in Cyber Security by
What is the difference between a false positive and a false negative in IDS?

1 Answer

0 votes
by

A false positive is considered to be a false alarm and a false negative is considered to be the most complicated state.

A false positive occurs when an IDS fires an alarm for legitimate network activity.

A false negative occurs when IDS fails to identify malicious network traffic.

Compared to both, a false positive is more acceptable than a false negative as they lead to intrusions without getting noticed.

...