Alerts are correlated based on locally generated signatures. When multiple alerts with the same signature are found they are correlated into a batch with the name ‘Infection Match.’ This allows you to track the infection information.
Local signatures are generated for Web Infection and Malware Object. The system will correlate alerts based on the signature. If an alert arrives with a signature that is already identified, it is blocked and will display ‘Infection Match’ in the Type column. If the same infection happens again within the expiration time of the signature (24 hours after signature hit time), then the infection is matched with the locally generated signature. If the ADD Product Series is in inline mode, the infection is blocked.
The infection match will show local.infection or local.callback malware type and if you display the details it will have a link for the original alert. Click the Original Alert Info link and it will take you to the original alerts signature details.