I do not need a solution (just sharing information)
Most browser based IPS detections comes from iframes within legit sites. SEP only logs the url of the iframe.
SEP should also log the root website.
Eg. If a user visites forbes.com that host adware through an iframe, SEP will log the source as infectedadsite.com and never leave any trace that the malicious site to be checked is actually forbes.com.
SEP should log both sites. E.g "infectedadsite.com blocked while visiting forbes.com"
Please vote for this idea at:
https://www.symantec.com/connect/ideas/ability-see...
0