METHOD OF COMPREHENSIVE ASSESSMENT OF THE EFFICIENCY OF APPLICATION OF CONTENT DISPOSAL AND RECONSTRUCTION TECHNOLOGY IN NETWORK INFRASTRUCTURE
DOI:
https://doi.org/10.31673/2409-7292.2026.029318Abstract
The article explores the possibilities of using Content Disarm and Reconstruction (CDR) technology to increase
the effectiveness of network resource protection during processing and transfer of files of various formats. The relevance
of the study is due to the rapid increase in the dangers associated with the growth of the number of hidden threats
implemented through legitimate file structures and capable of bypassing traditional means of detecting malicious content,
which causes a high level of complexity in their prevention or neutralization. The main attention is focused on developing
a method for comprehensive experimental assessment of the effectiveness of using CDR solutions as a means of
preventive countermeasures against threats that arise during the exchange of files with potentially malicious content. The
work considers the basics of the content security problem and the idea of its cleaning as one of the ways to solve it, as
well as the principle of operation of the content disarm and reconstruction technology, which consists in removing active
and potentially dangerous elements of the file with the subsequent formation of its safe copy based on the standard
structure of the corresponding file format that was processed. The features of CDR application to various types of files,
in particular documents, archives, images and multimedia content, are analyzed, and its advantages compared to classical
signature and behavioral protection tools, such as antiviruses and sandbox detection methods, are also identified. An
experimental methodology for mass testing CDR solutions on large volumes of files is proposed with further analysis of
the results and formation of a system of quantitative performance indicators that take into account the level of
neutralization of hidden threats, reconstruction correctness, processing performance and impact on network and
computing resources. As a result, directions for further research are identified, in particular, clarification of optimal
scenarios for the use of content neutralization and reconstruction technology, formalization of efficiency criteria and
development of methods for optimizing performance while maintaining high quality of file reconstruction.
Keywords: cybersecurity; information protection; network security; content disarm.
References
1. Wiseman, S. (2017). Content security through transformation: Problem statement (Report DS-2017-1). Deep
Secure. DOI: 10.13140/RG.2.2.13179.92969.
2. Wiseman, S. (2018). Classes of content transform (Technical Report Deep Secure-2018-1). Deep Secure.
DOI: 10.13140/RG.2.2.13130.47043.
3. Wiseman, S. (2017). Comparing content threat defence strategies. Deep Secure. DOI: 10.13140/RG.
2.2.27431.85925.
4. Wiseman, S. (2017). Stegware: Using steganography for malicious purposes (Report DS-2017-4). Deep
Secure. DOI: 10.13140/RG.2.2.15283.53289.
5. OPSWAT. (n.d.). Content disarm and reconstruction (CDR) selection guide. OPSWAT. https://info.opswat.
com/hubfs/Demand%20Gen%20Assets/White%20Papers/OPSWAT_CDR_SelectionGuide_EN.pdf.
6. OPSWAT. (2023). OPSWAT deep CDR: Content disarm and reconstruction. OPSWAT. https://selabs.uk/wpcontent/uploads/2024/03/cdr-protection-enterprise-OPSWAT-Deep-CDR-2023-10.pdf.
7. Olzak, T. (2025). Content disarm and reconstruction (CDR). https://www.researchgate.net/profile/TomOlzak/publication/389551208_Content_Disarm_and_Reconstruction_CDR/links/67c734b7645ef274a49ab7eb/ContentDisarm-and-Reconstruction-CDR.pdf.
8. Belkind, E., Dubin, R., & Dvir, A. (n.d.). Open image content disarm and reconstruction. https://arxiv.org/
pdf/2307.14057.
9. Dubin, R. (n.d.). Content disarm and reconstruction of PDF files. DOI: 10.1109/ACCESS.2023.3267717.
10. Coelho, J. F. C. (n.d.). Segurança em transferências de arquivos: A importância da limpeza de arquivos na sua
transferência através de uma tecnologia content disarm and reconstruction e a sua implementação.
http://hdl.handle.net/10400.26/51138.
11. Gilkarov, D., & Dubin, R. (n.d.). Zero-trust artificial intelligence model security based on moving target
defense and content disarm and reconstruction. https://arxiv.org/pdf/2503.01758.
12. Dubin, R. (n.d.). Disarming attacks inside neural network models. https://arxiv.org/pdf/2309.03071.
13. Chaganti, R., Ravi, V., Alazab, M., & Pham, T. D. (n.d.). Stegomalware: A systematic survey of malware
hiding and detection in images, machine learning models and research challenges. https://arxiv.org/pdf/2110.02504
14. Berlin, K., & Saxe, J. (n.d.). Improving zero-day malware testing methodology using statistically significant
time-lagged test samples. https://arxiv.org/pdf/1608.00669.
15. Hamilton, E. (1992). JPEG file interchange format. C-Cube Microsystems. https://www.w3.org/Graphics/
JPEG/jfif3.pdf.