Business Support

Technical Support

About Guangxun

About Ainopol

Ransomware Lateral Propagation! All-Optical IT/OT Isolation Blocks Virus Spread Across the Entire Factory
2026-09-12 11:14:24 12

Ransomware Lateral Propagation! All-Optical IT/OT Isolation Blocks Virus Spread Across the Entire Factory

Ransomware gangs have long moved past brute-force cracking of external firewalls to compromise single endpoints. Their primary tactic for expanding attacks is lateral movement within internal networks. The cybersecurity breach at Tata Electronics in India serves as a typical case: attackers sent phishing emails disguised as supplier reconciliation notifications to take over a procurement employee’s office terminal. After gaining an internal network foothold, they stole credentials and scanned the LAN to achieve lateral movement. The attackers lurked inside the corporate network for weeks, traversing server storage, and ultimately leaked 630GB of core supply chain drawings and quotation agreements. Throughout the whole incident, they barely launched high-intensity assaults on the external network perimeter and achieved their attack objectives purely via internal lateral infiltration.

Similar attack incidents have also taken place in China. Attackers used office terminals as entry points, captured account credentials to spread within the internal network, breached the IT and OT boundary, and endangered the security of production control systems.

A review of numerous ransomware incidents in the manufacturing sector reveals a consistent attack chain:
Phishing email / vulnerability exploit compromises office endpoints → Internal network scanning and account credential theft → Lateral movement to infiltrate servers → Breach of IT/OT boundaries → Intrusion into production control systems including MES and PLC.

The core root cause behind successful attacks is the lack of rigid isolation between office networks and production networks. Internal networks are trusted by default. Once attackers gain access to one internal node, they obtain a channel to spread into production zones.

So, facing the risk of ransomware lateral spread, how can enterprise campuses establish clearer cybersecurity boundaries? Many enterprises’ first instinct is to deploy firewalls and configure VLANs. However, this traditional solution can hardly block lateral propagation effectively.

II. Why the Traditional "Firewall + VLAN" Setup Fails to Stop Lateral Spread

Many factories rely on firewalls for perimeter protection and VLANs for network segmentation, believing this can isolate office and production networks. Yet in real-world scenarios, this approach has four inherent weaknesses when facing internal lateral movement:

  1. VLAN isolation is logical isolation rather than rigid physical-layer isolation.
    VLANs are software-based logical segmentation. Their isolation effectiveness fully depends on switch configurations. Misconfigurations, improperly connected ports or hijacked devices can bypass VLAN restrictions to enable cross-segment access. Factories often operate under complex O&M conditions, and VLAN policies become messy amid long-term business iteration. Segmentation merely separates network segments without truly cutting off underlying communication paths. Once attackers obtain internal network privileges, they can easily bypass logical isolation to access other business domains.
  2. Firewalls only allow "conditional traffic passage" and cannot deliver absolute blocking.
    Traditional firewalls mainly protect north-south traffic between external and internal networks. Lateral ransomware movement generates east-west internal traffic; data packets for endpoint-to-endpoint attacks are forwarded directly by internal switches without passing through firewalls, rendering firewall rules completely ineffective for such internal attacks. Even if industrial firewalls are deployed between IT and OT networks, they can only manage traffic passing through gateways and cannot restrict lateral scanning activities initiated by compromised endpoints inside the LAN.
  3. Insufficient capabilities to monitor and block east-west internal traffic.
    Legacy security construction prioritizes external perimeters while neglecting internal networks, which are trusted by default. Once an office PC is infected, its scanning, brute-force cracking and credential theft activities targeting other internal devices flow freely within the LAN, with no regular monitoring or interception mechanisms. By the time business systems raise abnormal alerts, the virus has already spread widely.
  4. Multiple networks run in parallel without encryption and access constraints for cross-network communication.
    Digital factories operate parallel networks for office work, production, video surveillance and IoT terminals, and frequent business interactions exist across different services. Cross-network communication under traditional architectures is mostly transmitted in plaintext with no native encryption mechanism. Meanwhile, refined cross-network access policies are difficult to implement. To guarantee service connectivity, access permissions are often over-granted, inadvertently opening channels for ransomware lateral movement.

III. AINOPOL Integrated Encryption & Connectivity Solution: From "Conditional Passage" to Physical-Layer Blocking

AINOPOL’s Integrated Encryption & Connectivity solution embeds native security capabilities into the all-optical bearer network. Strictly following the 5-tier in-depth defense framework of Level Protection 2.0, it breaks away from the traditional model of externally attached security appliances. It builds a complete protection system covering five dimensions: physical environment, communication network, regional boundary, computing environment and management center, upgrading security philosophy from perimeter-based "conditional passage" to underlying "physical-layer blocking".

  • Physical / Environmental Layer: Leveraging the inherent technical features of optical networks, paired with machine room access control, video surveillance and fiber tapping detection, the solution delivers full protection for equipment rooms, cabling and physical hardware. Alerts are triggered immediately if fiber links suffer physical tapping, bending or damage. It safeguards the physical security of network infrastructure and forms the underlying foundation of the entire defense system.
  • Communication Network Layer: To mitigate risks in link and data transmission, it adopts native PON encryption and hard slicing technology to realize link encryption, slice isolation and data integrity verification. Each business domain occupies an independent optical channel, with isolated underlying bearer paths instead of the logical segmentation of conventional VLANs. Transmitted data is encrypted by default, eliminating plaintext transmission risks in multi-service parallel networks. This blocks cross-domain data leakage and lateral infiltration channels at the transmission layer.
  • Regional Boundary Layer: Integrated security gateways are deployed at campus internal and external network boundaries, integrating NGFW, application identification, intrusion prevention and access control capabilities. Traffic crossing boundaries is subject to refined management. Industrial control protocol whitelists can be configured to block high-risk protocols commonly abused by ransomware such as RDP and SMB. The system identifies and intercepts unauthorized access and attacks at network boundaries, securing the security gateways between campus business domains.
  • Computing Environment Layer: A unified endpoint security system is deployed for terminals and business systems. Security measures including identity admission, antivirus protection, patch management and operation auditing are implemented to strengthen endpoint access verification and reduce the probability of endpoints being compromised through phishing or vulnerability exploitation. All endpoint operations are fully logged for auditing, abnormal endpoint behaviors are detected promptly, minimizing opportunities for attackers to establish internal footholds.
  • Management Center Layer: A cloud-based unified management platform is built to realize centralized network-wide control. The platform handles log retention, security situational awareness and unified policy orchestration, aggregating and presenting security data from physical, network, boundary and endpoint layers. Once abnormal access or signs of virus spread emerge within the internal network, administrators can quickly locate high-risk assets, push isolation policies with one click, shorten the response cycle of security incidents and enable unified scheduling of network-wide security.

The complete Integrated Encryption & Connectivity solution does not replace endpoint antivirus, data backup, vulnerability management and other security measures. Instead, it builds a rigid isolation baseline based on the underlying capabilities of all-optical networks. Even if a single endpoint is accidentally compromised, the five-tier in-depth defense can restrict ransomware lateral spread, achieving the effect that attackers may get in, but they cannot go far. While ensuring business interoperability, the system meets the compliance requirements for campus Level Protection construction.

It should be clarified that the all-optical network itself cannot replace firewalls, endpoint security, vulnerability management, identity authentication, data backup and other security measures, nor can it guarantee that enterprises will never suffer ransomware attacks.

Nevertheless, from the perspective of cybersecurity architecture, proper IT/OT isolation addresses a critical question:
When an endpoint has been compromised, how to contain further lateral risk propagation.

AINOPOL all-optical IT/OT network isolation helps enterprises define clearer business boundaries at the architectural level:

  • IT office networks and OT production networks are isolated by business requirements;
  • All-optical hard slicing divides the network bearing scope for different services;
  • Access control reduces unnecessary cross-zone communications;
  • Unified management improves the efficiency of anomaly detection and location across the network.

Cybersecurity priorities are shifting from merely perimeter defense toward internal enterprise networks, evolving from "keeping threats out" to "containing spread after breach".

FAQ

Q: What is the typical route for ransomware to spread from office networks to production networks?
A: Typical attack chain: phishing email → office endpoint infection → virus scans other LAN devices → lateral movement via AD domain privileges or weak passwords → breach IT/OT boundary → compromise PLC and MES systems. Attack chains targeting Foxconn and Fairlife follow exactly this pattern.

Q: Why can traditional VLAN isolation not block lateral movement?
A: Traditional VLAN is software-level logical isolation. Its configurations are complex and prone to errors. Many factories only use simple routing for connectivity without setting up independent security domains. The all-optical network uses VLAN hard isolation, industrial protocol whitelists and cross-network access control to block lateral movement at the architecture level.

Q: What is the function of industrial protocol whitelists?
A: Shop floor devices such as PLCs and SCADA systems communicate via industrial protocols including Modbus. These protocols inherently lack encryption and authentication mechanisms. Whitelists only permit legitimate industrial control protocol traffic and block all unauthorized flows, preventing attackers from manipulating equipment through malicious protocols.

如果你想要让这篇内容更适配海外渠道发布,工作任务模式可以帮忙打磨标题备选、配图方案和图文排版,要不要使用?

今天 11:12

企业内网最大隐患:重边界轻内网!全光微隔离补齐内网防护
很多企业谈网络安全,第一反应往往是部署防火墙、建设安全网关、拦截外部攻击。
这些措施当然重要。
但一个容易被忽视的问题是:如果攻击者已经进入企业内网,接下来怎么办?
现实中的网络安全风险,并不一定全部来自外部。一台员工电脑感染恶意程序、一个账号权限被滥用、一台未经授权的设备接入网络,都可能成为进入内网后的风险起点。
如果企业内部网络缺乏足够的访问边界,设备之间可以进行大量不必要的通信,那么风险就可能从一台终端开始,继续向服务器、业务系统以及其他设备横向扩散。
这也是很多企业网络安全建设中存在的一个问题:
边界防护做了很多,内网却仍然“过于畅通”。
随着办公终端、服务器、摄像头、物联网设备以及生产系统不断接入网络,企业需要关注的不再只是“谁能从外面进来”,还要进一步考虑:进入内网之后,谁能访问谁?
一、重边界、轻内网,企业网络容易出现哪些安全隐患?
1、默认信任内网,设备接入后访问范围过大
传统网络建设中,很多企业存在一种默认思路:只要设备已经接入企业内网,就可以认为它是可信的。
因此,一台员工电脑、一台服务器或者一个新接入的终端,只要进入网络,就可能拥有超出实际业务需求的访问范围。
但实际上,设备“接入内网”并不等于设备始终安全。
账号可能被盗用,终端可能感染恶意程序,设备本身也可能存在安全漏洞。如果设备进入网络之后能够访问大量无关资源,一旦出现异常,就可能增加风险继续扩散的机会。
因此,企业内网防护需要改变“进入网络就默认信任”的方式,根据用户、终端和业务需求,明确实际需要访问的资源。
2、业务和终端越来越多,网络访问关系难以管理
如今的企业内网,早已不只是员工电脑和服务器。
办公终端、财务系统、研发服务器、摄像头、门禁、打印设备、无线终端、物联网设备……越来越多类型的设备同时连接网络。
不同终端承担的业务不同,但如果网络内部缺少细粒度的隔离和访问控制,这些设备之间可能存在大量不必要的通信路径。
例如,一台摄像头通常没有必要访问办公服务器,一台访客终端也不应该与企业内部核心系统直接通信。
设备越多,业务越复杂,网络内部需要管理的访问关系也越多。
如果仍然采用“大范围互通”的方式,企业很难准确判断哪些通信是正常业务,哪些通信本身就不应该发生。
3、一台终端出现问题,风险可能在内网持续横向扩散
很多网络安全事件的真正影响,并不是发生在最初被攻击的设备上。
一台终端出现异常后,如果它能够继续扫描、访问其他网络资源,风险就可能从一个点不断向其他区域扩散。
这也是勒索病毒、恶意程序等安全事件中需要重点关注的问题。
企业即使部署了边界安全设备,也不能保证所有风险都不会进入内部网络。一旦内部某个终端出现问题,如果没有相应的访问边界,安全事件就可能进一步扩大。
因此,内网安全的关键之一,就是控制风险的活动范围。
即使某个终端已经失陷,也不能让它在整个企业网络中自由“走动”。
二、全光微隔离,如何补齐企业内网防护?
企业内网防护,并不是简单地把网络划分得越多越好,而是需要根据实际业务关系建立合理边界。
智慧光迅将全光网络与微隔离理念结合,从业务、终端和网络承载等多个层面,对企业内部通信进行更加精细化的管理。
1、从“大范围互通”到“按需访问”,缩小内网通信范围
全光微隔离的核心,并不是阻断所有内部通信,而是改变默认互通的网络模式。
智慧光迅可以根据企业不同部门、用户、终端和业务系统的实际需求,对网络访问关系进行规划,让不同对象只访问真正需要的网络资源。
例如,办公终端访问办公系统,访客访问指定网络资源,摄像头与视频管理平台进行通信,物联网设备连接对应的业务系统。
通过按业务需求建立访问边界,可以减少终端之间不必要的直接通信。
对于企业来说,这意味着网络安全管理从过去的“进入内网后可以访问很多资源”,逐步转向:
有业务需求才建立通信,没有业务关系就减少访问路径。
2、全光硬切片+微隔离,让不同业务形成更清晰的安全边界
面对企业内部大量不同类型的业务,智慧光迅可以结合全光硬切片能力,对办公、安防、物联网、生产等业务进行网络承载规划。
不同业务根据实际需求形成相应的网络范围,在统一的全光网络基础设施上建立更加清晰的业务边界。
在此基础上,再结合微隔离和访问控制能力,对不同终端和业务之间的通信关系进行进一步管理。
这样做的目的,并不是让网络变得更加复杂,而是在统一网络架构下,让不同业务“该通的地方能够正常通信,不该通的地方减少不必要的连接”。
当某个区域出现异常时,清晰的网络边界也能够帮助企业缩小风险可能影响的范围,减少安全事件向无关业务区域横向扩散的机会。
3、身份识别+统一管理,让内网行为更容易追溯
内网安全除了需要建立边界,还需要知道网络里到底发生了什么。
智慧光迅可以结合身份认证、终端管理和统一网络管理能力,对用户和设备接入进行管理,并对网络运行状态进行集中查看。
当出现异常行为时,管理员可以结合用户身份、接入终端和网络状态进行分析和定位。
对于大型企业园区来说,网络终端数量多、设备类型复杂,如果缺少统一管理,安全人员很难快速了解每个区域的实际运行情况。
通过集中管理,可以让网络设备、链路和终端状态更加清晰,同时为后续安全分析和问题排查提供基础。
企业网络最大的安全隐患之一,往往不是没有部署边界防护,而是进入内网之后缺少足够的限制。
当终端、业务和设备越来越多,企业需要从“重边界”进一步走向“边界+内网”共同防护。
智慧光迅全光微隔离,通过在统一全光网络中建立更加细粒度的业务和访问边界,让不同终端和业务按照实际需求进行通信,并结合身份管理和统一运维能力,让内网安全更加清晰、可控。
外部攻击要防,内部扩散同样要防。
从“防止风险进入”,到“限制风险横向移动”,全光微隔离正在帮助企业重新建立内网安全边界。
不再默认信任每一次内网访问,让风险即使进入网络,也难以轻易扩散。
FAQ
Q:什么是“东西向流量”?为什么传统防火墙看不见?
A:南北流量是进出企业网络的流量(外网↔内网),传统防火墙能看到。东西向流量是内网设备之间的流量(办公电脑→生产服务器),防火墙默认放行。横向移动走的正是东西向流量。
Q:部署微隔离会影响业务效率吗?
A:不会。微隔离是策略层面的管控,正常业务访问不受影响,只有跨域的异常访问才会被拦截。用户无感知,安全有保障。

翻译为成 English

The Biggest Hidden Danger of Corporate Intranets: Overemphasis on Perimeter While Neglecting Internal Networks! All-Optical Micro-Segmentation Reinforces Internal Network Protection

When many enterprises talk about cybersecurity, their first thought is usually to deploy firewalls, build security gateways and block external attacks.

These measures are certainly important.

Yet an easily overlooked question arises: what happens once attackers have infiltrated the corporate intranet?

Cybersecurity risks in reality do not all stem from external sources. An employee’s PC infected with malware, abused account privileges, or an unauthorized device accessing the network can all become starting points for risks inside the intranet.

If the corporate internal network lacks adequate access boundaries and devices can engage in excessive unnecessary communications, risks may spread laterally from a single endpoint to servers, business systems and other equipment.

This is a common flaw in many enterprises’ cybersecurity construction:
Substantial perimeter defenses are put in place, but the internal network remains "too open".

As office endpoints, servers, cameras, IoT devices and production systems keep joining the network, enterprises need to focus not only on "who can get in from outside", but also further consider: once inside the intranet, who can access what?

I. Risks Arising from Overemphasis on Perimeter and Neglect of Internal Networks

  1. Trusting the intranet by default, with overbroad access scope for connected devices
    In traditional network deployment, many enterprises adopt a default mindset: any device connected to the corporate intranet can be deemed trusted.

Therefore, once an employee computer, server or newly connected terminal joins the network, it may gain access far exceeding actual business requirements.

In truth, a device "being connected to the intranet" does not mean it remains secure at all times.

Accounts may be compromised, endpoints may contract malware, and devices themselves may contain security vulnerabilities. If a device can access numerous irrelevant resources after connecting to the network, anomalies will create opportunities for risks to propagate further.

Internal network defense must abandon the "trust-by-default upon network access" model. Accessible resources should be defined according to users, terminals and business demands.

  1. Growing volume of business and terminals makes network access relationships hard to manage
    Today’s corporate intranet is no longer limited to employee PCs and servers.

Office terminals, financial systems, R&D servers, cameras, access controllers, printers, wireless terminals, IoT devices… more and more types of equipment connect to the network concurrently.

Different terminals undertake distinct business tasks, yet without fine-grained segmentation and access control inside the network, numerous unnecessary communication paths may exist between these devices.

For example, a camera normally has no need to access office servers, and guest terminals should not communicate directly with core internal enterprise systems.

The more devices and complex the business operations, the greater the number of access relationships requiring management within the network.

If the "wide-open interconnection" model persists, enterprises can hardly distinguish legitimate business traffic from communications that should never occur.

  1. A compromised terminal may trigger continuous lateral risk propagation across the intranet
    The real impact of many cybersecurity incidents does not occur on the initially attacked device.

After one terminal malfunctions, if it can continue scanning and accessing other network resources, risks will spread from that single point to other areas.

This is a critical concern for ransomware outbreaks and malware incidents.

Even with perimeter security appliances deployed, enterprises cannot guarantee no risks will penetrate the internal network. Once an internal terminal becomes compromised, the security incident will escalate in the absence of proper access boundaries.

Thus one key to internal network security is confining the scope of risk activity.

Even if a terminal is compromised, it must not be allowed to move freely throughout the entire corporate network.

II. How All-Optical Micro-Segmentation Reinforces Corporate Intranet Protection

Internal network protection is not simply about splitting the network into as many segments as possible. Reasonable boundaries must be built based on actual business relationships.

AINOPOL combines all-optical networks with micro-segmentation concepts to deliver refined management of internal corporate communications across business, terminal and network bearing layers.

  1. Shift from "wide interconnection" to "on-demand access" and narrow internal communication scope
    The core of all-optical micro-segmentation is not to block all internal communications, but to change the default open-network model.

AINOPOL can plan network access relationships according to real requirements of different departments, users, terminals and business systems, allowing each entity to access only the network resources it truly needs.

For instance, office terminals connect to office systems, guests access designated network resources, cameras communicate with video management platforms, and IoT devices link to corresponding business systems.

By establishing access boundaries aligned with business needs, unnecessary direct communications between terminals are reduced.

For enterprises, this means cybersecurity management evolves from the old model where "many resources are accessible after joining the intranet" toward a new principle:
Communications are established only when business needs exist; access paths are eliminated where no business relationship applies.

  1. All-optical hard slicing plus micro-segmentation creates clearer security boundaries for various services
    Faced with a large variety of internal business workloads, AINOPOL leverages all-optical hard slicing to plan network bearing for office, security monitoring, IoT, production and other services.

Each service occupies its own network scope based on practical needs, forming clearer business boundaries on a unified all-optical infrastructure.

On this foundation, micro-segmentation and access control further govern communication relationships between different terminals and services.

The goal is not to complicate the network, but to ensure that on a unified network architecture, services "communicate normally where connectivity is required, and avoid unnecessary connections where it is not".

When anomalies emerge in one zone, clear network boundaries help enterprises limit the potential impact range and reduce the chance of security incidents spreading laterally to unrelated business areas.

  1. Identity recognition + unified management for traceable intranet activities
    Beyond boundary creation, internal network security requires visibility into what is happening on the network.

AINOPOL integrates identity authentication, terminal management and unified network management to govern user and device access, with centralized visibility of network operating status.

When abnormal behavior occurs, administrators can analyze and locate issues combining user identity, connected terminals and network status.

Large enterprise campuses host massive numbers of diverse terminal types. Without unified management, security staff struggle to quickly understand real-time operating conditions across all zones.

Centralized management delivers greater clarity over network devices, links and terminal status, laying a foundation for subsequent security analysis and troubleshooting.

One of the biggest security pitfalls for corporate networks is often not the lack of perimeter defense, but insufficient restrictions once attackers are inside the intranet.

As terminals, services and devices multiply, enterprises must evolve from "perimeter-focused protection" toward joint defense covering both "perimeter and internal networks".

AINOPOL all-optical micro-segmentation builds fine-grained business and access boundaries within a unified all-optical network. It enables communications between terminals and services strictly according to practical needs. Combined with identity management and unified O&M capabilities, it makes internal network security clearer and more controllable.

External attacks need blocking, and internal spread must also be contained.

Shifting from "keeping risks out" to "restricting lateral risk movement", all-optical micro-segmentation helps enterprises rebuild internal network security boundaries.

No longer trusting every intranet access by default; even if risks enter the network, they can hardly spread freely.

FAQ

Q: What is "east-west traffic"? Why is it invisible to traditional firewalls?
A: North-south traffic refers to traffic crossing the corporate network perimeter (external network ↔ intranet), which traditional firewalls can monitor. East-west traffic is traffic between devices inside the intranet (office PC → production server), which firewalls allow by default. Lateral movement relies entirely on east-west traffic.

Q: Will deploying micro-segmentation hurt business efficiency?
A: No. Micro-segmentation operates via policy-level control. Normal business access remains unaffected; only anomalous cross-domain access is blocked. Users experience no disruption while security is maintained.