Design and Evaluation of a Local Multi-Antivirus Scanning System: Containerized Orchestration and Performance Analysis of Parallel Antivirus Engines
2026 (English)Independent thesis Advanced level (degree of Master (Two Years)), 20 credits / 30 HE credits
Student thesis
Abstract [en]
This thesis studies malware scanning in secure USB transfer systems for high-assurance or air-gapped environments. In such settings, cloud-based multi-engine scanning services are unavailable or disallowed, while individual antivirus engines remain imperfect and often disagree on scan outcomes. The thesis therefore designs and evaluates a locally deployed, containerized multi-engine scanning system for secure USB file transfers. By implementing a proof-of-concept prototype with a Rust-based orchestration backend and Dockerized scanner plugins, and by evaluating it on controlled benign corpora and a MalwareBazaar-derived malware corpus, the thesis examines throughput, engine disagreement, decision policies, and architectural deployability. The results show that the backend metric concurrency_efficiency can be used to distinguish real file-level overlap from downstream engine saturation: across the benchmark sweeps, the metric followed the expected inverse concurrency trend even when throughput plateaued, indicating that the backend applied file concurrency correctly and that the observed knees were caused by engine-side limits rather than by missing orchestration parallelism. The results also show substantial verdict disagreement across ClamAV, AV1, and AV2 on the malware corpus. Based on these findings, the thesis proposes a review-aware quorum heuristic and a cascade any-hit execution strategy. In the direct comparison reported here, the cascade any-hit mode preserved the same aggregate outcomes as full parallel scanning while reducing batch duration by 27% and total engine scans by 58%. The study also shows that a plugin-based container design can support local multi-engine scanning and improve modularity and maintainability, but that this is achieved by front-loading adapter, configuration, and observability work. These findings are intended to support the design of local scanning systems for offline or security-critical environments and to clarify the trade-offs between performance, policy sensitivity, and deployability rather than to make a universal claim about malware-detection accuracy.
Place, publisher, year, edition, pages
2026. , p. 40
Keywords [en]
Cybersecurity, Malware, Antivirus
National Category
Computer and Information Sciences
Identifiers
URN: urn:nbn:se:liu:diva-227073ISRN: LIU-IDA/LITH-EX-A--26/083--SEOAI: oai:DiVA.org:liu-227073DiVA, id: diva2:2094652
External cooperation
Björn Knuthammar, link22 AB
Subject / course
Computer Engineering
Supervisors
Examiners
2026-08-282026-08-242026-08-28Bibliographically approved