| CPC H04L 63/0263 (2013.01) [G06N 5/022 (2013.01); G06N 20/20 (2019.01); H04L 41/14 (2013.01); H04L 41/16 (2013.01); H04L 41/5009 (2013.01); H04L 43/0811 (2013.01); H04L 43/0888 (2013.01); H04L 63/0236 (2013.01); H04L 63/0245 (2013.01); H04L 63/1416 (2013.01)] | 20 Claims |

|
1. A network system comprising:
processing circuitry;
one or more memories coupled to the processing circuitry and configured to store instructions which, when executed by the processing circuitry, cause the network system to:
obtain telemetry data, the telemetry data being associated with a plurality of applications running on a plurality of hosts;
based on the telemetry data, determine which applications of the plurality of applications run on a first host of the plurality of hosts, the determined applications comprising a subset of applications of the plurality of applications;
determine which firewall policies of a plurality of firewall polices apply to the subset of applications, the determined firewall policies comprising a subset of firewall policies of the plurality of firewall policies, each of the subset of firewall policies applying to at least one respective application of the subset of applications;
generate an indication identifying the subset of firewall policies; and
send the indication to a management plane of a distributed firewall.
|