
The compromise of a single surveillance camera may lead to full internal‑network breach. Starting from March 2026, CISA of the United States has released multiple security advisories for industrial control systems, disclosing critical vulnerabilities in products from several building‑automation vendors. Among them, CVE‑2026‑3611 (CVSS 10.0) is a zero‑credential vulnerability that enables attackers to take full control of building‑automation devices without any account credentials. Hotels, enterprise campuses and manufacturing plants are key deployment scenarios for such systems, and successful exploitation could trigger devastating consequences.
Legacy networks follow a “remediation‑after‑breach” security mindset: build the basic network first, then attach firewalls, IPS, internet‑behaviour auditing and other security appliances. Firewalls are deployed in bypass mode, IPS works as a standalone unit, and web‑behaviour management is purchased separately. Each device operates in isolation with little mutual awareness. This “appliance‑stacking” approach appears comprehensive yet contains numerous security gaps. As more hardware is added, policies grow overly complex and operation‑maintenance burdens surge, while security incidents keep recurring.
AINOPOL puts forward an alternative approach: integrated communication‑security architecture. Security capabilities are natively embedded within network infrastructure, rather than externally overlaid. Security is built‑in, not bolted‑on.
Legacy networks rely on MAC‑address whitelisting for device admission. However, MAC addresses can be easily forged. Attackers only need to collect valid MAC addresses from the local network and spoof them on their own hardware; the network will treat malicious devices as legitimate. The whole procedure takes less than one minute and requires no vulnerability exploitation.
Headless dumb terminals such as surveillance cameras, access‑control units and PLCs cannot install security clients or accept user passwords, making them prime targets for MAC spoofing. One hotel security incident involved criminals installing miniature spy cameras disguised as smoke detectors to stream stolen footage. The breach occurred because the network lacked device‑level admission control, permitting any random MAC address to join and obtain IP addresses.
Employees connect consumer routers or portable Wi‑Fi hotspots for personal convenience, which severely undermines overall network stability and security. Home routers enable DHCP by default and compete against corporate DHCP servers for IP assignment, causing endpoint communication failures. Worse still, mis‑wired LAN‑port connections trigger Layer‑2 broadcast storms. Switch CPU utilisation spikes to 100 %, bringing down network services for an entire floor.
More insidiously, rogue routers bypass corporate firewalls and security auditing to create unmonitored wireless backdoors. In May 2026, China’s Ministry of State Security disclosed that foreign intelligence agencies hijacked civilian routers as attack jump‑hosts to conduct cyber‑espionage targeting personnel from key organisations.
R&D drawings, process parameters and customer records are frequently transmitted in plaintext. Attackers inside the same broadcast domain can easily intercept such traffic. Under traditional network design, surveillance cameras and OA servers may reside within one subnet. Compromising a camera grants threat actors direct access to office business systems.
Furthermore, screen‑casting operations leave no logs, and access events lack traceable records. Once data leakage occurs, enterprises struggle to identify perpetrators or timelines. Ministry of Public Security Decree No. 151 mandates security‑event log retention for no less than 180 days. In legacy deployments, logs are scattered across heterogeneous hardware with insufficient storage and incomplete fields, resulting in untraceable audit trails.
These three threats stem from one root cause: security functions are externally appended instead of being inherently built‑into the network.
The core of AINOPOL’s integrated communication‑security solution is native fusion of connectivity and security features, instead of stacking external appliances. Security is built‑in, not bolted‑on.
Defend against MAC spoofing: ONU physical‑port plus MAC dual‑binding
The all‑optical network implements dual‑binding between ONU physical ports and device MAC addresses. Each hardware device is tightly associated with its designated port. To obtain network access, a device must match both the whitelisted MAC address and the assigned physical port. Even if attackers clone legitimate MAC values, connections from unauthorised ports will be blocked automatically. Every terminal undergoes identity verification upon plug‑in. Illegal devices trigger real‑time blocking and security alerts. Attackers may spoof MAC addresses, yet they cannot mimic physical‑port assignments.
Block unauthorized connections: triple admission control plus visual enforcement
AINOPOL deploys triple admission control combining 802.1X port access, MAC whitelisting and user‑identity authentication. Rogue routers, hidden spy cameras and external contractor laptops cannot satisfy multi‑dimensional authentication requirements. They receive no valid IP address and remain isolated from the intranet even when physically cabled.
Meanwhile, the EAAS cloud platform delivers a visual connection‑status dashboard. Operators gain full visibility into port modifications, connected‑device fingerprints and connection timestamps for traceability. Upon detection of rogue hardware, the system automatically generates alerts and terminates sessions. Unauthorised devices cannot connect, and any attempted intrusions are immediately visible.
Prevent data leakage: encryption, segmentation and auditing form three‑layer safeguards for data egress
Link‑layer AES‑128 encryption is enabled on the all‑optical network, with full‑suite national cryptographic algorithms SM2/SM3/SM4 supported for end‑to‑end protection. Data is encrypted throughout generation, transmission and storage phases.
Hardened VLAN segmentation divides the network into isolated security domains for office operations, production workloads and guest access. Inter‑domain communications are denied by default; cross‑domain sessions require explicit gateway policy approval. Even if attackers take control of surveillance cameras, they cannot reach OA or financial‑system assets.
The EAAS cloud platform centrally collects terminal‑access and traffic logs. Audit trails record user identities, timestamps, source endpoints and target resources. Logs are locally retained for at least 180 days, and compliance‑ready reports can be exported in one click. Encryption prevents data theft; segmentation restricts lateral movement; auditing ensures all operations are traceable.
Legacy appliance‑stacking model: firewalls, IPS, WAF and audit systems are purchased and deployed separately. Additional hardware brings increased configuration complexity and expanded attack surfaces. Security is bolted‑on, and vendors tend to shift blame when breaches happen.
All‑optical native‑security model: security capabilities reside inside network infrastructure. Port binding mitigates spoofing; triple admission blocks rogue devices; encryption‑segmentation‑auditing combats leakage. Security is standard‑factory functionality rather than optional add‑ons.
While competitors keep stacking discrete appliances for anti‑spoofing, anti‑rogue‑device and anti‑leakage purposes, AINOPOL delivers unified integrated communication‑security architecture.
Q: What risks are introduced by privately‑connected routers?
A: Minor consequences include IP conflicts and broadcast storms causing full‑floor outages. Severe risks arise when rogue routers create unaudited wireless backdoors bypassing firewalls and security policies, granting threat actors indirect intranet access. As disclosed by China’s Ministry of State Security in May 2026, foreign intelligence services abuse compromised civilian routers as jump‑hosts for cyber‑espionage.
Q: How do all‑optical networks prevent interception of in‑transit data?
A: Link‑layer AES‑128 encryption is activated, with full‑chain protection supported for SM2/SM3/SM4 national cryptographic algorithms. Data stays encrypted from generation through transmission to storage. Intercepted packets cannot be decrypted by adversaries.