A taxonomy for segmentation
Rohit Dube · 2025
Segmentation has been a foundational concept in network security for multiple decades. Initially used for traffic control and threat containment through virtual local area networks and sub-networks, segmentation has since evolved into more granular techniques, such as microsegmentation. The evolution of segmentation has been driven by commercial considerations, with individual security vendors describing their innovations and deployments in a somewhat ad-hoc manner. The resulting lack of a standardized vocabulary and taxonomy has hindered consistent understanding, implementation, and research. This paper proposes a comprehensive vocabulary and taxonomy for classifying segmentation methods across technologies, infrastructures, and enforcement strategies. The taxonomy enables security practitioners, vendors, and researchers to study, discuss, and deploy segmentation solutions more effectively in diverse environments. The paper also uses the language to describe major commercial and open-source product categories commonly used for segmentation. Finally, it applies the taxonomy to analyze prior research and identify under-explored areas that present opportunities for future work.