Views:

The Security Agent uses the Smart Scan Agent Pattern to scan for security risks and only queries the Smart Scan Pattern if the Smart Scan Agent Pattern cannot determine the risk of a file. The agent queries the Web Blocking List when a user attempts to access a website. Advanced filtering technology enables the agent to "cache" the query results. This eliminates the need to send the same query more than once.

Agents that are currently in your intranet can connect to a Smart Protection Server to query the Smart Scan Pattern or Web Blocking List. Network connection is required to connect to the Smart Protection Server. If more than one Smart Protection Server has been set up, administrators can determine the connection priority.

Tip:

Install several Smart Protection Servers to ensure the continuity of protection in the event that connection to a Smart Protection Server is unavailable.

Agents that are currently not in your intranet can connect to Trend Micro Smart Protection Network for queries. Internet connection is required to connect to the Smart Protection Network.

Figure 1. Query process

Agents without access to the network or the Internet still benefit from protection provided by the Smart Scan Agent Pattern and the cache containing previous query results. The protection is reduced only when a new query is necessary and the agent, after repeated attempts, is still unable to reach any smart protection source. In this case, the agent flags the file for verification and temporarily allows access to the file. When connection to a smart protection source is restored, all the files that have been flagged are re-scanned. Then, the appropriate scan action is performed on files that have been confirmed as a threat.

The following table summarizes the extent of protection based on the agent’s location.

Table 1. Protection Behaviors Based on Location
Location

Pattern File and Query Behavior

Access to the intranet

  • Pattern file: Agents download the Smart Scan Agent Pattern file from the Apex One server or a custom update source.

  • File and web reputation queries: Agents connect to the Smart Protection Server for queries.

Without access to the intranet but with connection to Smart Protection Network

  • Pattern file: Agents do not download the latest Smart Scan Agent Pattern file unless connection to the Apex One server or a custom update source is available.

  • File and web reputation queries: Agents connect to Smart Protection Network for queries.

Without access to the intranet and without connection to Smart Protection Network

  • Pattern file: Agents do not download the latest Smart Scan Agent Pattern file unless connection to the Apex One server or a custom update source is available.

  • File and web reputation queries: Agents do not receive query results and must rely on the Smart Scan Agent Pattern and the cache containing previous query results.