I have observed a lot of confusion being generated with these terms. I tried to simplify this but every time I see them from a different perspective they confuse me.
I have made this chart based on the understanding I have acquired till now and tried to make it easy to understand. I hope this is the correct information. (Let me know if I got anything wrong and I will correct it.)
- Positive means Alert was generated.
- Negative means Alert was not generated.
- True is good. When true, the alert is correct in identifying the issue.
- False is bad. When false, the alert is incorrect in identifying the issue.
So, to summarize
"False Positive" --> positive in the name = alert generated, but falsefully. (for genuine traffic)
"False Negative" --> negative in the name = alert not generated, but falsefully. (for malicious traffic)