Why 99% Attack Detection Rules Generate 99.9% False Positives in Real SOC Environments
A rule that catches 99% of attacks while erring on only 1% of normal events is routinely presented as a strong control during architecture reviews. The claim is rarely questioned because the numbers appear solid. Yet the arithmetic of rare events shows that almost every alert the rule generates will still be false—not because the rule is poorly written, but because genuine attacks are statistically rare.
The Base-Rate Problem in Numbers
Consider an organization that processes 200,000 logins per day, two of which represent real compromises. A rule advertised with 99% sensitivity and 1% false-positive rate produces:
- True positives: 2 × 0.99 = 1.98
- False positives: 199,998 × 0.01 = 2,000
- Total alerts: 2,002
- Precision: 0.10%
An analyst therefore faces roughly one thousand alerts for every genuine finding. The imbalance arises because the 1% error applied to the large population of normal events overwhelms the 99% hit rate applied to the tiny population of attacks.
Bayes' Theorem Formalizes the Outcome
Precision is expressed as:
Precision = (P × Se) / (P × Se + (1 − P) × FPR)
where P is the base rate of attacks, Se is sensitivity, and FPR is the false-positive rate on benign events. Because the numerator cannot exceed P, even perfect sensitivity cannot overcome a large denominator term driven by (1 − P) × FPR when attacks are rare.
What Actually Improves Precision
Raising sensitivity from 99% to 100% adds only 0.02 true positives while leaving 2,000 false positives untouched; precision remains 0.10%. Reducing the false-positive rate, however, produces immediate results:
- 1.00% FPR → 2,002 alerts, 0.10% precision
- 0.10% FPR → 202 alerts, 0.98% precision
- 0.01% FPR → 22 alerts, 9.01% precision
Lowering the false-positive rate by two orders of magnitude reduces daily workload from thousands of events to a manageable two dozen while preserving nearly all true detections.
Population Scoping and Cascaded Rules
Applying the same rule only to the 4,000 administrative and service-account logins (one of the two compromises) raises precision to 2.42% and cuts alerts to 41. The rule itself is unchanged; only its scope has been narrowed. A two-stage cascade achieves similar gains: a cheap broad filter followed by an expensive enrichment step on the remaining candidates can drop 98% of false positives while losing only 5% of true positives, yielding 94% overall sensitivity at 4.5% precision.
Operational Consequences and Recommended Metrics
Rules with 0.1% precision train analysts to close alerts without examination. Over time the rule is moved to low priority, then to reporting only, and finally disabled—coverage metrics still look perfect while actual detection has vanished. The article therefore advocates tracking two figures together: the absolute number of confirmed detections and the percentage of alerts that prove true. Reviewing quarterly tickets against these paired metrics quickly identifies rules that consume analyst attention without delivering value.
Related articles
macOS User Investigates Claude Regional Block via Logs and Restores Work Site Access with Targeted WireGuard Routes
A detailed case study describes how a macOS user analyzed Claude application logs after experiencing regional unavailability errors while using WireGuard VPN. The investigation covered ~/Library/Logs/Claude/ files containing markers like app-unavailable-in-region and region_unavailable, cross-referenced with tunnel activity dates from August to October 2026. No direct evidence linked the VPN to the account block, as tunnel logs were overwritten and system journals returned Operation not permitted errors. The user then addressed a secondary issue where WireGuard blocked access to work services including amoCRM, TGBooster, and Geekjob. Custom host routes were added via route add commands to direct specific IPv4 addresses through the local gateway while keeping Claude traffic in the tunnel. A launchd-based PF kill switch was tested for tunnel failure protection but caused a full internet outage on October 5 due to anchor and hook conflicts, leading to its rollback. By October 8, work sites functioned under VPN with verified routes, though persistent kill switch protection remained unresolved.
Publishing Internal APIs from DMZ Without Direct LAN Connections: Five Tested Architectures
When an API gateway resides in the DMZ but security policies forbid outbound connections into the LAN, organizations must adopt alternative patterns to expose internal services synchronously. The article examines five production-ready approaches built on the NEOMSA APIM platform, ranging from custom request-reply logic over Kafka to zero-code solutions using ActiveMQ Artemis and experimental reverse HTTP in HAProxy. Each pattern is evaluated against criteria such as the need for DMZ-to-LAN firewall rules, volume of custom code, support for streaming responses, and measured performance. Load tests on the Artemis-based bridge reached 50 requests per second with a 95th percentile latency of approximately 100 ms, while the Kafka implementation required roughly 2,500 lines of Java to emulate missing reply semantics. The analysis highlights trade-offs in operational complexity, vendor support implications, and security posture, particularly the benefit of preventing any outbound initiation from the DMZ.
FSB in Chelyabinsk Region Proposes QR-Code Passports for Tracking Construction Materials to Combat Theft
The regional branch of Russia's Federal Security Service in Chelyabinsk has suggested introducing an electronic tracking system for construction materials using unique QR codes assigned to each batch. The initiative aims to reduce theft and fraud during the construction of social facilities by creating a verifiable digital record of material movement from supplier to site. According to official representative Tatyana Sosnina, the system would allow real-time comparison between ordered quantities, project documentation, and actual usage on site. This approach is expected to help customers and oversight bodies quickly identify discrepancies between procurement records and physical consumption. The proposal does not yet include any announced timelines or estimated implementation costs. Experts note that the effectiveness of such QR-based tracking will ultimately depend on the accuracy of data entry at every stage of the supply chain rather than on the codes themselves.
Russian Internet Services Hit by Outages After Drone Attack on Yandex Data Center in Sasovo
On October 8, multiple Russian websites and internal corporate systems experienced significant disruptions. Users reported issues accessing media outlets, transport services, and marketplaces, with many problems affecting internal company tools and professional platforms. Cian linked its website and app outage to an infrastructure partner incident, while developers A101, Granel, and Brusnika also faced temporary unavailability. T-Bank reported problems with its corporate messenger and email distributions, and similar internal system issues appeared at Ozon, Wildberries, and HSE. Astral warned of possible delays in electronic reporting and document management services. Yandex confirmed a fire at its Sasovo data center in Ryazan region following a drone attack, with no casualties but full shutdown of the facility. Experts note that not all complaints can be attributed to a single event due to varying scales of impact across companies.