Malware

False positive

False positive is a scan that flags a good script, file, or host as malicious. The alarm is wrong, and acting on it costs time or breaks something.

How it is measured

Confirm by checking the source. Read the file, compare it against the vendor's official copy by hash, and see who owns the host. If the hash matches the upstream release and the host belongs to the vendor, the flag is wrong.

Track the rate as wrong alerts over total alerts. If a scanner raised 30 alerts this month and 11 were cleared, the false positive rate is 11 of 30.

Worked example

A scanner flags `assets/js/vendor.min.js` on a bookshop as obfuscated malware because it contains long unreadable lines. The owner downloads the same version of the library from its official release page, hashes both, and the SHA-256 values match.

The file is a minified build, not a threat. The owner marks it as reviewed with the version and hash noted.

How it differs

A false positive is a good thing called bad. A false negative is a bad thing called good. Suppressing noisy rules cuts false positives but widens the gap for misses. A false positive in Hack Check can come from a legitimate analytics script that matches a pattern, which is why the Tarsier Threat Index is a list of known hostile hosts rather than a list of suspicious-looking code.

Common errors

Deleting a plugin file because of a flag without checking its hash. Whitelisting a whole folder after one false alarm. Ignoring all alerts after a few false ones. Treating minified code as obfuscation. Failing to record why something was cleared.

In practice

When a flag looks wrong, verify with a hash from the official source and record the result. Keep a short list of cleared items with their version. Do not mute the rule globally; narrow the exception to the exact file.

See also

False negative, Tarsier Threat Index

Sources

Count this on a real site.

Watch my website