Sign In with your
Trend Micro Account
Need Help?
Need More Help?

Create a technical support case if you need further support.

Changing Conventional Scan to Smart Scan and vice versa in Apex One

    • Updated:
    • 1 Aug 2019
    • Product/Version:
    • Apex Central All.All
    • Apex One All.All
    • Apex One as a Service All.All
    • Platform:
    • Windows 10
    • Windows 2008
    • Windows 2008 Server R2
    • Windows 2012 Server
    • Windows 2012 Server R2
    • Windows 2016 Server
    • Windows 2019 Server
    • Windows 7 64-Bit
    • Windows 7 SP1 64bit
    • Windows 8 32-Bit
    • Windows 8 64-Bit
    • Windows 8.1 32-Bit
    • Windows 8.1 64-Bit
Summary

Apex One Security Agents can use either Conventional Scan or Smart Scan when scanning for malicious threats.

Details
Public
  1. Log on to the Apex Central console.
  2. Go to Policies > Policy Management.
  3. Create or select the policy created.
  4. On targets, select Manage Targets and select target Apex One agents.
  5. Under Apex One Agent Settings, select Scan Methods.

You should see the Scan Method Selected on your current configuration.

Scan Methods

 
If you are using default settings, Smart Scan is the default selected Option.
  1. Log on to the Apex Central console.
  2. Select Policies > Policy Management.

    Scan Methods

  3. Select the Policy you wish to customize.

    Scan Methods

  4. Select Scan Methods.

    Scan Methods

  5. Select Either of the following:
    • Conventional Scan
    • Smart Scan

    Scan Methods

  6. Click Deploy.

For more information about the Scan Methods:

A conventional scan client stores all Apex One patterns on the endpoint and scans all files locally.

Smart Scan leverages threat signatures that are stored in the cloud. When in Smart Scan mode, the Apex One security agent first scans for security risks locally. If the client cannot determine the risk of the file during the scan, the client connects to the local Smart Scan Server. If the clients cannot connect to it, they will attempt to connect to the Trend Micro Global Smart Scan Server.

Smart Scan provides the following features and benefits:

  • Provides fast, real-time security status lookup capabilities in the cloud.
  • Reduces the overall time it takes to deliver protection against emerging threats.
  • Reduces network bandwidth consumed during pattern updates. The bulk of pattern definition updates only needs to be delivered to the cloud and not to many endpoints.
  • Reduces the cost and overhead associated with corporate-wide pattern deployments.
  • Lowers kernel memory consumption on endpoints. Consumption increases minimally over time.

Trend Micro strongly recommends switching from Conventional Scanning to Smart Scanning:

  • Recent statistics shows that the Smart Scan Agent pattern (OTH, which is stored locally on the actual agent that uses Smart Scanning) covers 80% of the total threats, and that the Smart Scan pattern (TBL, stored on the Scan Server) covers the other 20%.
  • Aside from Smart Scan Agent pattern (icrc$oth.xxx), a local cache is used to reduce about 80% of outgoing queries. CRC cache works as a partial Smart Scan Pattern replica so that previously obtained CRC can be reused later.

In other words, the CRCs are ready to be used to protect an endpoint user and are effective on malware that have been previously detected. However, the date may vary among individual users according to their usage behavior.

Basis of ComparisonConventional ScanSmart Scan
AvailabilityAvailable in Apex One, including all earlier OfficeScan versionsAvailable in Apex One, including versions of OfficeScan 10.0 to XG
Scanning behaviorThe conventional scan client performs scanning on the local computer

The smart scan client performs scanning on the local computer.

If the client cannot determine the risk of the file during the scan, the client verifies the risk by sending a scan query to a Smart Scan Server.

Using advanced filtering technology, the client "caches" the scan query result. The scanning performance improves because the client does not need to send the same scan query to the Smart Scan Server.

If a client cannot verify a file’s risk locally and is unable to connect to any Smart Scan Server after several attempts:

      • The client flags the file for verification.
      • The client allows temporary access to the file.

When connection to a Smart Scan Server is restored, all the files that have been flagged are re-scanned. The appropriate scan action is then performed on files that have been confirmed as infected.

Components in use and updatedAll components are available on the update source, except the Smart Scan Agent PatternAll components are available on the update source, except the Virus Pattern and Spyware Active-monitoring Pattern
Typical update sourceApex One serverApex One server
Premium
Test Now
Internal
Rating:
Category:
Configure; Troubleshoot
Solution Id:
1122569
Feedback
Did this article help you?

Thank you for your feedback!

To help us improve the quality of this article, please leave your email here so we can clarify further your feedback, if neccessary:
We will not send you spam or share your email address.

*This form is automated system. General questions, technical, sales, and product-related issues submitted through this form will not be answered.

If you need additional help, you may try to contact the support team. Contact Support

To help us improve the quality of this article, please leave your email here so we can clarify further your feedback, if neccessary:
We will not send you spam or share your email address.

*This form is automated system. General questions, technical, sales, and product-related issues submitted through this form will not be answered.