Business Support

Technical Support

About Guangxun

About Ainopol

Phishing Emails Are Hard to Guard Against: How the All-Optical Multi-Layer Defense System Blocks External Intrusion Chains
2026-09-12 11:49:07 5

Phishing Emails Are Hard to Guard Against: How the All-Optical Multi-Layer Defense System Blocks External Intrusion Chains

An apparently flawless email may contain a "time bomb" capable of paralyzing an enterprise overnight.

An employee opens an attachment, and trojan malware is implanted onto the office PC. What follows is truly fatal: attackers move laterally from this computer, scan other devices on the internal network, and hunt for production systems and core data. Traditional firewalls monitor north-south internet traffic and allow such inward-to-outward lateral movement by default. By the time the breach is detected, data has already been exfiltrated.

The root cause of failing to block phishing emails lies not in employee carelessness, but in the lack of defense-in-depth capabilities built into the network architecture. Point defenses, whether endpoint antivirus or perimeter firewalls, can only block one segment of the attack chain. The real solution is to set checkpoints at every node an attacker must pass through.

I. The Complete Phishing Attack Chain

  1. Email Delivery
    Attackers use AI to generate highly customized phishing emails disguised as supplier quotations, system upgrade alerts or salary adjustment notices. These emails carry no obvious virus signatures and may pass through traditional gateways undetected.
  2. Link Click
    Employees click links within emails and land on fake OA login pages or cloud disk download portals. Phishing websites often contain web vulnerabilities such as SQL injection and XSS, or trick users into entering account credentials.
  3. Exploiting Vulnerabilities
    Attachments or links trigger system vulnerabilities, and malicious programs run on endpoints. Attackers exploit unpatched vulnerabilities to gain control over devices.
  4. Lateral Movement
    Attackers scan other devices within the LAN, exploit shared domain controller privileges or weak passwords to hop from one PC to another, moving from the office network into the production network.
  5. Data Theft or Ransomware Encryption
    Attackers bulk-export business data and configuration files, or encrypt core servers using ransomware.

The attack chain is closely linked. Breaking any single link will stop the entire attack.

II. How the All-Optical Multi-Layer Defense System Blocks Attacks Link by Link

Zhihui Guangxun’s converged connectivity-security solution is built on an all-optical network foundation, with security capabilities natively embedded into the network architecture. Following defense-in-depth principles, checkpoints are deployed at every stage of the attack chain.

Perimeter Blocking: Keep Phishing Payloads Out

A full-network domain name and URL intelligent risk control system is deployed to parse and block malicious emails, phishing links and virus attachments in real time. It accurately identifies phishing content disguised as O&M notifications, chip documents or supply-chain files, and links with firewalls to block threats at the entry point.
The IPv4/IPv6 dual-stack hardware firewall performs the first filtering at Layer 3/Layer 4 based on IP addresses and ports. The URL filtering engine carries out precise secondary filtering for HTTP/HTTPS requests at Layer 7. This dual interception prevents phishing payloads from entering the network.

IPS Blocks Vulnerability Exploitation

Even if a phishing email triggers a system vulnerability, the IPS intrusion prevention system intercepts malicious traffic in real time before it reaches the internal network. The Mengxiang Gateway integrates over 10,000 predefined IPS rules covering 26 types of vulnerability attacks. It blocks trojans, worms, viruses, spyware and vulnerability exploits at the network layer before threats enter the LAN.

AV Scans Malicious Files

The gateway-level AV antivirus engine is equipped with a 4-million-signature virus database, performing full-traffic virus detection for email attachments and file downloads. Unlike endpoint antivirus software that scans malware after it lands on the device, gateway AV intercepts threats before they enter the network. Malicious files are detected and blocked before reaching employee computers.

Slicing Isolation Stops Lateral Movement

Leveraging PON hard slicing capability, a single fiber is divided into multiple independent logical networks for office, production, security monitoring and IoT services, achieving complete Layer 2 / Layer 3 isolation between domains. Even if an office endpoint is infected with trojans, attackers cannot cross slicing boundaries to reach production systems and core data. This isolation operates at the optical layer instead of relying merely on policy configurations.

Full-Link Auditing Preserves Evidence

All endpoint access logs and traffic access logs are centrally collected and retained. Logs contain complete core fields including real-name information, online/offline timestamps, IP addresses, MAC addresses and accessed URLs. It meets the traceability requirements for internet behavior stipulated in Ministry of Public Security Order No.176, enabling rapid traceback after security incidents.

The five layers of defense work in tandem. Each layer intercepts a portion of attacks, and combined they form a complete defense-in-depth interception system. There is no perfect single-point defense; only a multi-layered defensive architecture works. No matter how long the phishing attack chain is, attackers cannot break through when checkpoints are deployed at every stage.
Security capabilities are built
inside the network, rather than attached externally. This is the essential difference between the converged connectivity-security solution and simply stacking standalone security appliances.

FAQ

Q: Firewalls and antivirus software are already deployed. Why do we still need the all-optical multi-layer defense?
A: Traditional firewalls focus on north-south traffic and allow internal lateral movement by default. Endpoint antivirus only protects individual devices and cannot stop malware from spreading laterally. The all-optical multi-layer defense sets checkpoints across the entire attack chain, ranging from ingress filtering to micro-segmentation, providing multi-level fallback protection.

Q: AI-generated phishing emails are increasingly difficult to identify. How to handle this?
A: Staff security training is necessary but cannot serve as the only line of defense. The all-optical network implements ingress filtering at the gateway layer. No matter how realistic AI-generated phishing emails appear, access will be blocked within milliseconds if the domain or IP is marked in threat intelligence feeds.

Q: Can log retention satisfy the requirements of Order No.176?
A: Zhihui Guangxun’s solution embeds log collection and retention within the unified management platform with complete log fields, complying with traceability requirements of Ministry of Public Security Order No.176 for internet behavior. No extra log server purchase is required.