Thank you for your answer. I use nftables for firewall. and no. I didn't mean processes that are in "interrupted sleep" mode. For example, you have 'wget' on your system, let's say its path is '/usr/sbin/wget'. You didn't call it, so there is no such process. But I need to restrict its network...