商务支持

技术支持

About Guangxun

关于光迅

Ransomware Lateral Propagation! All-Optical IT/OT Isolation Blocks Virus Spread Across the Entire Factory
2026-09-12 11:13:15 12

Ransomware Lateral Propagation! All-Optical IT/OT Isolation Blocks Virus Spread Across the Entire Factory

Ransomware gangs have long moved past brute-force cracking of external firewalls to compromise single endpoints. Their primary tactic for expanding attacks is lateral movement within internal networks. The cybersecurity breach at Tata Electronics in India serves as a typical case: attackers sent phishing emails disguised as supplier reconciliation notifications to take over a procurement employee’s office terminal. After gaining an internal network foothold, they stole credentials and scanned the LAN to achieve lateral movement. The attackers lurked inside the corporate network for weeks, traversing server storage, and ultimately leaked 630GB of core supply chain drawings and quotation agreements. Throughout the whole incident, they barely launched high-intensity assaults on the external network perimeter and achieved their attack objectives purely via internal lateral infiltration.

Similar attack incidents have also taken place in China. Attackers used office terminals as entry points, captured account credentials to spread within the internal network, breached the IT and OT boundary, and endangered the security of production control systems.

A review of numerous ransomware incidents in the manufacturing sector reveals a consistent attack chain:
Phishing email / vulnerability exploit compromises office endpoints → Internal network scanning and account credential theft → Lateral movement to infiltrate servers → Breach of IT/OT boundaries → Intrusion into production control systems including MES and PLC.

The core root cause behind successful attacks is the lack of rigid isolation between office networks and production networks. Internal networks are trusted by default. Once attackers gain access to one internal node, they obtain a channel to spread into production zones.

So, facing the risk of ransomware lateral spread, how can enterprise campuses establish clearer cybersecurity boundaries? Many enterprises’ first instinct is to deploy firewalls and configure VLANs. However, this traditional solution can hardly block lateral propagation effectively.

II. Why the Traditional "Firewall + VLAN" Setup Fails to Stop Lateral Spread

Many factories rely on firewalls for perimeter protection and VLANs for network segmentation, believing this can isolate office and production networks. Yet in real-world scenarios, this approach has four inherent weaknesses when facing internal lateral movement:

  1. VLAN isolation is logical isolation rather than rigid physical-layer isolation.
    VLANs are software-based logical segmentation. Their isolation effectiveness fully depends on switch configurations. Misconfigurations, improperly connected ports or hijacked devices can bypass VLAN restrictions to enable cross-segment access. Factories often operate under complex O&M conditions, and VLAN policies become messy amid long-term business iteration. Segmentation merely separates network segments without truly cutting off underlying communication paths. Once attackers obtain internal network privileges, they can easily bypass logical isolation to access other business domains.
  2. Firewalls only allow "conditional traffic passage" and cannot deliver absolute blocking.
    Traditional firewalls mainly protect north-south traffic between external and internal networks. Lateral ransomware movement generates east-west internal traffic; data packets for endpoint-to-endpoint attacks are forwarded directly by internal switches without passing through firewalls, rendering firewall rules completely ineffective for such internal attacks. Even if industrial firewalls are deployed between IT and OT networks, they can only manage traffic passing through gateways and cannot restrict lateral scanning activities initiated by compromised endpoints inside the LAN.
  3. Insufficient capabilities to monitor and block east-west internal traffic.
    Legacy security construction prioritizes external perimeters while neglecting internal networks, which are trusted by default. Once an office PC is infected, its scanning, brute-force cracking and credential theft activities targeting other internal devices flow freely within the LAN, with no regular monitoring or interception mechanisms. By the time business systems raise abnormal alerts, the virus has already spread widely.
  4. Multiple networks run in parallel without encryption and access constraints for cross-network communication.
    Digital factories operate parallel networks for office work, production, video surveillance and IoT terminals, and frequent business interactions exist across different services. Cross-network communication under traditional architectures is mostly transmitted in plaintext with no native encryption mechanism. Meanwhile, refined cross-network access policies are difficult to implement. To guarantee service connectivity, access permissions are often over-granted, inadvertently opening channels for ransomware lateral movement.

III. AINOPOL Integrated Encryption & Connectivity Solution: From "Conditional Passage" to Physical-Layer Blocking

AINOPOL’s Integrated Encryption & Connectivity solution embeds native security capabilities into the all-optical bearer network. Strictly following the 5-tier in-depth defense framework of Level Protection 2.0, it breaks away from the traditional model of externally attached security appliances. It builds a complete protection system covering five dimensions: physical environment, communication network, regional boundary, computing environment and management center, upgrading security philosophy from perimeter-based "conditional passage" to underlying "physical-layer blocking".

  • Physical / Environmental Layer: Leveraging the inherent technical features of optical networks, paired with machine room access control, video surveillance and fiber tapping detection, the solution delivers full protection for equipment rooms, cabling and physical hardware. Alerts are triggered immediately if fiber links suffer physical tapping, bending or damage. It safeguards the physical security of network infrastructure and forms the underlying foundation of the entire defense system.
  • Communication Network Layer: To mitigate risks in link and data transmission, it adopts native PON encryption and hard slicing technology to realize link encryption, slice isolation and data integrity verification. Each business domain occupies an independent optical channel, with isolated underlying bearer paths instead of the logical segmentation of conventional VLANs. Transmitted data is encrypted by default, eliminating plaintext transmission risks in multi-service parallel networks. This blocks cross-domain data leakage and lateral infiltration channels at the transmission layer.
  • Regional Boundary Layer: Integrated security gateways are deployed at campus internal and external network boundaries, integrating NGFW, application identification, intrusion prevention and access control capabilities. Traffic crossing boundaries is subject to refined management. Industrial control protocol whitelists can be configured to block high-risk protocols commonly abused by ransomware such as RDP and SMB. The system identifies and intercepts unauthorized access and attacks at network boundaries, securing the security gateways between campus business domains.
  • Computing Environment Layer: A unified endpoint security system is deployed for terminals and business systems. Security measures including identity admission, antivirus protection, patch management and operation auditing are implemented to strengthen endpoint access verification and reduce the probability of endpoints being compromised through phishing or vulnerability exploitation. All endpoint operations are fully logged for auditing, abnormal endpoint behaviors are detected promptly, minimizing opportunities for attackers to establish internal footholds.
  • Management Center Layer: A cloud-based unified management platform is built to realize centralized network-wide control. The platform handles log retention, security situational awareness and unified policy orchestration, aggregating and presenting security data from physical, network, boundary and endpoint layers. Once abnormal access or signs of virus spread emerge within the internal network, administrators can quickly locate high-risk assets, push isolation policies with one click, shorten the response cycle of security incidents and enable unified scheduling of network-wide security.

The complete Integrated Encryption & Connectivity solution does not replace endpoint antivirus, data backup, vulnerability management and other security measures. Instead, it builds a rigid isolation baseline based on the underlying capabilities of all-optical networks. Even if a single endpoint is accidentally compromised, the five-tier in-depth defense can restrict ransomware lateral spread, achieving the effect that attackers may get in, but they cannot go far. While ensuring business interoperability, the system meets the compliance requirements for campus Level Protection construction.

It should be clarified that the all-optical network itself cannot replace firewalls, endpoint security, vulnerability management, identity authentication, data backup and other security measures, nor can it guarantee that enterprises will never suffer ransomware attacks.

Nevertheless, from the perspective of cybersecurity architecture, proper IT/OT isolation addresses a critical question:
When an endpoint has been compromised, how to contain further lateral risk propagation.

AINOPOL all-optical IT/OT network isolation helps enterprises define clearer business boundaries at the architectural level:

  • IT office networks and OT production networks are isolated by business requirements;
  • All-optical hard slicing divides the network bearing scope for different services;
  • Access control reduces unnecessary cross-zone communications;
  • Unified management improves the efficiency of anomaly detection and location across the network.

Cybersecurity priorities are shifting from merely perimeter defense toward internal enterprise networks, evolving from "keeping threats out" to "containing spread after breach".

FAQ

Q: What is the typical route for ransomware to spread from office networks to production networks?
A: Typical attack chain: phishing email → office endpoint infection → virus scans other LAN devices → lateral movement via AD domain privileges or weak passwords → breach IT/OT boundary → compromise PLC and MES systems. Attack chains targeting Foxconn and Fairlife follow exactly this pattern.

Q: Why can traditional VLAN isolation not block lateral movement?
A: Traditional VLAN is software-level logical isolation. Its configurations are complex and prone to errors. Many factories only use simple routing for connectivity without setting up independent security domains. The all-optical network uses VLAN hard isolation, industrial protocol whitelists and cross-network access control to block lateral movement at the architecture level.

Q: What is the function of industrial protocol whitelists?
A: Shop floor devices such as PLCs and SCADA systems communicate via industrial protocols including Modbus. These protocols inherently lack encryption and authentication mechanisms. Whitelists only permit legitimate industrial control protocol traffic and block all unauthorized flows, preventing attackers from manipulating equipment through malicious protocols.