In short: yes
The longer version is: To ensure we are able to scan traffic quickly it is efficient to kjeep the threat database small in size: To be able to provide the best possible coverage we investigate which signatures are active 'in the wild', which ones are dangerous and which ones are still relevant
If a vulnerability is widely patched, it is safe to assume the threat level becomes lower, and if the signature is not picked up in the wild much any more, that means the signature has become obsolete and it is safe to dselete from the repository,, thus ensuring only the important signatures are used to scan your traffic
... View more