I have no idea
but the sigs may be applied to the deeply inspected packets, for one option. I haven't read up on how any particular vendor's device is supposed to operate.
AVs, not matter where implemented, are like slightly leaky dykes. Good enough most of the time, but occasionally someone gets flooded a little.