Scan_Methods

Scan Methods

OfficeScan clients can use either conventional scan or smart scan when scanning for security risks.

Conventional Scan

Conventional scan is the scan method used in all earlier OfficeScan versions. A conventional scan client stores all OfficeScan components on the client computer and scans all files locally.

Smart Scan

Smart scan is a next-generation, in-the-cloud based endpoint protection solution. At the core of this solution is an advanced scanning architecture that leverages threat signatures that are stored in-the-cloud.

Scan Methods Compared

The following table provides a comparison between these two scan methods:

Comparison between conventional scan and smart scan

Basis of Comparison

Conventional Scan

Smart Scan

Availability

Available in this and all earlier OfficeScan versions

Available starting from OfficeScan 10

Scanning behavior

The conventional scan client performs scanning on the local computer.

  • The smart scan client performs scanning on the local computer.

  • If the client cannot determine the risk of the file during the scan, the client verifies the risk by sending a scan query to a Smart Protection Server.

  • Using advanced filtering technology, the client "caches" the scan query result. The scanning performance improves because the client does not need to send the same scan query to the Smart Protection Server.

  • If a client cannot verify a file’s risk locally and is unable to connect to any Smart Protection Server after several attempts:

  • The client flags the file for verification.

  • The client allows temporary access to the file.

  • The client connects to the Trend Micro Smart Protection Network if the client's computer location is set to the default client connection status setting.

  • When connection to a Smart Protection Server is restored, all the files that have been flagged are re-scanned. The appropriate scan action is then performed on files that have been confirmed as infected.

Components in use and updated

All components available on the update source, except the Smart Scan Agent Pattern

All components available on the update source, except the Virus Pattern and Spyware Active-monitoring Pattern

Typical update source

OfficeScan server

OfficeScan server

Switching From Smart Scan to Conventional Scan

When you switch clients to conventional scan, consider the following:

1. Number of clients to switch

Switching a relatively small number of clients at a time allows efficient use of OfficeScan server and Smart Protection Server resources. These servers can perform other critical tasks while clients change their scan methods.

2. Timing

When switching back to conventional scan, clients will likely download the full version of the Virus Pattern and Spyware-active Monitoring Pattern from the OfficeScan server. These pattern files are only used by conventional scan clients.

Consider switching during off-peak hours to ensure the download process finishes within a short amount of time. Also consider switching when no client is scheduled to update from the server. Also temporarily disable "Update Now" on clients and re-enable it after the clients have switched to smart scan.

3. Client tree settings

Scan method is a granular setting that can be set on the root, domain, or individual client level. When switching to conventional scan, you can:

  1. Select to use conventional scan or smart scan.

  2. If you selected domain(s) or client(s) on the client tree, click Save to apply settings to the domain(s) or client(s). If you selected the root icon, choose from the following options:

Switching From Conventional Scan to Smart Scan

If you are switching clients from conventional scan to smart scan, take note of the following:

1. Product license

To use smart scan, ensure that you have activated the licenses for the following services and that the licenses are not expired:

2. Smart protection sources

Smart scan clients connect to smart protection sources to send scan queries and verify a file’s risk against the Smart Scan Pattern. The smart protection source depends on the client’s location. Internal clients connect to a Smart Protection Server, while external clients connect to the Trend Micro Smart Protection Network. Refer to Smart Protection Servers.

Trend Micro Smart Protection Network

If connection to the Smart Protection Network requires proxy authentication, specify authentication credentials. For details, see External Proxy.

Smart Protection Server

OfficeScan provides two types of Smart Protection Servers. Both servers have the same functions.

If you have not set up any of these servers, install them first before switching clients to smart scan. Refer to the Trend Micro Smart Protection Server for OfficeScan Getting Started Guide for information on reactivating the integrated server, and installing and managing the standalone server.

3. Smart Protection Server list

Add the Smart Protection Servers you have set up to the Smart Protection Server list. Clients refer to the list to determine which Smart Protection Server to connect to. The client tries connecting to other servers on the list if it cannot connect to a particular server.

For details on configuring the list, see Smart Protection Sources.

4. Computer location settings

OfficeScan includes a location awareness feature that identifies the client computer’s location and determines whether the client connects to the Smart Protection Network or Smart Protection Server. This ensures that clients remain protected regardless of their location.

To configure location settings, see Computer Location.

5. OfficeScan server

Ensure that clients can connect to the OfficeScan server. Only online clients will be notified to switch to smart scan. Offline clients get notified when they become online. Roaming clients are notified when they become online or, if the client has scheduled update privileges, when scheduled update runs.

Also verify that the OfficeScan server has the latest components because smart scan clients need to download the Smart Scan Agent Pattern from the server. To update components, see OfficeScan Server Update.

6. Other Trend Micro products

If you have Trend Micro™ Network VirusWall™ Enforcer installed:

7. Number of clients to switch

Switching a relatively small number of clients at a time allows efficient use of OfficeScan server and Smart Protection Server resources. These servers can perform other critical tasks while clients change their scan methods.

8. Timing

When switching to smart scan for the first time, clients need to download the full version of the Smart Scan Agent Pattern from the OfficeScan server. The Smart Scan Pattern is only used by smart scan clients.

Consider switching during off-peak hours to ensure the download process finishes within a short amount of time. Also consider switching when no client is scheduled to update from the server. Also temporarily disable "Update Now" on clients and re-enable it after the clients have switched to smart scan.

9. Client tree settings

Scan method is a granular setting that can be set on the root, domain, or individual client level. When switching to smart scan, you can:

See also: