CPC H04L 63/0263 (2013.01) [G06N 5/022 (2013.01); G06N 20/20 (2019.01); H04L 41/14 (2013.01); H04L 41/16 (2013.01); H04L 41/5009 (2013.01); H04L 43/0811 (2013.01); H04L 43/0888 (2013.01); H04L 63/0236 (2013.01); H04L 63/0245 (2013.01); H04L 63/1416 (2013.01)] | 20 Claims |
16. A network system comprising:
processing circuitry; and
one or more memories coupled to the processing circuitry and configured to store instructions which, when executed by the processing circuitry, cause the network system to:
receive connection data related to an egress connection of an application service of an application;
send, to a computing device, the connection data;
receive, from the computing device and in response to sending the connection data, a notification indicative of the egress connection being an anomalous connection;
generate, based on the notification indicative of the egress connection being anomalous, a notification to apply a firewall policy of a distributed firewall to at least one network interface card (NIC) of a plurality of NICs implementing the distributed firewall; and
send the notification to apply the firewall policy to the at least one NIC.
|