The threat-intelligence ip-confidence-threshold command sets the confidence threshold for triggering IPS threat intelligence linkage.
The undo threat-intelligence ip-confidence-threshold command restores the confidence threshold to the default value.
threat-intelligence ip-confidence-threshold ip-confidence-threshold
undo threat-intelligence ip-confidence-threshold
| Parameter | Description | Value |
|---|---|---|
ip-confidence-threshold |
Specifies the confidence threshold for triggering IPS threat intelligence linkage. A larger value indicates more reliable threat intelligence. |
The value is an integer in the range from 1 to 100. |
By default, the confidence threshold for triggering IPS threat intelligence linkage is 80.
In the threat intelligence linkage scenario, the threat intelligence query module extracts the source IP address of a threat event and sends it to the threat intelligence query server to query threat event intelligence. If the obtained threat event risk level and intelligence confidence reach the preset linkage triggering threshold, the device changes the threat event processing action from alert to block, improving the blocking rate of the IPS service against high-risk threats.