Business Support

Technical Support

About Guangxun

About Ainopol

How Much Can Enterprise Full‑Optical Networks Govern Non‑Work Employee Web Browsing: Stock Trading and Short‑Video Streaming at Work
2026-08-14 16:26:23 6

How Much Can Enterprise Full‑Optical Networks Govern Non‑Work Employee Web Browsing: Stock Trading and Short‑Video Streaming at Work

“Our company subscribes to a 200 Mbps dedicated line, yet the OA system becomes inaccessible every afternoon. After investigation, one‑third of total bandwidth is consumed by staff streaming short‑form videos and playing online games.”

This is far from an isolated case. The addictive content‑delivery mechanism of short‑video platforms keeps employees engaged far longer than expected once apps such as Douyin are opened. One hour of cumulative non‑work entertainment per day equates to nearly 250 lost working hours per year. For knowledge‑intensive roles in R&D and design that demand sustained focus, frequent context‑switching between work and entertainment triggers the attention residue effect: after closing a video, the brain still requires several minutes to refocus on work tasks.

Bandwidth congestion, reduced productivity and heightened security risks — when employees engage in personal online activities during working hours, enterprises lose far more than just network speed.

What governance capabilities does a full‑optical network deliver? AINOPOL provides end‑to‑end coverage: from identifying personal‑use behaviour, to blocking unauthorised activities, and generating auditable compliance evidence.

I. Three Major Hazards of Non‑Work‑Related Employee Internet Usage

Congestion of mission‑critical corporate bandwidth

A single 1080P short‑video stream consumes roughly 5‑8 Mbps. Twenty concurrent users can eat up 100‑160 Mbps of egress bandwidth. When business‑critical applications compete with recreational traffic, OA response slows at best; core services may time‑out and disconnect at worst. An IT manager at a mid‑sized internet firm reported that nearly one‑third of corporate bandwidth was occupied by employee entertainment traffic, rendering the OA system unreachable during peak hours.

Concealed security vulnerabilities

Game clients and video applications downloaded by staff originate from unvetted sources. Third‑party installers may carry malicious code or ransomware payloads. Certain “free‑to‑use” apps secretly upload background data, creating data‑leakage risks. Entertainment platforms can also serve as attack jump‑points: threat actors send phishing links via platform private messages, implant trojans upon user clicks, and perform lateral movement across the corporate intranet.

Legal and compliance liabilities

A manufacturing enterprise once faced legal repercussions: an employee accessed overseas gambling websites over the corporate network, and public‑security authorities traced activity back to the corporate public IP. Although confirmed as individual misconduct, the firm expended substantial resources assisting official investigations, and the responsible IT supervisor was held accountable. Employee visits to gambling, pornographic, phishing or pirated‑resource websites consume bandwidth and may expose the enterprise to joint legal liability.

II. Governance Scope of the AINOPOL Full‑Optical Network

Built upon the PON passive‑optical‑network architecture, AINOPOL embeds application‑control capabilities natively within full‑optical gateways. Visualised policy configuration is delivered via the EAAS cloud‑operation‑and‑maintenance platform, forming a closed loop covering identification, enforcement, auditing and traffic optimisation — no additional dedicated hardware appliances are required.

Layer 1: Visibility — accurately identify who is using the network and which applications are in use

The built‑in ZDPI Layer‑7 protocol‑identification engine recognises more than 10 000 common applications with up to 90 % accuracy, including short‑video services, online games, live‑streaming portals, video‑streaming sites, instant‑messaging and social‑media platforms. Powered by DPI technology, the engine penetrates HTTPS encryption and dynamic ports to detect application fingerprints.

Meanwhile, the AINOPOL solution supports real‑name authentication via DingTalk, WeCom, SMS verification and other methods, binding three attributes: person, device and account. End‑users and their application usage are fully visible on the management platform.

Layer 2: Enforcement — from blanket blocking to granular per‑user policies

AINOPOL full‑optical application governance delivers multi‑dimensional fine‑grained controls:

Application control: Throttle or outright block games, video‑streaming, file‑downloading, online‑shopping, stock‑trading and other categories. Administrators can fully prohibit designated application families (e.g. all online games) during predefined working hours. For services permitted yet bandwidth‑limited (e.g. video streaming), set hard bandwidth caps to preserve throughput for core business workflows.

URL filtering: Over 3 000 pre‑loaded URL classification entries span finance, e‑commerce, entertainment, social media and dozens of other categories. Entire categories such as “shopping sites” or “stock‑market portals” may be allowed or blocked with one click. Whitelist mode suits classified‑security roles and finance departments: only pre‑audited domain names are permitted. Blacklist mode permits general web access while intercepting high‑risk categories.

Intelligent traffic shaping: Business‑critical traffic for video conferencing, OA and ERP is automatically assigned high‑priority queues. Recreational flows (short‑video, gaming) are placed into low‑priority queues with strict bandwidth ceilings during office hours. Unused bandwidth is released when business demand eases and instantly reclaimed when workloads rise.

Time‑based policies: Block entertainment‑category applications completely during core working hours and relax permissions for lunch breaks. Differential rules support flexible privileges for management alongside strict constraints for regular staff.

IPv4 / IPv6 dual‑stack packet‑filter hardware firewall: Creates defence‑in‑depth together with URL filtering. The packet‑filter firewall performs first‑pass inspection at L3/L4 based on IP addresses and ports. The URL‑filtering engine conducts second‑pass precise inspection at Layer 7. Even malicious sites with newly‑registered domains absent from classification libraries can be blocked at IP‑level if threat‑intelligence feeds flag their addresses.

Layer 3: Audit trails — comprehensive records of all web activity

The solution logs full metadata for every URL access event: timestamp, authenticated‑user identity, target URL / domain name, access outcome, block reason and traffic volume. Local log retention reaches 180 days, complying with the six‑month logging requirement specified in Public‑Security Decree 151.

Every event — who accessed what, from which device, at what time, and whether traffic was allowed or denied — is traceable, auditable and exportable.

Breaking past limitations of legacy networks without hardware stacking, the AINOPOL full‑optical fine‑grained application‑governance suite delivers visibility, manageability, controllability and traceability for network behaviour via native embedded intelligence.

Through tiered rate‑limiting, time‑differentiated policies, multi‑layer security defences and full‑event auditing, it preserves priority stable bandwidth for OA, ERP, video conferencing and core office services. Meanwhile it standardises employee web‑browsing conduct, closes network‑security gaps and reinforces compliance safeguards. Corporate networks evolve from basic connectivity tools into digital‑management infrastructure that boosts productivity and mitigates risk.

FAQ

Q: What types of applications can the full‑optical network identify?

A: The AINOPOL ZDPI engine accurately recognises over 10 000 common applications with 90 % recognition accuracy, including short‑video platforms (Douyin, Kuaishou), online games, video‑streaming sites (Youku, iQIYI), live‑streaming services, instant‑messaging software, social‑media platforms and P2P downloading tools.

Q: Will legitimate office‑related access be mistakenly blocked?

A: No. Both whitelist and blacklist modes are supported. Whitelist mode, for security‑sensitive posts, permits only pre‑approved domain names. Blacklist mode allows general web access and blocks only specified risky categories. Department‑level, user‑group‑level and time‑based differentiated authorisations ensure normal business workflows remain unaffected.

Q: Does deployment require purchasing additional hardware?

A: No. Application‑control capabilities are deeply embedded inside full‑optical gateways. Visual policy configuration is performed via the EAAS cloud‑O&M platform. The M1 Dream Gateway consolidates routing, switching, firewall, AC controller, IPPBX, log‑auditing and media‑streaming capabilities within one appliance to fulfil all requirements.