True Positive / False Positive
Definition
A true positive is an alert that correctly identifies malicious activity. A false positive is an alert that fires on legitimate traffic. Alert triage aims to resolve which category each alert belongs to before any investigative resources are committed.
- True positive
- Alert correctly identifies malicious activity
- False positive
- Alert fires on legitimate traffic
- Process stage
- Alert triage
- Goal
- Classify each alert before committing investigative resources
Common questions
Why is triaging true versus false positives placed before deeper investigation?+
Investigative resources are limited, and chasing every alert as if confirmed would exhaust an analyst's time on noise. Triage sorts alerts by confidence first so effort goes to activity most likely to be genuinely malicious.
What happens when a false positive rate is chronically high?+
Analysts become desensitised and start dismissing alerts faster, which raises the risk of missing a genuine true positive buried in the noise, sometimes called alert fatigue. Tuning detection rules to reduce false positives is a standing operational task.
Related terms
- Anomaly-Based IDS
- An intrusion detection system that models normal traffic behaviour and alerts when observed traffic deviates significantly from that baseline. Detects novel attacks...
- Five-Tuple
- The five fields that uniquely identify a network flow: source IP address, source port, destination IP address, destination port, and transport protocol...
- Lateral Movement
- Attacker activity after initial compromise in which the threat actor traverses from one internal system to another, typically to escalate privileges, access...
- Proxy Log
- A record generated by a forward proxy server for each HTTP or HTTPS request made by an internal client. Contains the URL,...
- Signature-Based IDS
- An intrusion detection system that compares network traffic against a database of known attack patterns (signatures). Snort and Suricata are the dominant...