Malware

False negative

False negative is a scan that says a page is clean when it holds malware. The tool missed it, and you were told everything is fine.

How it is measured

You only learn about false negatives afterward: a customer report, a search warning, or a second scanner flagging the same file. To estimate the rate, seed known-bad samples into a test site and count how many the scanner misses.

Track it as missed over total known bad. If a test pack of 50 injected pages gets 41 flagged, the miss rate is 9 of 50.

Worked example

A site owner runs a free scanner on Monday and gets green. On Thursday a customer reports a redirect on their phone. The injected script only fires for mobile visitors arriving from Google, so the scanner, which fetched once from a datacenter with no referer, never saw it.

A second scan with a mobile user agent and a search referer shows the redirect immediately.

How it differs

A false negative is a miss: bad code, no alarm. A false positive is the opposite error: good code, alarm raised. Tuning a scanner to remove one usually makes the other worse. The Tarsier Threat Index reduces misses on known hostile hosts, but it cannot catch a payload from a host nobody has reported.

Common errors

Treating a clean scan as a certificate. Running one scan from one place. Never testing the scanner with known-bad samples. Trusting a scan result for a page that serves different content to crawlers. Skipping manual review after an alert elsewhere.

In practice

Do not stop at one green result. Re-check from a phone user agent with a search referer, review modified files, and read logs. Keep a few harmless test samples to confirm your scanner still catches them.

See also

False positive, Tarsier Threat Index

Sources

Count this on a real site.

Watch my website