- CheckMates
- :
- Non-English Discussions
- :
- Chinese 中文
- :
- 有關IPS/Threat Prevention政策設計的優化與避免誤判方式
Options
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×
Sign in with your Check Point UserCenter/PartnerMap account to access more great content and get a chance to win some Apple AirPods! If you don't have an account, create one now for free!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
有關IPS/Threat Prevention政策設計的優化與避免誤判方式
Hello All,
如同今天CCSE Training中松倫所提到的,在IPS或Threat Prevention的Log/Event中可能會遇到Severity為High/Critical,但Confidence為Low的情況,對於客戶而言是否需要特別關注或調整安全政策?
基本上各位需要先了解Severity/Performance impact/Confidence這三者的定義,才能進一步跟客戶說明並進行policy tuning
附件檔案內有明確說明上述分類的差異,同時也請參考先前上傳過的R80.10 IPS Best Practice Guide
Cheers,
Danny
0 Replies
