Skip to main content
MB_arr
Staff
Staff
February 21, 2026

Technical Tip: Understanding threat weight vs. threat score in FortiWeb HTTP protocol constraints

  • February 21, 2026
  • 0 replies
  • 208 views
Description This article clarifies the distinction between Threat Weight and Threat Score in FortiWeb HTTP Protocol Constraints. Setting the Threat Weight to the minimum value does not control threat score calculation. Threat scoring is determined by constraint enforcement and action configuration. This distinction is important when tuning Client Management to avoid unintended Suspicious or Malicious classifications.
Scope FortiWeb.
Solution

 

  1. Threat weight behavior.

 

Threat Weight affects log severity only. It determines the severity level displayed in the Attack log (critical, severe, substantial, moderate, low, and informative). It does not influence Threat Score calculation. The screenshot below shows the Threat Weight set to the lowest, and the severity displayed as Informational.

 

THREAT WEIGHT 1.jpg

 

Threat weight set to severe severity:

The example below shows Threat Weight configured to a higher level and severity displayed as Severe.

 

THREAT WEIGHT_2.jpg

 

 

  1. Threat Score Behavior.

 

If the constraint Action is configured as Alert and Deny, FortiWeb:

  1. Records the violation in the Attack Log.
  2. Increments Threat Score.

 

Threat Score increment example:

 THREAT WEIGHT_3.jpg

 

THREAT WEIGHT_4.jpg

 

 

  1. Preventing threat score increments:
Threat scoring is prevented only when one of the following is applied:

 

  1. The specific HTTP Protocol Constraint is disabled.
  2. An HTTP Constraint Exception is configured to exempt trusted traffic.

An example is shown in the screenshots below.

 

Boday_parameter_disable.jpg  EXCEPTION.jpg

 

Conclusion:

Threat Weight and Threat Score serve distinct functions in FortiWeb. Threat Weight affects only the severity displayed in logs, while Threat Score increments whenever an enabled protocol constraint is violated. Preventing a constraint from contributing to Threat Score requires disabling the constraint or applying an exception.

 

Related document: