About Malware detection
NetBackup finds malware in supported backup images and finds the last good-known image which is malware free.
Malware detection provides the following benefits:
You can select one or more backup images of the supported policy-types for on-demand scan. You can use a predefined list of scan host.
If malware is detected during the scanning, a notification is generated in WebUI.
The following steps depict the Malware workflow:
Primary server verify if the given backup images are eligible for scan. Primary server checks if they have valid instant access capable copy and if the policy type is supported.
Note:
The backup images which failed in validation, are ignored.
Once backup images are queued for on-demand scan, the primary server identify the storage server and create instant access mount of configured share type specified in scan host pool.
Primary server instructs the available media server to initiate Malware scan on the scan host.
Scan host mounts instant access mount on the scan host and initiate the scan using malware tool configured in the scan host pool.
Once scan is completed, scan host is unmounted, and results are sent to the media server. Then, media server sends result to the primary server.
Primary server updates the scan results and unmounts the instant access.
Maximum of three scans can be initiated on scan host at given point of time.