<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IPS false positives/negative in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-false-positives-negative/m-p/120267#M17018</link>
    <description>&lt;P&gt;How can we prevent false positives and false negatives from occurring? We are usually creating exceptions but that is the reactive measure. Can anyone help me understand the preventive measure here?&lt;/P&gt;&lt;P&gt;What are the configuration and steps required here?&lt;/P&gt;&lt;P&gt;Thanks in advance &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 03 Jun 2021 08:13:02 GMT</pubDate>
    <dc:creator>praveshnayal</dc:creator>
    <dc:date>2021-06-03T08:13:02Z</dc:date>
    <item>
      <title>IPS false positives/negative</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-false-positives-negative/m-p/120267#M17018</link>
      <description>&lt;P&gt;How can we prevent false positives and false negatives from occurring? We are usually creating exceptions but that is the reactive measure. Can anyone help me understand the preventive measure here?&lt;/P&gt;&lt;P&gt;What are the configuration and steps required here?&lt;/P&gt;&lt;P&gt;Thanks in advance &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jun 2021 08:13:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-false-positives-negative/m-p/120267#M17018</guid>
      <dc:creator>praveshnayal</dc:creator>
      <dc:date>2021-06-03T08:13:02Z</dc:date>
    </item>
    <item>
      <title>Re: IPS false positives/negative</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-false-positives-negative/m-p/120275#M17019</link>
      <description>&lt;P&gt;This is the sad truth of all the wonderful Security Tooling we have: False Positives and False Negatives, due to the dynamic threat landscape, it is a continuous process of evaluating logs and act accordingly.&lt;/P&gt;&lt;P&gt;From my own experience: implement the best-practice policy (for CP is the Optimized) and use a period to monitor the alerts on a daily basis that are generated (Prevent and Detect) and use Exception as narrow as possible (specific scope and protections). After sometime the monitoring less false positives will occur. Also implement like a recurrent NGFW review to see which exceptions are not hit anymore.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jun 2021 10:31:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-false-positives-negative/m-p/120275#M17019</guid>
      <dc:creator>kitetsu89</dc:creator>
      <dc:date>2021-06-03T10:31:17Z</dc:date>
    </item>
    <item>
      <title>Re: IPS false positives/negative</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-false-positives-negative/m-p/120316#M17043</link>
      <description>&lt;P&gt;This is one of the goals of Infinity Threat Prevention (available from R81): threat prevention with minimal tuning required.&lt;BR /&gt;That said, false positives do occur and, unfortunately, have to be handled in a reactive manner.&lt;BR /&gt;False negatives generally mean existing protections and/or protection mechanisms need to be improved.&lt;BR /&gt;Appropriate segmentation and access policies go a long way here.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jun 2021 21:40:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-false-positives-negative/m-p/120316#M17043</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-06-03T21:40:19Z</dc:date>
    </item>
  </channel>
</rss>

