New in 2025.3: Reducing false positives with Machine Learning

  • March 3, 2025
  • 2 min read

False positives have long been a challenge in behavioral malware detection. Monitoring the processes on a computer for malicious intent can sometimes result in mistaking legitimate software—such as software updates or unsigned applications—for malware, leading to unnecessary alerts and interruptions.
To address this, Emsisoft has integrated a machine learning model into our behavior blocker (BB) to significantly reduce false positives while maintaining a 0% false negative rate. This ensures fewer false alarms without compromising security.

Unlike traditional signature-based detection, behavioral malware detection monitors system activity in real time, identifying threats based on how they act rather than how they look. This approach is highly effective at catching new and evolving malware, but it also comes with challenges. Some legitimate software, particularly those that modify system files during installation or updates, can appear suspicious to behavior blockers. To avoid missing real threats, security software often errs on the side of caution, flagging these programs as potential risks.

Over time, we have introduced multiple layers to continually improve the effectiveness of our behavior blocker. Now, with the addition of machine learning, we’re taking false-positive reduction to the next level.

With this enhancement, Emsisoft users will experience:

This machine learning model serves as an intelligent filter within our behavior blocker, complementing existing false-positive reduction layers. By combining AI-driven insights with Emsisoft’s proven security technologies, we’re delivering smarter, more precise malware protection.

Device protection (desktop)

Management console (web app)

How to obtain the new version

So long as you have auto-updates enabled, you will receive the latest version automatically during your regularly scheduled updates.

Note to Enterprise users: If you have chosen to receive “Delayed” updates, client systems will receive the new version no earlier than 30 days after the regular “Stable” availability.

Emsisoft Enterprise Security + EDR

Robust and proven endpoint security solution for organizations of all sizes. Start free trial

Have a great and well-protected day!

Emsi

Emsi

Emsisoft founder and managing director. In 1998 when I was 16, a so called 'friend' sent me a file via ICQ that unexpectedly opened my CD-ROM drive, which gave me a big scare. It marked the start of my journey to fight trojans and other malware. My story

What to read next