Hello,
may I ask an expert from Fortinet to explain in detail how the "Intelligent analysis" feature works? Admin guide is rather vague. I have just created my first WA test profile. I have kept the Intelligent analysis value at default 50. Now it has been 2 hours and already 2 legitimate messages got classified as:
Identified by BEC-Weighted Analysis: Intelligent analysis, score: 50
I see no valid issues with messages. So far it looks like it creates false positives, exactly the opposite of what Admin guide states.
Thanks,
Petr
Hello Petr,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
Hello,
We are still looking for an answer to your question.
We will come back to you ASAP.
Thanks,
To address the issue of false positives in your weighted analysis profile, you can take the following steps:
Hello Jean-Phillipe,
thanks for the explanation. However, I was hoping for less generic answer. I have e-mails looking like legitimate ones. For example I am sending myself test e-mail from Gmail. SPF, DKIM, DMARC are all correct, yet the Intelligent analysis triggers for a reason I do not understand.
How can this be troubleshooted?
Petr
Hello Jean-Phillipe,
after a month of testing, there are multiple negative results:
1. Intelligent analysis behaviour is still a mystery, no change
2. Sender-recipient relation does not work as I would expect. For example - first time sender sending obvious spam is evaluated as SRR strength: neutral(7). After analysing thousands of SRR:weak evaluations I can make a conclusion that this alone cannot differentiate between wanted and unwanted senders, making much more false positives than true positives.
In addition, after looking for information, it looks like SRR is a cloud based feature, working at Fortiguard level. I would expect that it would analyse based on our own sent e-mails and calculating SRR strengths, but apparently it works in a different way.
So far these features, which I expected would help with spam/scam/phishing, do not help us at all.
Thanks,
Petr
User | Count |
---|---|
2534 | |
1351 | |
795 | |
641 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.