Network firewall technology has been around for decades, helping to protect and create an IT perimeter. What has also been around for decades is the innate complexity of firewall policy management, especially in larger environments with growing numbers of devices, users and applications.

Today Cisco is taking a stab at solving firewall policy complexity by using the power of artificial intelligence (AI). The new AI Assistant for Firewall Policy is a generative AI-powered technology that aims to enable organizations to use natural language queries to understand and configure firewall policies across distributed organizations.

Another key challenge that is increasingly facing firewall administrators is that of visibility in an era where increasing volumes of network traffic is encrypted. To help solve that issue, Cisco is introducing the AI-powered Encrypted Visibility Engine. The overall goal for Cisco is nothing less than an attempt to fundamentally change the way network administrators experience and security.

"For firewall administrators, this is a leap forward with just absolutely magical capability," Tom Gillis, SVP and general manager of security at Cisco, told SDxCentral. "We have got it in customers hands, it's real, it's not something over the rainbow, It's here now and it's just one example of what we're doing with AI to fundamentally change the way the administrator experiences security."

Untangling the complexity of firewall policies with AI

Firewall rules and policy have become enormously complex in the modern era.

Gillis said that Firewall technology was originally created in a very different era, when organizations relied on physical boxes, there was no cloud and an IP address could be used in many respects as the basis of identity. What has happened as virtualization, cloud and increasing scale have come to organizations is a corresponding complexity in firewall policies. It's at a point now, Gillis said, where organizations can have extreme difficulty figuring out what is or isn't allowed through a set of firewalls.

To address this complexity, Cisco has trained large language models (LLMs) on the specific semantics of the firewall policy. This allows Cisco to provide a natural language interface to better understand what policy is in place. Gillis said administrators can now ask questions like "can Tom get to this database?" or request access changes like "we just acquired this company and they need access to SharePoint, but I don't want to give them access to Jira."

Gillis emphasized that no longer will simple access queries require "an enormous amount of fanfare" and complex change requests. The AI assistant determines access from existing firewall policies but makes it straightforward to understand via natural language.

Firewall policies alone, however, are not always the arbiter of access to a given application or resource. There can also be access control lists (ACLs), role-based access control (RBAC) or identity and access management (IAM) in place. Gillis acknowledged the assistant sees only  firewall policies currently but hinted at broader ambitions to enable visibility across multiple sub systems using a single interface to provide a holistic view.

Encrypted traffic analysis getting an AI boost

In addition to the AI assistant, Cisco is applying AI to analyze encrypted traffic passing through firewalls.

Gillis said that Cisco's AI-powered encrypted visibility engine works by analyzing metadata about network flows rather than decrypting the actual payloads. Some of the metadata it analyzes includes the flow patterns, source and destination of traffic, as well as the behavior of endpoints initiating connections. Cisco is able to train models that recognize patterns and anomalies by leveraging data from every incident its response team investigates.

Even though the payloads are encrypted, Gillis said this metadata analysis can still "learn an amazing amount" and provide visibility without decrypting traffic. He also mentioned Cisco looks at details like the process that initiated a network connection on endpoints to provide additional context around encrypted flows.

Overall, Gillis noted that there is a lot more AI work coming from Cisco in the coming months that will help to improve network security.

"I think this is really the tip of the iceberg," Gillis said.  "I think that this AI capability is going to continue to startle us with the way that people administer, deploy, and manage security infrastructure."