies.
  • Test performance and failure behaviour.

Want to organise file inspection?

Describe the system that handles the files and how it communicates. We will select an integration scenario suitable for the environment.

Discuss your deployment