Product guide
Updating Detection Definitions
VirusScan Enterprise software depends on the scanning engine and the information in the
detection definition (DAT) files to identify and take action on threats. New threats appear on a
regular basis. To meet this challenge, McAfee releases new DAT files every day, incorporating
the results of its ongoing research. The update task retrieves the most current DAT files,
EXTRA.DAT file, scanning engine, Service Packs, and Patches.
Contents
How an update strategy is determined
Update tasks and how they work
Mirror tasks and how they work
How the AutoUpdate repository works
How rolling back DAT files works
How an update strategy is determined
Updates can be accomplished using many methods. You can use update tasks, manual updates,
login scripts, or schedule updates with management tools. This section describes using the
update task. Any other methods are beyond the scope of this guide.
An efficient updating strategy generally requires that at least one client or server in your
organization retrieve updates from the McAfee download site. From there, the files can be
replicated throughout your organization, providing access for all other computers. Ideally, you
should minimize the amount of data transferred across your network by automating the process
of copying the updated files to your share sites.
The main factors to consider for efficient updating are the number of clients and the number
of sites. You might also consider the number of systems at each remote site and how remote
sites access the Internet. However, the basic concepts of using a central repository to retrieve
updates and scheduling update tasks to keep your environment up-to-date apply to any size
organization.
Using an update task allows you to:
• Schedule network-wide DAT file rollouts at convenient times and with minimal intervention
from either administrators or network users. You might, for example, stagger your update
tasks, or set a schedule that phases in, or rotates, DAT file updates to different parts of the
network.
• Split duties for rollout administration among different servers or domain controllers, among
different regions of wide-area networks, or across other network divisions. Keeping update
traffic primarily internal can also reduce the potential for network security breaches.
• Reduce the waiting time required to download new DAT or upgraded engine files. Traffic
on McAfee computers increases dramatically on regular DAT file publishing dates and
23McAfee VirusScan Enterprise 8.7i