<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Is there a default runtime policy with basic rules for containers and virtual machines before the ML learning is done? in Prisma Cloud Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/is-there-a-default-runtime-policy-with-basic-rules-for/m-p/572172#M1138</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As mentioned in &lt;A href="https://docs.prismacloud.io/en/classic/compute-admin-guide/runtime-defense/runtime-defense" target="_blank"&gt;https://docs.prismacloud.io/en/classic/compute-admin-guide/runtime-defense/runtime-defense&lt;/A&gt; the ML will learn the allowed network, process communication and file system and patterns but before that will it scan files for basic viruses or block known bad ip addresses without making a custom rule &lt;A href="https://docs.prismacloud.io/en/classic/compute-admin-guide/runtime-defense/custom-runtime-rules?" target="_blank"&gt;https://docs.prismacloud.io/en/classic/compute-admin-guide/runtime-defense/custom-runtime-rules?&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also when the application changes it's pattern because the the developers changed the app will the new features cause issues as new process, file system and network access will be seen in the system ? Basically I am asking if the ML model will automatically adapt by changing itself or giving recommendations for new rule changes. Outside of that is there a trusted ip address that can be configured that the the devs can use to access to changed the web app and then Prisma Cloud to adapt when it sees traffic coming from this IP address?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 08 Jan 2024 20:50:21 GMT</pubDate>
    <dc:creator>nikoolayy1</dc:creator>
    <dc:date>2024-01-08T20:50:21Z</dc:date>
    <item>
      <title>Is there a default runtime policy with basic rules for containers and virtual machines before the ML learning is done?</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/is-there-a-default-runtime-policy-with-basic-rules-for/m-p/572172#M1138</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As mentioned in &lt;A href="https://docs.prismacloud.io/en/classic/compute-admin-guide/runtime-defense/runtime-defense" target="_blank"&gt;https://docs.prismacloud.io/en/classic/compute-admin-guide/runtime-defense/runtime-defense&lt;/A&gt; the ML will learn the allowed network, process communication and file system and patterns but before that will it scan files for basic viruses or block known bad ip addresses without making a custom rule &lt;A href="https://docs.prismacloud.io/en/classic/compute-admin-guide/runtime-defense/custom-runtime-rules?" target="_blank"&gt;https://docs.prismacloud.io/en/classic/compute-admin-guide/runtime-defense/custom-runtime-rules?&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also when the application changes it's pattern because the the developers changed the app will the new features cause issues as new process, file system and network access will be seen in the system ? Basically I am asking if the ML model will automatically adapt by changing itself or giving recommendations for new rule changes. Outside of that is there a trusted ip address that can be configured that the the devs can use to access to changed the web app and then Prisma Cloud to adapt when it sees traffic coming from this IP address?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 20:50:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/is-there-a-default-runtime-policy-with-basic-rules-for/m-p/572172#M1138</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2024-01-08T20:50:21Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a default runtime policy with basic rules for containers and virtual machines before the ML learning is done?</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/is-there-a-default-runtime-policy-with-basic-rules-for/m-p/572365#M1139</link>
      <description>&lt;P&gt;Yes, Prisma Cloud will log&amp;nbsp;&lt;SPAN&gt;only threat-based runtime events (malicious files or connections to high-risk IPs) even if there aren't any rules created under Defend--&amp;gt;Runtime.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Whenever there are changes in the images by the developers, Prisma Cloud automatically detects when new images are added anywhere in the environment and automatically puts them in learning mode to create a new model.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs.prismacloud.io/en/classic/compute-admin-guide/runtime-defense/runtime-defense-containers#learning-mode" target="_blank"&gt;https://docs.prismacloud.io/en/classic/compute-admin-guide/runtime-defense/runtime-defense-containers#learning-mode&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs.prismacloud.io/en/classic/compute-admin-guide/runtime-defense/runtime-defense-containers#models" target="_blank"&gt;https://docs.prismacloud.io/en/classic/compute-admin-guide/runtime-defense/runtime-defense-containers#models&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;You can explicitly allow or deny&amp;nbsp;outgoing connections that deviates from your runtime policy w.r.t IP's and DNS. Please scroll down to Networking on the following link:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs.prismacloud.io/en/classic/compute-admin-guide/runtime-defense/runtime-defense-containers#best-practices" target="_blank"&gt;https://docs.prismacloud.io/en/classic/compute-admin-guide/runtime-defense/runtime-defense-containers#best-practices&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jan 2024 16:33:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/is-there-a-default-runtime-policy-with-basic-rules-for/m-p/572365#M1139</guid>
      <dc:creator>PPawar3</dc:creator>
      <dc:date>2024-01-09T16:33:27Z</dc:date>
    </item>
  </channel>
</rss>

