05.08.2013 Views

OfficeScan 10 Administrator's Guide - Online Help Home - Trend Micro

OfficeScan 10 Administrator's Guide - Online Help Home - Trend Micro

OfficeScan 10 Administrator's Guide - Online Help Home - Trend Micro

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Behavior Monitoring<br />

Protecting Computers from Security Risks<br />

<strong>OfficeScan</strong> constantly monitors computers (or endpoints) for unusual modifications to<br />

the operating system or on installed software. Administrators (or users) can create<br />

exception lists that allow certain programs to start despite violating a monitored change,<br />

or completely block certain programs. In addition, programs with a valid digital<br />

signature or have been certified are always allowed to start.<br />

Note: To help ensure that this feature does not interfere with critical applications,<br />

<strong>OfficeScan</strong> leaves this feature disabled on server platforms, even when it is enabled<br />

through the console. To enable this feature on a server computer, manually modify<br />

registry settings on that computer. For instructions, refer to Post-installation<br />

Considerations on page 3-57.<br />

To manage behavior monitoring settings:<br />

PATH: NETWORKED COMPUTERS > CLIENT MANAGEMENT > SETTINGS > BEHAVIOR MONITOR-<br />

ING SETTINGS<br />

1. From the Behavior Monitoring screen, update the following as required:<br />

Note: <strong>OfficeScan</strong> automatically enables Malware Behavior Blocking and disables Event<br />

Monitoring.<br />

• Enable Malware Behavior Blocking: Select this option to enable program<br />

behavior monitoring for proactive detection of malware and similar threats.<br />

• Enable Event Monitoring: Select this option to monitor system events that<br />

may introduce threats/security risks into the computer and then select an<br />

action for each system event:<br />

Tip: <strong>Trend</strong> <strong>Micro</strong> recommends enabling Certified Safe Software Service to reduce the<br />

likelihood of false positive detections. See To enable Certified Safe Software Service: on<br />

page 5-69.<br />

• Assess: Always allow processes associated with an event but record this<br />

action in the logs for assessment<br />

• Allow: Always allow processes associated with an event<br />

5-65

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!