4.2.4 Enable AI /heuristic based malware detection

Information

AI /heuristic based detection should be enabled.

Rationale:

The AV Engine AI malware detection model integrates into regular AV scanning to help detect potentially malicious Windows Portable Executables (PEs) in order to mitigate zero-day attacks. It is an additional layer of protection on top of traditional antivirus protection.

In version 6.x, it is named 'Heuristic detection'. On version 7.x, Fortinet has renamed this to AI based detection.

Solution

On CLI:

FGT1 # config antivirus settings
FGT1 (settings) # set machine-learning-detection enable

Default Value:

Enabled.

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-4, CSCv7|8.1, CSCv7|8.2, CSCv7|8.3

Plugin: FortiGate

Control ID: 997b61700925292c538a6bad940377c200b0ba5cace2ea92a578996d45f4c76c