Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
pne
New Contributor II

Fortimail weighted analysis - Intelligent analysis

Hello,

 

may I ask an expert from Fortinet to explain in detail how the "Intelligent analysis" feature works? Admin guide is rather vague. I have just created my first WA test profile. I have kept the Intelligent analysis value at default 50. Now it has been 2 hours and already 2 legitimate messages got classified as:

 

Identified by BEC-Weighted Analysis: Intelligent analysis, score: 50

 

I see no valid issues with messages. So far it looks like it creates false positives, exactly the opposite of what Admin guide states.

 

Thanks,

Petr

5 REPLIES 5
Jean-Philippe_P
Moderator
Moderator

Hello Petr, 

 

Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible. 

 

Thanks, 

Jean-Philippe - Fortinet Community Team
Jean-Philippe_P
Moderator
Moderator

Hello,

 

We are still looking for an answer to your question.

 

We will come back to you ASAP.

 

Thanks,

Jean-Philippe - Fortinet Community Team
Jean-Philippe_P
Moderator
Moderator

To address the issue of false positives in your weighted analysis profile, you can take the following steps:

 

  1. Review the Intelligent Analysis Configuration: Ensure that the intelligent analysis settings are correctly configured. Check the factors contributing to the analysis, such as SPF, DKIM, DMARC, and header analysis.

  2. Adjust the Score Weight: Consider lowering the score weight for intelligent analysis if it is causing false positives. This can help reduce the likelihood of legitimate emails being flagged.

  3. Examine Specific Factors: Investigate which specific factors (e.g., SPF, DKIM) might be contributing to the false positives. Ensure that these factors are correctly set up for your legitimate senders.

  4. Whitelist Legitimate Senders:
    If certain senders are consistently flagged, consider adding them to a whitelist to prevent their emails from being marked as spam.

  5. Monitor and Adjust: Continue to monitor the performance of the weighted analysis profile and make further adjustments as needed based on the results. By following these steps, you should be able to reduce the occurrence of false positives in your weighted analysis profile.
Jean-Philippe - Fortinet Community Team
pne
New Contributor II

Hello Jean-Phillipe,

 

thanks for the explanation. However, I was hoping for less generic answer. I have e-mails looking like legitimate ones. For example I am sending myself test e-mail from Gmail. SPF, DKIM, DMARC are all correct, yet the Intelligent analysis triggers for a reason I do not understand.

 

How can this be troubleshooted?

 

Petr

pne
New Contributor II

Hello Jean-Phillipe,

 

after a month of testing, there are multiple negative results:

 

1. Intelligent analysis behaviour is still a mystery, no change

2. Sender-recipient relation does not work as I would expect. For example - first time sender sending obvious spam is evaluated as SRR strength: neutral(7). After analysing thousands of SRR:weak evaluations I can make a conclusion that this alone cannot differentiate between wanted and unwanted senders, making much more false positives than true positives.
In addition, after looking for information, it looks like SRR is a cloud based feature, working at Fortiguard level. I would expect that it would analyse based on our own sent e-mails and calculating SRR strengths, but apparently it works in a different way.

So far these features, which I expected would help with spam/scam/phishing, do not help us at all.

 

Thanks,

Petr

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors