AI policy statistics in Secure Workload

AI Policy Statistics is a feature in Cisco Secure Workload that:

  • tracks and analyzes policy performance trends over time by using the AI engine.

  • provides users with insights into policy effectiveness

  • helps perform efficient audits by identifying, configuring, and addressing policies that require attention.

The AI engine generates conditions such as No Traffic, Overshadowed, and Broad. No Traffic applies to policies not affecting any flow for more than 30 days, Overshadowed applies to policies overshadowed by other policies, and Broad is for a policy source or destination filter that is underutilized.

To understand how AI Policy Statistics works with the AI engine, watch this video: Policy Statistics with Secure Workload AI Engine


Attention


Recent GUI updates mean some images or screenshots in the user guide might not reflect the current product design. Use the guide with the latest software version for accuracy.


AI policy statistics in Secure Workload

The AI Policy Statistics feature in Secure Workload offers key functionalities:

  • Policy trend analysis: You can view the performance trends of policies over a specific time period. They can compare the expected number of flows with the actual performance of the policies.

  • Policy conditions: The AI engine identifies and flags policies that meet specific conditions and require user attention.


    Note


    A policy condition rule cannot be in more than one condition at a time. For example, a rule can be in either the Broad or Overshadowed condition at a time, but not both simultaneously.


    • No Traffic—A policy that does not affect any flow for a configured period.

      Figure 1. Policy condition–No Traffic
    • Overshadowed—A policy that overshadows another policy.

      Figure 2. Policy Condition–Overshadowed
    • Broad—A policy source filter or destination filter that has underutilized policy filters. For example, if a filter consists of ten inventories and only two out of the ten inventories participate in the flows that are affected by the policy, the filter will be at only 20 percent utilization.

      Figure 3. Policy Condition–Broad

AI policy statistics on traffic flows

AI Policy Statistics are numeric measures that

  • reflect the impact of each policy on network traffic flows,

  • provide insights into policy effectiveness, and

  • focus on deployed policies, excluding drafts or unpublished versions.


Note


The First Scanned On and Last Used On columns shows the timestamp of the first time the AI engine scanned a policy, and the timestamp of the last time it scanned a policy.


Figure 4. AI Policy Statistics
AI Policy Statistics and their role in evaluating traffic flow policies

Calculate policy statistics

A policy statistic is a performance measurement that:

  • depends on flows matching a policy's criteria,

  • updates every six hours for one week, and

  • includes AI algorithms to analyze data and identify patterns beyond simple hit counts.

Machine learning algorithms are used to analyze and identify patterns, and trends in hit counts, providing a detailed overview of policy performance compared to simple firewall hit counts.

Prerequisites for AI Policy Statistics

AI Policy Statistics is a feature that allows you to assess the performance of AI-driven policies.

  • Policies must be actively published for AI analysis.

  • The AI engine must be configured and running optimally.

  • Users must have Role-Based Access Control (RBAC) permissions to access technical data.

Before leveraging the AI Policy Statistics feature, ensure that these prerequisites are met:

  • Publish policies: Ensure policies are actively published in Cisco Secure Workload for the AI engine to scan and calculate statistics. Only published policies are included in the analysis.

  • AI engine activation: The AI engine must be running and configured in the Secure Workload environment. Configure the AI settings optimally. Review the AI settings and revert them to defaults if they do not produce expected results.

  • User access privileges: Ensure that users have the necessary Role-Based Access Control (RBAC) permissions that allow viewing of policy statistics and data trends.

Set up AI policy settings

Establish advanced policy configurations with AI capabilities to enhance policy management.

The AI engine allows you to view policy statistics and applied policy rules in the workspaces. You can leverage the advanced capabilities of the AI engine to enhance:

  • Continuous policy discovery using the AI Policy Discovery functionality.

  • Trend analysis of policy condition for policy effectiveness.

  • Real-time policy updates based on escaped flows.

  • In-depth policy performance statistics over time.

  • AI-assisted recommendations for policy improvements.


Note


Policy statistics are visible only after the policies are published.


Before you begin

Ensure policies are published to view statistics.

Procedure


Step 1

Log in to the Cisco Secure Workload application and from the navigation pane, choose Defend > Segmentation.

  1. To check how policies are analyzed, choose a workspace.

  2. To check which policies are attached to this workspace, and which policies are being considered for analysis by the AI engine, click Manage Policies.

    For instructions on how to create policies, see Manually create policies.

  3. To check the policies that have already been analyzed, click the Policy Analysis tab, and then click Analyze Latest Policies.

    Note

     

    Ensure you complete a thorough analysis before publishing the policies.

Step 2

To verify the policies that are analyzed on the workload, from the navigation pane, choose Defend > Segmentation and click Policy AI Settings.

After analyzing the policies, the AI engine calculates the policy statistics every six hours. By default, the policy statistics shows one week's data. However, to update the required interval, you can also change the time frame in the Policy AI Settings page.

Figure 6. Policy AI Settings
Advanced Automatic Policy Discovery Configurations

What to do next

Create alerts for policies to trigger notifications when traffic hits them. Analyze and remediate the problem, and restore traffic to the vulnerable workload based on the notification. For more information, refer to Configure Alerts.

Frequently asked questions

This section lists some potential scenarios that you might face while using the AI engine:

  • Question: Why am I unable to see the policies for the workspace?

    Answer: Verify if the policies are published. Ensure they are published for the AI engine to scan them.

  • Question: How often are policy statistics updated?

    Answer: Policy statistics are updated every six hours. Note that this is not configurable by users.

  • Question: Can I enforce the policy suggestions immediately after I get the suggestions?

    Answer: Policy conditions are suggestions and you must verify the suggestions before taking any action on them.

  • Question: What should I do if the results are not as expected?

    Answer: If results are not as expected, check the AI Policy settings and revert to the defaults for optimal usage.

  • Question: Is there customer-facing documentation on the models used? Are there details on the AI services used?

    Answer: We are not using any Large Language Models (LLMs). Results are derived from decision tree and data processing. AI-related services are server processes running inside a Secure Workload cluster on a VM, which is not a yarn job.