- CheckMates
- :
- Products
- :
- General Topics
- :
- Re: Best way to alert Checkpoint of probable FPs?
Options
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×
Sign in with your Check Point UserCenter/PartnerMap account to access more great content and get a chance to win some Apple AirPods! If you don't have an account, create one now for free!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Best way to alert Checkpoint of probable FPs?
Hello,
Checkpoint IPS has recently (09-08-2018) started erroneously tagging many domains ending in akamaiedge.net as malicious (Phishing_website.upvi) which is creating very large amounts of FP alerts. Here are some examples:
e11696.dscg.akamaiedge.net
e16595.dsca.akamaiedge.net
e912.f.akamaiedge.net
e6640.g.akamaiedge.net
.. etc
Hopefully someone at Checkpoint reviews this post and fixes the issue ASAP. Thanks!
4 Replies
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
A TAC case is always your best bet in the case of a false positive.
I'll see what I can find out from our Threat Operations team, though.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I also encountered a similar problem (09-sept-2018 - 10-sept-2018).
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The false positive should have already been addressed by now, assuming you have installed the latest IPS signatures.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Problem is solved:)
