scanmet

Scan Methods

OfficeScan clients can use one of two scan methods when scanning for security risks. The scan methods are smart scan and conventional scan.

Smart Scan

Clients that use smart scan are referred to as smart scan clients in this document. Smart scan clients benefit from local scans and in-the-cloud queries provided by File Reputation Services.

Conventional Scan

Clients that do not use smart scan are called conventional scan clients. A conventional scan client stores all OfficeScan components on the client computer and scans all files locally.

Scan Methods Compared

The following table provides a comparison between the two scan methods:

Conventional Scan and Smart Scan Compared

Basis of Comparison

Conventional Scan

Smart Scan

Availability

Available in this and all earlier OfficeScan versions

Available starting in OfficeScan 10

Scanning behavior

The conventional scan client performs scanning on the local computer.

  • The smart scan client performs scanning on the local computer.

  • If the client cannot determine the risk of the file during the scan, the client verifies the risk by sending a scan query to a smart protection source.

  • The client "caches" the scan query result to improve the scan performance.

Components in use and updated

All components available on the update source, except the Smart Scan Agent Pattern

All components available on the update source, except the Virus Pattern and Spyware Active-monitoring Pattern

Typical update source

OfficeScan server

OfficeScan server

Default Scan Method

In this OfficeScan version, the default scan method for fresh installations is smart scan. This means that if you perform OfficeScan server fresh installation and did not change the scan method on the web console, all clients that the server manages will use smart scan.

If you upgrade the OfficeScan server from an earlier version and automatic client upgrade is enabled, all clients managed by the server will still use the scan method configured before the upgrade. For example, upgrading from OfficeScan 8.x, which only supports conventional scan, means that all clients will still use conventional scan upon upgrade. If you upgrade from OfficeScan 10, which supports smart scan and conventional scan, all upgraded clients that use smart scan will continue to use smart scan and all clients using conventional scan will continue to use conventional scan.

Switching from Smart Scan to Conventional Scan

When you switch clients to conventional scan, consider the following:

Considerations When Switching to Conventional Scan

Consideration

Details

Number of clients to switch

Switching a relatively small number of clients at a time allows efficient use of OfficeScan server resources. The OfficeScan server can perform other critical tasks while clients change their scan methods.

Timing

When switching back to conventional scan, clients will likely download the full version of the Virus Pattern and Spyware-active Monitoring Pattern from the OfficeScan server. These pattern files are only used by conventional scan clients.

Consider switching during off-peak hours to ensure the download process finishes within a short amount of time. Also consider switching when no client is scheduled to update from the server. Also temporarily disable "Update Now" on clients and re-enable it after the clients have switched to smart scan.

Client tree settings

Scan method is a granular setting that can be set on the root, domain, or individual client level. When switching to conventional scan, you can:

  • Create a new client tree domain and assign conventional scan as its scan method. Any client you move to this domain will use conventional scan. When you move the client, enable the setting Apply settings of new domain to selected clients.

  • Select a domain and configure it to use conventional scan. Smart scan clients belonging to the domain will switch to conventional scan.

  • Select one or several smart scan clients from a domain and then switch them to conventional scan.

  • Any changes to the domain’s scan method overrides the scan method you have configured for individual clients.

Switching from Conventional Scan to Smart Scan

If you are switching clients from conventional scan to smart scan, ensure that you have set up Smart Protection Services. For details, see Setting Up Smart Protection Services.

The following table provides other considerations when switching to smart scan:

Considerations When Switching to Smart Scan

Consideration

Details

Unavailable features and functions

Smart scan clients cannot report Smart Scan Pattern and Smart Scan Agent Pattern information to the Policy Server.

Product license

To use smart scan, ensure that you have activated the licenses for the following services and that the licenses are not expired:

  • Antivirus

  • Web Reputation and Anti-spyware

OfficeScan server

Ensure that clients can connect to the OfficeScan server. Only online clients will be notified to switch to smart scan. Offline clients get notified when they become online. Roaming clients are notified when they become online or, if the client has scheduled update privileges, when scheduled update runs.

Also verify that the OfficeScan server has the latest components because smart scan clients need to download the Smart Scan Agent Pattern from the server. To update components, see OfficeScan Server Updates.

Number of clients to switch

Switching a relatively small number of clients at a time allows efficient use of OfficeScan server resources. The OfficeScan server can perform other critical tasks while clients change their scan methods.

Timing

When switching to smart scan for the first time, clients need to download the full version of the Smart Scan Agent Pattern from the OfficeScan server. The Smart Scan Pattern is only used by smart scan clients.

Consider switching during off-peak hours to ensure the download process finishes within a short amount of time. Also consider switching when no client is scheduled to update from the server. Also temporarily disable "Update Now" on clients and re-enable it after the clients have switched to smart scan.

Client tree settings

Scan method is a granular setting that can be set on the root, domain, or individual client level. When switching to smart scan, you can:

  • Create a new client tree domain and assign smart scan as its scan method. Any client you move to this domain will use smart scan. When you move the client, enable the setting Apply settings of new domain to selected clients.

  • Select a domain and configure it to use smart scan. Conventional scan clients belonging to the domain will switch to smart scan.

  • Select one or several conventional scan clients from a domain and then switch them to smart scan.

  • Any changes to the domain’s scan method overrides the scan method you have configured for individual clients.

IPv6 support

Smart scan clients send scan queries to smart protection sources.

A pure IPv6 smart scan client cannot send queries directly to pure IPv4 sources, such as:

  • Smart Protection Server 2.0 (integrated or standalone)

  • IPv6 support for Smart Protection Server starts in version 2.5.

  • Trend Micro Smart Protection Network

Similarly, a pure IPv4 smart scan client cannot send queries to pure IPv6 Smart Protection Servers.

A dual-stack proxy server that can convert IP addresses, such as DeleGate, is required to allow smart scan clients to connect to the sources.

  1. In the client tree, click the root domain icon to include all clients or select specific domains or clients.

  2. Click Settings > Scan Settings > Scan Methods.

  3. Select Conventional scan or Smart scan.

  4. If you selected domain(s) or client(s) in the client tree, click Save. If you clicked the root domain icon, choose from the following options:

See also: