This resolution KB article addresses the issue of high RE CPU utilization, exceeding 90% when attaching the recommended or Client-Protection predefined IDP attack group to a security policy.
The “recommended” predefined attack group is resource-intensive compared to other attack groups and also the “Client-Protection” group, which is designed for devices with at least 2 GB of memory. However, even if a device has 2 GB of control plane memory, other processes may also consume significant resources, leading to high CPU utilization.
As a solution, customers can opt for the 'Critical' attack group or the lighter 'Client-Protection-1g' attack group, both of which are optimized for lower memory usage and include all critical attack signatures for client protection.