Hi experts,
I need some documents about the reasons for classification of confidence level of Anti-Virus blade and IPS blade under our firewall threat prevention policy.
I have read sk116254 but most of the information is about reasons for classification of security levels.
To better understand what I need, I've made a list of three tiers of questions, with the answer to the third question is what I want to know.
For example if there is a file through the firewall with low severity and low confidence, I want to know
1. How this file is diagnosed as low severity.
2. How this file is diagnosed as low confidence.
3. How does the Check Point determine that this file is produce false positive events in high/medium/low probability.
The SK can only answer me first two questions. I need to know the third one. How it judgement? By our experience? What is the basis of the analysis through our experience, or the chance of a previous miscarriage of justice, or a certain pattern to analyze?
Look forward to your answer. Thanks in advance.