Cyberattacks take many forms and have increasingly long dormancy periods. Advanced persistent threats (APTs), for example, can bypass code-based traditional security solutions such as anti-virus software, firewalls, and IPS, and lurk within systems for extended periods. ANS micro-segmentation can apply quarantine policies to anomalous virtual machines.
After applying the "strict quarantine policy," the virtual machine is completely isolated from the system network, with no ingress or egress traffic permitted. Even if the virtual machine is attacked or compromised, this policy prevents it from affecting other workloads in the system.
When a system administrator needs to diagnose or test a specific virtual machine, they can also apply the "forensic quarantine policy," which allows only objects configured by the administrator to communicate with the virtual machine.
