-
公开(公告)号:US20210029146A1
公开(公告)日:2021-01-28
申请号:US16546513
申请日:2019-08-21
Applicant: VMware, Inc.
Inventor: Mani KANCHERLA , Jian LAN , Xi ZENG , Hailing XU , K. Antion SHIBAN
Abstract: Embodiments described herein relate to managing firewall rules. Embodiments include identifying a plurality of firewall rules for request handling. Embodiments include determining a deny count for each given firewall rule of the plurality of firewall rules based on a number of requests flagged on account of the given firewall rule. Embodiments include determining an anomaly score for each given firewall rule of the plurality of firewall rules indicating a severity of attacks the given firewall rule protects against. Embodiments include determining an urgency measure for each given firewall rule of the plurality of firewall rules based on the deny count for the given firewall rule and the anomaly score for the given firewall rule. Embodiments include determining an update to at least one firewall rule of the plurality of firewall rules based on the urgency measure for each given firewall rule of the plurality of firewall rules.