Why 99% Attack Detection Rules Generate 99.9% False Positives in Real SOC Environments
A rule that catches 99% of attacks while erring on only 1% of normal events is routinely presented as a strong control during architecture reviews. The claim is rarely questioned because the numbers appear solid. Yet the arithmetic of rare events shows that almost every alert the rule generates will still be false—not because the rule is poorly written, but because genuine attacks are statistically rare.
The Base-Rate Problem in Numbers
Consider an organization that processes 200,000 logins per day, two of which represent real compromises. A rule advertised with 99% sensitivity and 1% false-positive rate produces:
- True positives: 2 × 0.99 = 1.98
- False positives: 199,998 × 0.01 = 2,000
- Total alerts: 2,002
- Precision: 0.10%
An analyst therefore faces roughly one thousand alerts for every genuine finding. The imbalance arises because the 1% error applied to the large population of normal events overwhelms the 99% hit rate applied to the tiny population of attacks.
Bayes' Theorem Formalizes the Outcome
Precision is expressed as:
Precision = (P × Se) / (P × Se + (1 − P) × FPR)
where P is the base rate of attacks, Se is sensitivity, and FPR is the false-positive rate on benign events. Because the numerator cannot exceed P, even perfect sensitivity cannot overcome a large denominator term driven by (1 − P) × FPR when attacks are rare.
What Actually Improves Precision
Raising sensitivity from 99% to 100% adds only 0.02 true positives while leaving 2,000 false positives untouched; precision remains 0.10%. Reducing the false-positive rate, however, produces immediate results:
- 1.00% FPR → 2,002 alerts, 0.10% precision
- 0.10% FPR → 202 alerts, 0.98% precision
- 0.01% FPR → 22 alerts, 9.01% precision
Lowering the false-positive rate by two orders of magnitude reduces daily workload from thousands of events to a manageable two dozen while preserving nearly all true detections.
Population Scoping and Cascaded Rules
Applying the same rule only to the 4,000 administrative and service-account logins (one of the two compromises) raises precision to 2.42% and cuts alerts to 41. The rule itself is unchanged; only its scope has been narrowed. A two-stage cascade achieves similar gains: a cheap broad filter followed by an expensive enrichment step on the remaining candidates can drop 98% of false positives while losing only 5% of true positives, yielding 94% overall sensitivity at 4.5% precision.
Operational Consequences and Recommended Metrics
Rules with 0.1% precision train analysts to close alerts without examination. Over time the rule is moved to low priority, then to reporting only, and finally disabled—coverage metrics still look perfect while actual detection has vanished. The article therefore advocates tracking two figures together: the absolute number of confirmed detections and the percentage of alerts that prove true. Reviewing quarterly tickets against these paired metrics quickly identifies rules that consume analyst attention without delivering value.
Related articles
Teenage Smartphone Addiction: Causes, Consequences, and Treatment Approaches
Smartphone use has become an integral part of adolescent life, but problematic usage patterns rather than device ownership itself are the focus of concern. Medical experts avoid the term smartphone addiction and instead address issues like disrupted self-control, social media overuse, and gaming disorder that interfere with sleep, studies, relationships, and mental health. Data from Pew Research indicates nearly 50% of U.S. teens aged 13-17 are online almost constantly, while CDC findings link four or more hours of daily screen time to elevated anxiety and depression symptoms. Family digital habits strongly influence teen behavior, and rigid bans often fail without addressing underlying issues such as boredom, anxiety, or social isolation. Parents are advised to track specific disruptions over a week and consider professional help when signs of depression, bullying, or self-harm appear alongside device overuse.
VK WorkSpace Federation Enables Secure Multi-Organization On-Premise Messaging Without Infrastructure Merge
VK Tech has released federation capabilities for its VK WorkSpace corporate messenger that connect independent On-Premise installations while preserving each organization's full control over data, administration, and security policies. The feature, first piloted in November 2025 and expanded in the July 2026 26.2 release, supports multi-party chats across more than two separate environments. Federation relies on mutual trust establishment and per-user access grants rather than full directory replication or proxy access to a single host instance. Each participating organization maintains local copies of messages, files, and chat metadata, allowing continued access even if a partner installation becomes unavailable. The architecture deliberately avoids both centralized hosting and open protocols such as Matrix to keep changes to the existing messenger core minimal. Administrators retain independent levers to create or revoke trusts and to limit which employees may communicate externally.
Sergey Volkov of Cloud.ru Named Top CISO in Russian IT Sector Ranking
Sergey Volkov, Director of the Cyber Protection Center at Cloud.ru, has secured first place in the information security category of the annual Top-1000 Russian Managers ranking. The ranking, published by the Association of Managers in the Kommersant newspaper since 2001, is compiled through peer evaluations by top executives followed by review from expert commissions. Volkov oversees information security strategy and operations for Cloud.ru, and his top position reflects professional recognition of his leadership results. The Association also analyzed broader achievements among laureates and identified key trends in Russian management. Artificial intelligence adoption for business process optimization appeared in 80 percent of reviewed accomplishments. Client orientation through user experience analysis and personalized solutions ranked second, while operational efficiency via cost reduction, automation, and digitalization took third place.
Russia Hands Down First Conviction Under New Criminal Article for Online Drug Propaganda
A resident of Orenburg became the first person in Russia to receive a criminal sentence under Article 230.3 of the Criminal Code, which criminalizes online drug propaganda following repeated administrative violations. The man was fined 100,000 rubles and had his mobile phone confiscated after he printed and posted leaflets containing a QR code that directed users to job advertisements linked to drug distribution. The scheme began when he was recruited via messenger to place the leaflets for 10 rubles each, without realizing the content involved narcotics-related vacancies. Prior to this case, the individual had already been sanctioned twice within the same year for illegal drug advertising, allowing prosecutors to escalate the matter to the new criminal provision that took effect on 1 March. The court considered his prior record as a recidivism aggravating factor yet imposed the minimum fine after he admitted guilt, expressed remorse, and cooperated with investigators. The ruling has already entered into force, marking the initial application of the statute that permits penalties up to two years of imprisonment or fines between 100,000 and 300,000 rubles.