Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Gabriel_Leega
New Contributor II

Diagnosis of alerts and false positives

Hello everyone, I'm facing some security alerts in the software (here I would put the site's name) flagged on the website www.virus.total.com and would like to understand better how to distinguish between legitimate 'alerts' and 'false positives'.

Could someone explain to me what criteria are used to determine if an alert is genuine or if it might be a false positive?

Also, what are the best practices for handling these alerts without compromising the security of my system, and what are the direct channels for contacting for clarification, alert removal, or for engaging services related to this issue?

Thank you for your help!

1 Solution
Gabriel_Leega

Hi Saleha,

Thank you for your response and guidance. I will proceed with the request.

Best regards.

View solution in original post

4 REPLIES 4
saleha
Staff
Staff

Hi Gabriel_Leega,

 

Thank you for reaching out. It depends on what security UTM did the url get flagged for. I checked the url www.virus.total.com on Fortiguard webfiltering service and can see the category is business therefore I assume traffic was flagged by a different match:

https://www.fortiguard.com/webfilter

 

You can share the security log that matched your traffic if you find it in "Intrusion Prevention", "Application Control", SSL, Anti-Virus or other Security logs by going to "Log&Report>Security Events":
https://docs.fortinet.com/document/fortigate/7.4.4/administration-guide/876272

 

Thank you,

saleha

Gabriel_Leega

Saleha,

Thank you for your response and feedback.

Our URL www.sts.snt-mkt-automation.com has been flagged on the site www.virus.total.com.

Could you please analyze this?

Best regards.

Gabriel

saleha
Staff
Staff

Hi Gabriel,

Thank you for the reply. The url "www.sts.snt-mkt-automation.com" is listed under "Phishing" category which means the rating service have found that your website is duplicating a legitimate website with the purpose of eliciting financial, personal or other private information from the users. If this website is considered legitimate business website I recommend submitting a request to change the category for this url on the "www.virus.total.com" website. You can do the same on "fortiguard.com":
https://www.fortiguard.com/faq/wfratingsubmit

 

Thank you,

saleha

Gabriel_Leega

Hi Saleha,

Thank you for your response and guidance. I will proceed with the request.

Best regards.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors