INTELLIGENT FIREWALL FLOW CREATOR
Example systems, methods, and storage media are described. An example network system includes processing circuitry and one or more memories coupled to the processing circuitry. The one or more memories are configured to store instructions which, when executed by the processing circuitry, cause the network system to obtain telemetry data, the telemetry data comprising indications of creations of instances of a flow. The instructions cause the network system to, based on the indications of the creations of the instances of the flow, determine a pattern of creation of the instances of the flow. The instructions cause the network system to, based on the pattern of creation of the instances of the flow, generate an action entry in a policy table for a particular instance of the flow prior to receiving a first packet of the particular instance of the flow.
1 . A network system comprising:
processing circuitry; and
one or more memories coupled to the processing circuitry and configured to store instructions which, when executed by the processing circuitry, cause the network system to:
obtain telemetry data, the telemetry data comprising indications of creations of instances of a flow;
based on the indications of the creations of the instances of the flow, determine a pattern of creation of the instances of the flow; and
based on the pattern of creation of the instances of the flow, generate an action entry in a policy table for a particular instance of the flow prior to receiving a first packet of the particular instance of the flow.
2 . The network system of claim 1 , wherein the creation of the instances of the flow occurs prior to the creation of the particular instance of the flow.
3 . The network system of claim 1 , wherein as part of determining the pattern of creation of the instances of the flow, the instructions cause the network system to execute a machine learning model.
4 . The network system of claim 1 , wherein as part of the generating the action entry, the instructions cause the network system to execute a machine learning model.
5 . The network system of claim 4 , wherein the machine learning model is an unsupervised machine learning model.
6 . The network system of claim 4 , wherein the machine learning model is trained using respective indications of a plurality of creations of instances of a plurality of flows.
7 . The network system of claim 1 , wherein the instructions further cause the network system to:
receive, by a network interface card (NIC) having NIC processing circuitry, the first packet of the particular instance of the flow;
determine, by the NIC, an action based on the action entry in the policy table; and
execute, by the NIC, the action on the first packet of the particular instance of the flow.
8 . The network system of claim 1 , wherein the action entry relates to a backup service.
9 . A method comprising:
obtaining telemetry data, the telemetry data comprising indications of creations of instances of a flow;
based on the indications of the creations of the instances of the flow, determining a pattern of creation of the instances of the flow; and
based on the pattern of creation of the instances of the flow, generating an action entry in a policy table for a particular instance of the flow prior to receiving a first packet of the particular instance of the flow.
10 . The method of claim 9 , wherein the creation of the instances of the flow occurs prior to the creation of the particular instance of the flow.
11 . The method of claim 9 , wherein determining the pattern of creation of the instances of the flow comprises executing a machine learning model.
12 . The method of claim 9 , wherein generating the action entry comprises executing a machine learning model.
13 . The method of claim 12 , wherein the machine learning model is an unsupervised machine learning model.
14 . The method of claim 12 , wherein the machine learning model is trained using respective indications of a plurality of creations of instances of a plurality of flows.
15 . The method of claim 9 , further comprising:
receiving, by a network interface card (NIC) having NIC processing circuitry, the first packet of the particular instance of the flow;
determining, by the NIC, an action based on the action entry in the policy table; and
executing, by the NIC, the action on the first packet of the particular instance of the flow.
16 . The method of claim 9 , wherein the action entry relates to a backup service.
17 . Non-transitory computer-readable storage media storing instructions, which, when executed, cause processing circuitry to:
obtain telemetry data, the telemetry data comprising indications of creations of instances of a flow;
based on the indications of the creations of the instances of the flow, determine a pattern of creation of the instances of the flow; and
based on the pattern of creation of the instances of the flow, generate an action entry in a policy table for a particular instance of the flow prior to receiving a first packet of the particular instance of the flow.
18 . The non-transitory computer-readable storage media of claim 17 , wherein the creation of the instances of the flow occurs prior to the creation of the particular instance of the flow.
19 . The non-transitory computer-readable storage media of claim 17 , wherein as part of determining the pattern of creation of the instances of the flow, the instructions cause the network system to execute a machine learning model.
20 . The non-transitory computer-readable storage media of claim 17 , wherein as part of the generating the action entry, the instructions cause the network system to execute a machine learning model.