๐ด
False positive: legitimate activity flagged as malicious. Causes alert fatigue.
๐ต
False negative: malicious activity not detected. More dangerous โ missed attack.
Tuning IDS/IPS reduces false positives. Too sensitive = false positives. Too lenient = false negatives. Both are bad โ balance is key. False negatives are more dangerous (undetected attacks).