Understanding these concepts is crucial for accurate threat detection and response as it helps to evaluate and improve the accuracy of security measures, ensuring they are reliable and effective at detecting and mitigating threats without causing unnecessary alerts or missing real threats.
- True Positive (TP)
This is an event where a legitimate security threat, vulnerability or malicious activity is correctly identified by the security system.
- False Positive (FP)
This occurs when a benign activity, vulnerability, is incorrectly identified as malicious by the security system.
- True Negative (TN)
This occurs when a benign activity, vulnerability, is correctly identified as non-malicious by the security system.
- False Negative (FN)
This happens when a security threat, vulnerability or malicious activity is not detected by the security system, allowing it to go unnoticed.
Outcome | Threat Present | Threat Absent |
---|---|---|
Detected | True Positive (TP) | False Positive (FP) |
Not Detected | False Negative (FN) | True Negative (TN) |