An intrusion in CFP3 turns out to be anything that is blocked and logged. There are some applications that seem to create a lot of traffic that is blocked and logged by default as being suspicious-mostly for unknown programs. Check your firewall log to see what is listed there. If all is working with the blocks, create an explicit rule to block but not log the same items for the same application(s) and the intrusions should go away. You can also reset the counter by turning CFP3 off and then back on.
