InterviewDB Experience · USA

Antivirus Scanner - Design a File Scanning and Quarantine System

Interview Experience

Problem

Design an antivirus scanning system. It should:

  • Accept a file (represented as a byte string or path).
  • Check against a signature database (each signature is a known malicious byte pattern).
  • Classify the file as CLEAN, INFECTED, or SUSPICIOUS.
  • On INFECTED, quarantine the file (move to isolated storage, log the event).
  • Support adding new signatures at runtime.
python
class AntivirusScanner:
    def load_signatures(self, signatures: List[bytes]): ...
    def scan(self, file_path: str) -> ScanResult: ...
    def quarantine(self, file_path: str, reason: str): ...
    def add_signature(self, signature: bytes): ...

class ScanResult:
    status: str   # "CLEAN" | "INFECTED" | "SUSPICIOUS"
    matched_signatures: List[bytes]
    scanned_at: datetime

Example:

scanner.load_signatures([b"\xDE\xAD\xBE\xEF", b"MALWARE_MARKER"])
result = scanner.scan("/tmp/suspicious.exe")
# result.status -> "INFECTED"
# result.matched_signatures -> [b"MALWARE_MARKER"]

Follow-ups

  1. How would you use Aho-Corasick to scan for multiple signatures in a single O(n) pass?
  2. How do you scan compressed/archived files?
  3. How would you parallelize scanning across thousands of files?
  4. How do you prevent a quarantine bypass where malware deletes itself before isolation?

Full Details

Problem

Design an antivirus scanning system. It should:

  • Accept a file (represented as a byte string or path).
  • Check against a signature database (each signature is a known malicious byte pattern).
  • Classify the file as CLEAN, INFECTED, or SUSPICIOUS.
  • On INFECTED, quarantine the file (move to isolated storage, log the event).
  • Support adding new signatures at runtime.
python
class AntivirusScanner:
    def load_signatures(self, signatures: List[bytes]): ...
    def scan(self, file_path: str) -> ScanResult: ...
    def quarantine(self, file_path: str, reason: str): ...
    def add_signature(self, signature: bytes): ...

class ScanResult:
    status: str   # "CLEAN" | "INFECTED" | "SUSPICIOUS"
    matched_signatures: List[bytes]
    scanned_at: datetime

Example:

scanner.load_signatures([b"\xDE\xAD\xBE\xEF", b"MALWARE_MARKER"])
result = scanner.scan("/tmp/suspicious.exe")
# result.status -> "INFECTED"
# result.matched_signatures -> [b"MALWARE_MARKER"]

Follow-ups

  1. How would you use Aho-Corasick to scan for multiple signatures in a single O(n) pass?
  2. How do you scan compressed/archived files?
  3. How would you parallelize scanning across thousands of files?
  4. How do you prevent a quarantine bypass where malware deletes itself before isolation?

About This Question

This is a candidate experience report from a c3 ai interview during the onsite round.

It covers the following topics: Coding, Sql, Strings, Onsite .