Inside a USB scan: how it actually works

Most security tools live on the network or the endpoint. The link22 USB Scan Solution lives somewhere different: at the physical doorway where removable media meets your environment. That changes how you reason about it. There is no abstract pipeline. There are two USB ports, a touch screen, and a set of decisions that get made before any file reaches a workstation.
usb scanning station

This article walks through what happens inside that scan, step by step, and explains the parts the demo video does not have time to cover.

The five steps

The walkthrough video shows a process that fits on one screen. Behind that simplicity is a deliberate design.

1. Physical separation. The user inserts the untrusted drive (often referred to as the red drive) into the source port. A clean, company-approved drive (the green drive) goes into the destination port. The two drives never see the same data path. This is the foundation of the whole solution. Logical isolation alone is not enough when a USB device might be impersonating a keyboard or executing firmware-level commands.

2. File selection. The interface lets the user browse the source drive and pick which files to import. The station ships pre-configured, so there is nothing for an end user to set up. This matters more than it sounds: every step that requires training is a step that gets skipped, worked around, or done wrong under time pressure.

3. Deep analysis. This is where the scan does its work. Files run through multiple antivirus engines in parallel. Signature-based detection catches known threats. Heuristic and behavioural analysis catches variants. On top of that, Content Disarm and Reconstruction (CDR) deconstructs document files and rebuilds them from scratch. Macros, embedded scripts, and hidden payloads do not survive the rebuild.

4. Blocking and logging. If something fails the checks, it does not get a second chance. The transfer is blocked, the malicious file is deleted, and the event is recorded. The user sees a clear warning on the screen. Your security team sees the log entry. Nothing crosses the perimeter quietly.

5. Safe transfer. Clean files are written to the green destination drive. The user removes it, walks to their workstation, and uses it as they would any approved drive. The risk has been handled at the doorway, not at the desk.

What the video does not have time to explain

A two-minute walkthrough has to leave things out. Three of those omissions matter when you are evaluating the solution.

File types and limits. The scan handles the document and archive formats that move between organisations every day: Office files, PDF, common image formats, archives. Encrypted archives are the exception. CDR cannot rebuild what it cannot read, so encrypted containers need to be extracted before scanning. This is not a gap; it is a deliberate choice. The alternative would be to let opaque data through, which defeats the point of the checkpoint.

Time per scan. Scan time depends on file size and engine count, not on network state. Because everything happens locally on the station, you do not see the latency variability that comes with cloud-based scanning. A typical document set finishes in seconds. Larger archives take longer, but never long enough to push users back toward shortcuts.

Antivirus updates without internet. This is the question that comes up first in regulated environments. The station supports three update paths: direct internet connection for environments that allow it, local network updates for segmented networks, and signed offline update bundles for fully air-gapped sites. All three keep the signature database current without breaking the isolation properties of the deployment.

Why physical separation does the heavy lifting

It is tempting to think of this as a software problem. It is not. Plenty of USB-borne attacks bypass software defences entirely. A device that registers itself as a Human Interface Device can start typing commands the moment it is plugged in. A USB-kill device can deliver an electrical surge that takes the host down before any operating system gets a chance to log it.

The two-port design exists because trust cannot be derived from inspection alone. The source drive talks to a hardened, isolated environment that knows how to handle hostile devices. The clean drive talks to your network. They never talk to each other. That separation is the part of the solution that survives every category of USB attack, including the ones we have not seen yet.

What the audit log captures

Every scan is recorded: timestamp, user (where applicable), source drive identifier, files selected, files transferred, files blocked, threats detected. This matters for two reasons.

First, it gives your security team something to investigate. A blocked transfer is a signal: someone tried to bring something in, and that something failed a check. The log lets you trace the source and decide what to do next.

Second, it is what auditors look for under NIS2 and other regulatory frameworks that mandate documented handling of removable media. A scan station that runs but does not log is not an auditable control. The link22 station logs by default.

Where this fits

The USB Scan Solution is not a replacement for endpoint protection, network segmentation, or staff training. It is the missing piece at a specific point in the data flow: the moment when something physical from outside your organisation needs to become something usable inside. That moment used to be a coin toss. With a checkpoint in place, it is a process.

If your environment relies on USB drives for legitimate operational reasons (and most regulated environments still do), the scan station is the lowest-friction way to keep that workflow without keeping the risk.

Learn more about the link22 USB Scan Solution at link22.eu/product/usb-scan-solution/.

Marcus Ekbäck - Business Area Manager CDS

Contact us!​

Sign up for our newsletter!​