Techniques are described herein for optimizing rules created on a firewall / intrusion prevention system to ensure that they stay relevant and updated. This may be achieved by leveraging network observables generated at a management center. These techniques are useful because behavior analytics associated with the user access of network is crucial in creating these rules.

This work is licensed under a Creative Commons Attribution 4.0 License.