A multi-cloud node based distributed network scanning method and system

By building an adaptive scheduling mechanism and hot standby takeover system in a multi-cloud environment, the problem of unreasonable selection and scheduling of scanning nodes is solved, achieving efficient task allocation and seamless takeover of faulty nodes, thereby improving the execution efficiency and continuity of scanning tasks.

CN121486360BActive Publication Date: 2026-03-31JIANGSU IDEABANK MICROELECTRONICS TECH
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2026-01-07
Publication Date
2026-03-31

AI Technical Summary

Technical Problem

In multi-cloud environments, traditional centralized scanning architectures struggle to adapt to complexity. The selection and scheduling of scanning nodes lack comprehensive consideration of network topology and communication quality, resulting in inefficiency of some nodes, task timeouts or failures, and a lack of effective backup mechanisms, which affects the continuity and integrity of scanning tasks.

Method used

We construct an adaptive scheduling mechanism and node hot standby takeover system based on network status awareness. By acquiring the network status parameters and node load signals of each scanning node in a multi-cloud environment, we perform availability domain division and dynamic scheduling, reorganize scanning paths, identify network blind spot nodes, establish an effective scanning coverage domain, optimize task allocation in low-latency areas, and achieve seamless takeover of faulty nodes using hot standby node clusters.

Benefits of technology

It improves the efficiency and continuity of scanning tasks, ensures that tasks are executed preferentially in areas with superior network conditions, and achieves efficient collaborative execution of scanning tasks and synchronous aggregation of results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121486360B_ABST
    Figure CN121486360B_ABST
Patent Text Reader

Abstract

The application discloses a kind of distributed network scanning method and system based on multiple cloud nodes, by collecting the network state and load information of each scanning node, available domain is divided and dynamic scheduling loop is constructed;Reorganize scanning path and identify network blind area through bidirectional connectivity detection, build effective scanning coverage domain;Delay distribution is analyzed to determine low delay window, and the optimal scanning route is planned and task allocation strategy is formulated;Task is disassembled into core detection sequence and edge detection sequence, and hot standby node cluster is constructed for edge task;Abnormal monitoring is carried out to core task, and when node is disconnected, hot standby node is drafted to form takeover link node, and collaborative scanning grid is formed;According to collaborative scanning grid, node feedback topology is built, time delay calibration is carried out to generate distributed scanning instruction, and the execution efficiency and fault tolerance of scanning task in multi-cloud environment are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security technology, and in particular to a distributed network scanning method and system based on multiple cloud nodes. Background Technology

[0002] With the deepening of enterprise informatization, multi-cloud hybrid deployment has become the mainstream IT infrastructure model. Conducting network security scanning in a multi-cloud environment faces challenges such as dispersed node distribution, significant differences in network conditions, and limited cross-cloud communication. Traditional centralized scanning architectures are ill-suited to the complexity of multi-cloud scenarios, limiting the execution efficiency and coverage completeness of scanning tasks.

[0003] Existing distributed scanning schemes have several shortcomings in multi-cloud environments. Firstly, the selection and scheduling of scanning nodes lack comprehensive consideration of network topology and communication quality, leading to inefficient execution by some nodes due to poor network conditions, and even task timeouts or failures. Secondly, when scanning nodes fail or become disconnected, there is a lack of effective backup mechanisms and task continuation methods, affecting the continuity and integrity of scanning tasks. Furthermore, the uneven distribution of network latency across different regions in a multi-cloud environment means that existing schemes fail to fully utilize the transmission advantages of low-latency areas for optimized task allocation. Summary of the Invention

[0004] This invention discloses a distributed network scanning method and system based on multi-cloud nodes, aiming to solve problems such as unreasonable scheduling of scanning nodes, difficulty in discovering network blind spots, low efficiency of task allocation, and lack of effective takeover of node failures in multi-cloud environments. By constructing an adaptive scheduling mechanism based on network state awareness and a node hot standby takeover system, and building a node feedback topology for latency calibration, the method enables efficient collaborative execution of scanning tasks among multi-cloud nodes.

[0005] The first aspect of this invention proposes a distributed network scanning method based on multiple cloud nodes, comprising the following steps:

[0006] The network status parameters and node load signals of each scanning node are obtained in a multi-cloud environment. Based on the network status parameters, the available domain is divided to generate a scanning baseline threshold. Based on the scanning baseline threshold and the node load signal, a dynamic scheduling loop is formed.

[0007] Based on the dynamic scheduling loop, the scanning path reorganization process is implemented to form an enhanced detection channel. The enhanced detection channel is used to detect network blind spot nodes and avoid the network blind spot nodes to build an effective scanning coverage area.

[0008] For the effective scanning coverage area, a delay distribution analysis is performed to determine a low-latency window. The low-latency window is then transformed into a priority scanning area to form a preferred scanning route. A task allocation strategy is generated along the preferred scanning route.

[0009] The task allocation strategy is decomposed into a core detection sequence and an edge detection sequence. Elastic capacity analysis is performed on the edge detection sequence to extract a candidate node set. Resource aggregation is performed on the candidate node set to form a hot standby node cluster.

[0010] Anomaly monitoring is performed on the core detection sequence to obtain node disconnection signals. Based on the node disconnection signals, corresponding nodes are selected from the hot standby node cluster to form a takeover node link. The takeover node link is then seamlessly connected with the core detection sequence to generate a collaborative scanning grid.

[0011] Based on the collaborative scanning mesh, a node feedback topology is constructed, and a time delay calibration analysis is performed on the node feedback topology to generate distributed scanning commands.

[0012] A second aspect of this invention proposes a distributed network scanning system based on multiple cloud nodes, comprising:

[0013] The status awareness module is used to acquire network status parameters and node load signals of each scanning node in a multi-cloud environment, divide the available domain based on the network status parameters to generate a scanning baseline threshold, and form a dynamic scheduling loop based on the scanning baseline threshold and the node load signal.

[0014] The path reorganization module is used to perform scan path reorganization processing based on the dynamic scheduling loop to form an enhanced detection channel, and to detect network blind spot nodes by means of the enhanced detection channel, thereby avoiding the network blind spot nodes and building an effective scan coverage area.

[0015] The latency analysis module is used to perform latency distribution analysis on the effective scan coverage area to determine the low latency window, convert the low latency window into a priority scan area to form a preferred scan route, and generate a task allocation strategy along the preferred scan route.

[0016] The task allocation module is used to decompose the task allocation strategy into a core detection sequence and an edge detection sequence, perform elastic capacity analysis to extract a candidate node set for the edge detection sequence, and perform resource aggregation to form a hot standby node cluster for the candidate node set.

[0017] The fault takeover module is used to perform abnormal monitoring for the core detection sequence to obtain node disconnection signals, extract corresponding nodes from the hot standby node cluster to form a takeover node link based on the node disconnection signals, and seamlessly connect the takeover node link with the core detection sequence to generate a collaborative scanning grid.

[0018] The instruction output module is used to build a node feedback topology based on the cooperative scanning grid, and to perform time delay calibration analysis on the node feedback topology to generate distributed scanning instructions.

[0019] The beneficial effects of this invention are reflected in the following points: 1. By collecting network status parameters and node load signals of each scanning node in a multi-cloud environment, available domains are divided and dynamic scheduling loops are established. The scanning paths are reorganized to form enhanced detection channels. Network blind spot nodes are identified through bidirectional connectivity detection, and an effective scanning coverage area is built, solving the problems of insufficient network quality considerations in node scheduling and ineffective coverage of some areas. 2. Delay distribution analysis is performed on the effective scanning coverage area to identify high-latency isolation segments and form efficiency evaluation indicators. Low-latency windows are transformed into priority scanning areas to form preferred scanning routes, generating task allocation strategies that prioritize task execution in areas with superior network conditions, thus improving task execution efficiency. 3. The task allocation strategy is decomposed into core detection sequences and edge detection sequences. Elastic capacity analysis is performed on the edge detection sequences to extract candidate node sets and aggregate them into hot standby node clusters. When the execution node of the core detection sequence loses connection, adjustment points are extracted from the hot standby node cluster to form takeover node links, which are connected with the core detection sequence to form a collaborative scanning grid. Based on the collaborative scanning grid, node feedback topology is built for delay calibration to generate distributed scanning commands, ensuring continuous execution of scanning tasks and synchronous aggregation of results. Attached Figure Description

[0020] The accompanying drawings illustrate specific examples of the technical solutions described in this invention and, together with the detailed embodiments, form part of the specification, serving to explain the technical solutions, principles, and effects of this invention.

[0021] Unless otherwise specified or defined, the same reference numerals in different figures represent the same or similar technical features, and different reference numerals may be used to represent the same or similar technical features.

[0022] Figure 1 This is a flowchart illustrating a distributed network scanning method based on multiple cloud nodes according to the present invention.

[0023] Figure 2 This is a structural block diagram of a distributed network scanning system based on multiple cloud nodes according to the present invention. Detailed Implementation

[0024] In the following description, specific details such as particular system architectures and techniques are set forth for illustrative purposes and not for limitation, in order to provide a thorough understanding of the embodiments of this application. However, those skilled in the art will understand that this application may also be implemented in other embodiments without these specific details. In other instances, detailed descriptions of well-known systems, apparatuses, circuits, and methods have been omitted so as not to obscure the description of this application with unnecessary detail.

[0025] It should be understood that, when used in this application specification and the appended claims, the term "comprising" indicates the presence of the described features, integrals, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, integrals, steps, operations, elements, components and / or a collection thereof.

[0026] References to "one embodiment" or "some embodiments" as described in this specification mean that one or more embodiments of this application include a specific feature, structure, or characteristic described in connection with that embodiment. Therefore, the phrases "in one embodiment," "in some embodiments," "in other embodiments," "in still other embodiments," etc., appearing in different parts of this specification do not necessarily refer to the same embodiment, but rather mean "one or more, but not all, embodiments," unless otherwise specifically emphasized. The terms "comprising," "including," "having," and variations thereof mean "including but not limited to," unless otherwise specifically emphasized.

[0027] The technical solutions of the embodiments of this application will be described below.

[0028] like Figure 1 As shown, this embodiment of the invention provides a distributed network scanning method based on multiple cloud nodes, including the following steps S110-S160:

[0029] Step S110: Obtain the network status parameters and node load signals of each scanning node in a multi-cloud environment, divide the available domain according to the network status parameters to generate a scanning baseline threshold, and form a dynamic scheduling loop based on the scanning baseline threshold and the node load signals.

[0030] Specifically, the system acquires network status parameters and node load signals for each scanning node in a multi-cloud environment. Communication connections are established with scanning nodes on various cloud platforms, covering all scanning instances deployed in public, private, and hybrid cloud environments. Status acquisition requests are sent to each scanning node, including a collection time identifier and a list of collection items. Upon receiving the request, each node collects its local network connection status and resource usage. Network connection status includes the node's cloud platform identifier, availability zone number, network egress bandwidth, inter-node latency, and packet loss rate. Resource usage includes CPU utilization, memory usage, concurrent connections, and task queue depth. The collected data related to network connection status is encapsulated into network status parameters, stored in structured record format, with fields covering network topology location and communication quality indicators. The collected data related to resource usage is encapsulated into node load signals, stored in time-series format, with sequence elements including the collection time and utilization values ​​for each resource dimension. The validity of the network status parameters and node load signals is verified, and abnormal records with timeouts or missing data are removed. Due to differences in network topology, the inter-node latency distribution in network status parameters varies significantly among scanning nodes deployed across cloud platforms. Node latency within the same cloud platform is typically low and stable, while latency between nodes across cloud platforms fluctuates significantly due to the quality of public network links. It should be noted that communication connections between scanning nodes in a multi-cloud environment are based on pre-deployed cross-cloud network infrastructure, including but not limited to: cloud networking services provided by cloud service providers (such as AWS Transit Gateway, Alibaba Cloud Enterprise Network CEN, Tencent Cloud Cloud Network CCN), enterprise-built IPSec VPN tunnels, or SD-WAN networking solutions. The technical solution of this invention is implemented under the premise that the aforementioned cross-cloud network infrastructure has been established. Each scanning node communicates through a unified private network address space, and network connectivity between nodes is guaranteed by the underlying network infrastructure. The technical problem solved by this invention is how to achieve efficient task scheduling and fault takeover in a node cluster with existing cross-cloud communication capabilities, rather than how to overcome the network isolation limitations of cloud platforms.

[0031] Available domains are partitioned based on network status parameters to generate scanning baseline thresholds. The network topology location and communication quality indicators of each node in the network status parameters serve as the basis for available domain partitioning. Nodes are grouped according to their cloud platform affiliation and availability zone distribution in the network status parameters. Nodes within the same cloud platform and availability zone are grouped into the same available domain, and nodes within an available domain exhibit low-latency, high-bandwidth network connectivity. Communication capabilities of each available domain are evaluated, with evaluation indicators including average intra-domain latency, average inter-domain latency, and domain egress bandwidth capacity from the network status parameters. Based on the communication capability evaluation results, available domains are tiered. Available domains with strong communication capabilities are suitable for high-concurrency scanning tasks, while those with weak communication capabilities are suitable for low-frequency deep scanning tasks. Corresponding task distribution constraints are set for each available domain tier, including maximum concurrent task count, maximum target quantity per task, and task timeout limit. The tiering results of each available domain and the task distribution constraints are integrated to form the scanning baseline thresholds. The scanning baseline thresholds are stored in the form of a threshold configuration table. Each row in the table corresponds to an availability zone, and the columns include the zone number, zone level, concurrency limit, target number limit, and timeout threshold. Private cloud nodes deployed in the core data center are typically classified as high-level availability zones, and their scanning baseline thresholds are configured with higher concurrency limits. Public cloud nodes deployed at the edge are classified as low-level availability zones, and their scanning baseline thresholds are configured with stricter constraints.

[0032] In some embodiments, the step of constructing a dynamic scheduling loop based on the scanning reference threshold and the node load signal includes: generating a threshold fluctuation band based on the scanning reference threshold; performing correlation processing on the node load signal and the threshold fluctuation band to form a load-threshold coupling characteristic; extracting a stable scheduling interval within the load-threshold coupling characteristic; and constructing a dynamic scheduling loop based on the scheduling weight of the stable scheduling interval.

[0033] Threshold fluctuation bands are generated based on the scanning baseline threshold. The constraints of each available domain in the scanning baseline threshold need to have allowable fluctuation ranges set. These fluctuation ranges are centered on the nominal value of the constraints in the scanning baseline threshold, extending upwards and downwards by a certain proportion to form fluctuation intervals. The extension proportions are determined according to the scheduling accuracy requirements. A fluctuation range is set for the concurrency upper limit constraint in the scanning baseline threshold. The nominal concurrency upper limit is multiplied by the fluctuation coefficient to obtain the upper boundary, and the nominal value is divided by the fluctuation coefficient to obtain the lower boundary. A fluctuation range is also set for the timeout threshold constraint, allowing actual timeout judgments to fluctuate within a certain range. The fluctuation intervals of each constraint are combined to form a multi-dimensional threshold fluctuation band. The threshold fluctuation band is represented in the form of an interval vector, with each component of the vector corresponding to the fluctuation interval of each constraint. When enterprises perform full-network asset scanning during peak business periods, public network link quality fluctuates significantly. In this case, the threshold fluctuation band is appropriately widened to enhance scheduling fault tolerance and avoid frequent task migrations due to network jitter. When performing targeted vulnerability detection during late-night maintenance windows, the network condition is stable, and the threshold fluctuation band can be appropriately narrowed to improve scheduling accuracy.

[0034] The node load signal and threshold fluctuation band are correlated to form a load-threshold coupling characteristic. The time series of the node load signal contains the current load value and historical change data of each node. The current value and trend of the node load signal are the basis for the correlation processing. The current load level of each node in the node load signal is compared with the constraint interval of its availability zone in the threshold fluctuation band to determine the position of the load level in the threshold fluctuation band. When the load level is below the lower boundary of the threshold fluctuation band, it is marked as a light load state; when the load level is within the threshold fluctuation band range, it is marked as a normal state; and when the load level is above the upper boundary of the threshold fluctuation band, it is marked as a heavy load state. Scanning nodes deployed in the backup data center have fewer scanning tasks during normal periods. The node load signal shows that its resource utilization rate is consistently below the lower boundary of the threshold fluctuation band, marking it as a light load state, suitable for undertaking new scanning tasks. Scanning nodes deployed in the main data center undertake multiple asset discovery tasks simultaneously during security inspections. The node load signal shows that its concurrent connection number exceeds the upper boundary of the threshold fluctuation band, marking it as a heavy load state, requiring a pause in accepting new tasks. The calculation method compares the changing trend of the node load signal with the distance to the threshold fluctuation zone boundary, estimating the expected time for the load trend to reach the boundary. The load status, boundary distance, and trend prediction of each node are integrated to form the load-threshold coupling characteristic. This load-threshold coupling characteristic is stored in a characteristic table indexed by nodes, recording the current status flag, upper boundary distance, lower boundary distance, and trend prediction value of each node.

[0035] Stable scheduling intervals are extracted within the load-threshold coupling characteristic. The state records of each node in the load-threshold coupling characteristic serve as the basis for identifying stable nodes. Nodes in a normal state and with stable trends constitute a stable node set. Trend stability is determined based on the trend prediction value in the load-threshold coupling characteristic. Trend stability is defined as a load change rate below a set threshold with no continuous deviation in the direction of change. Nodes in a normal state and with stable trends have good task carrying capacity and scheduling predictability. The capacity of the stable node set is summarized. The remaining load-bearing capacity is calculated based on the upper boundary distance of each node in the load-threshold coupling characteristic, and the summation yields the total capacity of the set. When the total capacity of the set is higher than the capacity safety threshold, the stable node set can smoothly carry subsequent tasks. At this time, the load interval corresponding to the stable node set is marked as a stable scheduling interval. The stable scheduling interval is stored in the form of a combination of load level interval and node list. The lower bound of the interval is the lowest load level among the stable nodes, and the upper bound of the interval is the highest load level among the stable nodes. The node list records the numbers of all stable nodes.

[0036] A dynamic scheduling loop is constructed based on the scheduling weights within a stable scheduling interval. Each node within the stable scheduling interval needs to be assigned a scheduling weight, determined by a combination of the node's remaining capacity and response speed. The weight is calculated for each node in the node list within the stable scheduling interval; nodes with larger remaining capacity and faster response speeds receive higher weights. The scheduling weight W = α × (1 - L / Lmax) + β × (Rmin / R), where L is the current load of the node within the stable scheduling interval, Lmax is the node's maximum load capacity, R is the node's response latency, Rmin is the minimum response latency within the stable scheduling interval, and α and β are weight coefficients with α + β = 1. The scheduling weights of each node are normalized so that the sum of the weights is 1; the normalized weights represent the task distribution probability. A task distribution channel is established between the scheduler and each node within the stable scheduling interval, supporting task routing based on weighted probabilities. The scheduling weight configuration, task distribution channel, and feedback monitoring mechanism are integrated to form a closed-loop dynamic scheduling loop. The dynamic scheduling loop operates as a scheduling controller. The controller continuously receives tasks to be scheduled, selects target nodes for distribution based on weights, and simultaneously receives execution feedback from nodes to update load information. This feedback drives the dynamic adjustment of weights, forming a closed-loop control. During quarterly security audits, enterprises initiate network-wide vulnerability scanning, resulting in a surge of scanning tasks entering the scheduler. The dynamic scheduling loop distributes these tasks to various nodes according to their weights. If a node experiences a spike in CPU utilization due to undertaking in-depth testing of high-risk vulnerabilities, exceeding the upper limit of the stable scheduling range, the dynamic scheduling loop automatically reduces the scheduling weight of that node. Subsequent tasks are then prioritized for distribution to other lightly loaded nodes. Once that node completes its in-depth testing tasks, its load decreases, and its scheduling weight is restored.

[0037] Step S120: Based on the dynamic scheduling loop, the scanning path is reorganized to form an enhanced detection channel. The enhanced detection channel is used to detect network blind spot nodes and build an effective scanning coverage area by avoiding network blind spot nodes.

[0038] Specifically, enhanced detection channels are constructed by reorganizing scan paths based on dynamic scheduling loops. The node topology in the dynamic scheduling loop is the foundation of scan path planning. The scan path defines the transmission link from the scheduler through various scan nodes to the scan target. The dynamic scheduling loop records the connection weights and scheduling priorities between nodes, and identifies high-load and low-load links based on the weight distribution in the dynamic scheduling loop. The original scan paths are optimized and reorganized using three strategies: path merging, path splitting, and path backup. Path merging integrates multiple paths pointing to adjacent targets into a tree structure with a shared front end, reducing redundant transmission overhead. When an enterprise initiates port scans on multiple servers within the same network segment, multiple independent paths would have been required. After path merging, the backbone link from the scheduler to the network segment gateway is shared, with branching only at the gateway to each target server. Path splitting distributes traffic on high-load paths to multiple parallel paths, preventing a single path from becoming a bottleneck. When a scan node simultaneously handles hundreds of scan tasks, causing egress bandwidth saturation, path splitting switches some tasks to other nodes within the same availability zone. Path backup establishes redundant alternative paths for critical paths. When the primary path fails, it automatically switches to the backup path. If the primary link between the core scanning node and the scheduler is interrupted, the backup path maintains continuous scanning task execution via a backup gateway. The recombined scanning paths are encapsulated into channels, including path identifiers, path node sequences, path bandwidth capacity, and path priorities. All encapsulated scanning paths are integrated to form enhanced detection channels. These enhanced detection channels are stored as channel sets, where each channel is independent and covers different scanning target areas. Compared to the original paths, they offer higher bandwidth utilization and fault tolerance, supporting the efficient execution of large-scale concurrent scanning tasks.

[0039] In some embodiments, detecting network blind spot nodes using the enhanced detection channel includes: dividing the enhanced detection channel into a main detection segment and a secondary detection segment; initiating a forward connectivity detection path from the main detection segment to the secondary detection segment, and simultaneously initiating a reverse connectivity detection path from the secondary detection segment to the main detection segment; comparing the response differences between the forward connectivity detection path and the reverse connectivity detection path to form a bidirectional interruption point list; and marking points in the bidirectional interruption point list that lack responses in both directions as network blind spot nodes.

[0040] The enhanced detection channel is divided into main detection segments and secondary detection segments. The topology of each channel within the enhanced detection channel includes a starting node, relay nodes, and terminal nodes. The location and role of the nodes in the enhanced detection channel are the basis for segment division. Segmentation is based on the node's location within the enhanced detection channel: the channel portion closer to the scheduler is designated as the main detection segment, and the channel portion closer to the scanned target is designated as the secondary detection segment. The boundary points for segment division are selected at the middle of the channel or the boundary point of the network topology, ensuring a roughly balanced number of nodes and coverage area between the two segments. The main detection segment is labeled with its node list and segment entry / exit locations; the secondary detection segments are similarly labeled. The main detection segment is typically located in the core network area, with stable inter-node connections and sufficient bandwidth; the secondary detection segment typically extends to the edge network area, where inter-node connections may be affected by cross-cloud platform or cross-regional factors. After segmentation, the connection point information between the main and secondary detection segments is recorded; the connection point serves as the communication bridge between the two segments.

[0041] A forward connectivity probe path is initiated from the main probe segment to the secondary probe segment, and a reverse connectivity probe path is simultaneously initiated from the secondary probe segment to the main probe segment. Forward probe tasks are deployed on each node of the main probe segment. These tasks send connectivity test packets to nodes within the secondary probe segment. The test packets use either ICMP or TCP protocols, and the sending time and target node address are recorded. It should be noted that bidirectional connectivity probing uses a lightweight heartbeat mechanism. A single ICMP probe packet is 64 bytes in size, and a TCP probe packet (SYN packet) is 40-60 bytes in size. The probe period is set to 5-10 seconds. Taking a cluster of 100 scanning nodes as an example, each node sends a probe packet every 10 seconds. The probe bandwidth consumption of a single node is approximately 64 bytes × 100 nodes ÷ 10 seconds = 640 bytes / second, equivalent to about 5.12 Kbps. Compared to the 100Mbps-1Gbps network bandwidth typically configured for industrial-grade scanning nodes, the probe traffic accounts for less than 0.01%, and its impact on the bandwidth resources of normal scanning tasks is negligible. Probe and scanning tasks are executed in independent threads at the operating system level. The CPU utilization of the probe thread is typically below 0.1%, and it does not significantly compete with the scanning task for resources. Regarding the choice of probe frequency, a 5-10 second probe cycle is a common configuration for center-hop detection in distributed systems. Taking a 5-second cycle as an example, 2-3 consecutive probe failures (i.e., 10-15 seconds) are sufficient to confirm that a node is out of contact. This response time is much faster than the typical minute-level or even hour-level execution cycle of network scanning tasks, meeting the need for timely detection of network blind spots. After receiving test packets from nodes within the probe segment, a response is returned. The main probe segment node records the response reception time and response status. The sending and response records of each test packet are combined to form a forward connectivity probe path. Simultaneously, reverse probe tasks are deployed on each node in the secondary probe segment. These tasks send test packets to nodes in the primary probe segment, using the same protocol and parameter configuration as the forward probe. Nodes in the primary probe segment receive the packets and return responses. The nodes in the secondary probe segment record these responses, forming a reverse connectivity probe path. The forward and reverse connectivity probe paths are executed synchronously to ensure network state consistency at the time of probe. After bidirectional probes are completed, the forward connectivity probe path records the connectivity status from the core to the edge, and the reverse connectivity probe path records the connectivity status from the edge to the core.

[0042] For example, the step of comparing the response differences between the forward connectivity detection path and the reverse connectivity detection path to form a bidirectional breakpoint list includes: identifying response abrupt change features based on the forward connectivity detection path and the reverse connectivity detection path to determine a detection window; tracing the response change process along the detection window to form a response trajectory map; extracting the node coordinates of each breakpoint in the response trajectory map; and arranging the node coordinates according to the degree of interruption to generate a bidirectional breakpoint list.

[0043] The detection window is determined by identifying abrupt response characteristics based on forward and reverse connectivity probe paths. Response records in the forward connectivity probe path are arranged chronologically, and the moments when abrupt responses occur are identified. These abrupt responses include three forms: sudden increases in response time, lost responses, and incorrect responses. Abrupt responses are also identified in the reverse connectivity probe path to locate anomalous moments. The abrupt response moments identified in both the forward and reverse connectivity probe paths are aligned; when abrupt responses occur in both directions at similar times, they are marked as bidirectional anomalous points. Time windows are formed by extending a certain duration forward and backward from each bidirectional anomalous point, covering the probe records before and after the anomalous event. The time windows of all anomalous points are integrated, and overlapping portions are removed to form a set of detection windows. Detection windows are stored as a list of time intervals, with each element containing the start and end times of the window and the number of associated anomalous points. The detection windows define the time periods requiring focused attention; probe records outside the windows have normal connectivity and do not require further processing.

[0044] The response trajectory map is formed by tracing the response changes along the detection window. The detection records within the detection window require fine-grained processing to extract the response state at each detection moment. The response state is represented by a multi-dimensional vector, with vector components including response time, response success rate, and response error type. The response state vectors at each moment within the detection window are arranged chronologically to form a temporal evolution sequence of the response state. Change curves are plotted with time as the horizontal axis and each component of the response state as the vertical axis; the curves of each component are superimposed to form a comprehensive response change view. The response change views of each node are arranged according to the network topology location to form a response trajectory map covering the entire detection range. The response trajectory map is stored in a two-dimensional matrix, with rows corresponding to network topology locations and columns corresponding to time series; the matrix elements are the response state codes for the corresponding locations at the corresponding moments. The response trajectory map visually displays the distribution patterns of response anomalies in the temporal and spatial dimensions; areas where anomalies are concentrated correspond to locations with network connectivity problems.

[0045] Extract the node coordinates of each interruption point from the response trajectory diagram. The distribution of abnormal states in the response trajectory diagram is the basis for identifying interruption points, and areas with continuously abnormal response states need to be highlighted. An interruption point is defined as a network location where the response is lost or the response error persists for more than the judgment time, which is set according to the network tolerance requirements. Detect the response state sequence at each corresponding position in the response trajectory diagram row by row. When the duration of consecutive abnormal states in the sequence exceeds the judgment time, mark that position as an interruption point. Record the row and column positions of each interruption point in the response trajectory diagram as node coordinates. The row component of the node coordinates corresponds to the network topology location number, and the column component corresponds to the time range of the interruption. Label the attributes of each node coordinate, including interruption type, interruption duration, interruption impact range, and source probe direction. The source probe direction indicates whether the node coordinate was identified from forward probe, reverse probe, or bidirectional probe. Interruption types are divided into complete interruption and partial interruption. Complete interruption refers to a complete loss of response, while partial interruption refers to an abnormal response that is not completely lost. Summarize all identified interruption points and their node coordinates to form an interruption point set.

[0046] A bidirectional interruption point list is generated by sorting node coordinates according to their degree of interruption. Each interruption point in the set needs to have its interruption severity score calculated, determined by a combination of the interruption type, duration, and impact range at the node's coordinate location. Complete interruptions receive higher scores than partial interruptions, longer durations receive higher scores than shorter durations, and wider impact ranges receive higher scores than narrower impact ranges. Bidirectional attribute labels are determined based on the probe direction attribute of the node coordinates. Node coordinates originating solely from forward probes are labeled as forward unidirectional interruptions, those originating solely from reverse probes are labeled as reverse unidirectional interruptions, and those originating from bidirectional probes are labeled as bidirectional interruptions. All node coordinates are sorted in descending order by interruption severity score; the result is the bidirectional interruption point list. The bidirectional interruption point list is stored in list format, with each element containing node coordinates, interruption severity score, interruption type, bidirectional attribute, and associated node information. The bidirectional interruption point list comprehensively records all connectivity problems within the probe range and their severity ranking.

[0047] Points in the bidirectional interruption point list that lack bidirectional responses are marked as network blind zone nodes. Entries in the bidirectional interruption point list marked with a bidirectional interruption attribute are the filtering targets; the network locations corresponding to these entries show no response in both forward and reverse probing. The bidirectional interruption entries in the bidirectional interruption point list are further filtered, retaining entries with a complete interruption type and excluding some interruption entries. A complete bidirectional interruption point indicates that bidirectional communication between this location and surrounding nodes has failed, placing it in a network connectivity blind zone. The network nodes corresponding to the filtered interruption points are marked as network blind zone nodes, with the marking information including node number, node network address, availability domain, and blind zone discovery time. A separate record table is created for network blind zone nodes, supporting queries by node number or availability domain. Network blind zone nodes are nodes that scanning tasks cannot reach or return results from; these nodes cannot be used as execution nodes for scanning tasks or relay nodes for scanning targets. Border nodes deployed between different cloud platforms by enterprises are prone to becoming network blind spots due to security policies restricting bidirectional communication; nodes deployed in network isolation areas may also be identified as network blind spots because firewall rules block probe packets.

[0048] To build an effective scanning coverage area, network blind spot nodes are avoided. The network blind spot node record table and enhanced detection channel configuration are the inputs for blind spot avoidance processing. Channels containing blind spot nodes in the enhanced detection channels require path correction. The node sequences of each channel in the enhanced detection channel are detected to identify whether they contain network blind spot nodes. Channels containing network blind spot nodes are marked as affected channels. Path correction is performed on affected channels, using two strategies: node replacement and path detour. Node replacement replaces the network blind spot node in the enhanced detection channel with another normal node within the same availability domain, requiring the replacement node to have normal connectivity with upstream and downstream nodes. Path detour inserts detour paths before and after the network blind spot node, with the detour path reaching the downstream node of the original path via other reachable nodes. After correction, the enhanced detection channel's connectivity is verified; channels that pass verification are restored to an effective state. The coverage areas of all effective channels are summarized to calculate the set of scanning targets covered by each channel. After removing targets that cannot be covered by any effective channel, the remaining set of targets and their associated effective channels constitute the effective scanning coverage area. The effective scan coverage area is stored as a coverage area configuration, which includes a list of covered targets, a list of associated channels, and coverage statistics. The effective scan coverage area is the actual executable target range for a scan task. The scheduler only issues scan tasks to targets within the effective scan coverage area to ensure that the task can be executed normally and return results.

[0049] Step S130: Perform delay distribution analysis on the effective scan coverage area to determine the low-latency window, transform the low-latency window into a priority scan area to form a preferred scan route, and generate a task allocation strategy along the preferred scan route.

[0050] In some embodiments, the step of performing delay distribution analysis on the effective scan coverage area to determine a low-latency window includes: identifying delay bottlenecks in the effective scan coverage area to generate high-latency isolation segments; evaluating transmission efficiency based on the high-latency isolation segments to form an efficiency evaluation index; performing delay interpolation using the efficiency evaluation index to generate a continuous delay distribution; and performing threshold filtering based on the continuous delay distribution to generate a low-latency window.

[0051] High-latency isolation segments are generated by identifying latency bottlenecks within the effective scan coverage area. The latency sampling sequences of each channel within the effective scan coverage area form the data basis for bottleneck location. Points with latency values ​​exceeding the average latency plus twice the standard deviation are marked as outliers. Outliers within the effective scan coverage area are clustered, grouping temporally or spatially adjacent outliers into the same cluster. The network path segment corresponding to each cluster is the latency bottleneck location. Bottlenecks typically occur at links across availability zones, cloud platform exits, or nodes sharing bandwidth contention. Each bottleneck location and its impact range within the effective scan coverage area is labeled as a high-latency isolation segment. A high-latency isolation segment is defined as a network path interval with persistently high latency that negatively impacts overall transmission performance. Its start and end nodes, average latency level, latency fluctuation amplitude, and bottleneck cause type are recorded. Bottleneck cause types include insufficient bandwidth, excessive routing hops, link congestion, and device processing latency. Due to public network links and multi-layer gateway forwarding, scanning nodes deployed across cloud platforms often form typical high-latency isolation segments, with latency between cross-platform nodes reaching tens of times that between nodes in the same region. In contrast, intranet connection latency between different availability zones within the same cloud platform is relatively stable and rarely forms high-latency isolation segments.

[0052] Efficiency evaluation indicators are formed based on transmission efficiency assessment using high-latency isolation sections. The distribution and severity of high-latency isolation sections are key factors in efficiency evaluation, and the path length of each channel through these sections directly affects transmission efficiency. The evaluation dimensions include three aspects: effective transmission rate, latency stability, and bottleneck impact. The effective transmission rate is the ratio of the channel's actual available bandwidth to its nominal bandwidth; latency stability is obtained by normalizing the latency variance, with a smaller variance indicating higher stability, and a value ranging from 0 to 1; bottleneck impact is the proportion of the channel's path length through high-latency isolation sections to its total path length. The three dimensions are weighted to obtain the efficiency evaluation value E = α × η + β × S - γ × I, where η is the effective transmission rate, S is the latency stability, I is the bottleneck impact, and α, β, and γ are weighting coefficients satisfying α + β + γ = 1. The comprehensive evaluation value is standardized to form the efficiency evaluation index for each channel, with the numerical range normalized to the zero-to-one interval. The efficiency evaluation indices of each channel are arranged in descending order to form an efficiency evaluation table, with the channels ranked higher exhibiting better transmission performance. Channels carrying deep vulnerability scanning tasks have high requirements for latency stability, and the stability weight β should be appropriately increased; channels carrying fast port detection tasks have high requirements for bandwidth utilization, and the effective transmission rate weight α should be appropriately increased.

[0053] A continuous delay distribution is generated through delay interpolation using efficiency evaluation metrics. Channels with high efficiency evaluation metrics typically correspond to lower transmission delays, showing a negative correlation. Delay sampling points are distributed at key nodes in each channel, with unsampled blank areas existing between nodes. An inverse distance weighting method is used to estimate the delay values ​​in these blank areas, with closer locations to sampling points being more significantly affected. Efficiency evaluation metrics are introduced as auxiliary variables during interpolation; when there are significant differences in efficiency evaluation metrics between adjacent sampling points, the interpolation result shifts towards the less efficient side to reflect potential delay increases. The entire coverage area is gridded, and interpolated delay values ​​are calculated at each grid intersection. The delay values ​​of all grid points are then integrated to form a continuous delay distribution. This continuous delay distribution is stored as raster data, with each grid cell recording the estimated delay value at its corresponding location, eliminating blank areas between sampling points. In cloud environments, node distribution is uneven; dense sampling in core areas results in high interpolation accuracy, while sparse sampling in edge areas necessitates the use of efficiency evaluation metrics for correction to improve estimation accuracy.

[0054] Low-latency windows are generated based on threshold filtering using a continuous latency distribution. The numerical range of the continuous latency distribution requires calculation of statistical quantiles. A percentile method is used to set the low-latency threshold, defining regions with latency values ​​below the 25th percentile as low-latency regions. The continuous latency distribution is then segmented by threshold; grid cells with latency values ​​below the threshold are marked as low-latency regions, while those above are marked as non-low-latency regions. Connectivity processing is performed on the marking results, grouping spatially adjacent cells that are all marked as low-latency into the same connected region, and removing fragmented regions that are too small to be of practical use. The filtered connected regions are defined as low-latency windows. Each low-latency window is independently numbered and its boundary range, coverage area, average latency within the region, and list of included nodes are recorded. Low-latency windows are the priority target areas for scanning tasks; distributing tasks to nodes within a low-latency window results in lower execution latency. Enterprise core data center deployment areas, due to their well-developed network infrastructure, typically form large low-latency windows, capable of supporting hundreds of concurrent scanning tasks simultaneously; low-latency windows in edge deployment areas are relatively dispersed and smaller in scale, with each window supporting only a few dozen concurrent tasks.

[0055] Low-latency windows are transformed into priority scan areas to form optimal scan routes. Each low-latency window requires scan value assessment, which considers the number of scan targets covered by the low-latency window, the processing capacity of nodes within the low-latency window, and the distance between the low-latency window and the scheduling center. Windows with more targets, stronger node processing capacity, and closer proximity to the scheduling center have higher scan value. Based on the scan value assessment results, low-latency windows are prioritized, with high-priority windows becoming priority scan areas. These areas inherit the boundary range and node list of the low-latency windows, while also gaining a priority label and scan capacity quota. Access routes are planned for each priority scan area, selecting the path with the fewest nodes and lowest cumulative latency while meeting bandwidth requirements. The priority scan areas and their access routes are integrated to form optimal scan routes, stored in a routing table. Each entry in the table corresponds to a priority scan area, and the entry content includes the area number, priority, access path, and path latency. Large-scale port scanning tasks targeting internet assets require high bandwidth support and should be prioritized for priority scan areas with strong node processing capacity; vulnerability verification tasks targeting internal network devices are latency-sensitive and should be prioritized for priority scan areas closest to the target network segment.

[0056] A task allocation strategy is generated along the preferred scan route. The queue of scan tasks awaiting allocation records each scan task and its attributes. The coverage area of ​​each priority scan region in the preferred scan route is used as the basis for task matching. The target address range of each task is matched with the coverage area of ​​each priority scan region in the preferred scan route. When a task's target falls within the coverage area of ​​a priority scan region, the task is marked as executable by that region. For tasks with multiple executable regions, the optimal region is selected as the allocation target based on the region priority in the preferred scan route. The resource requirements for each task are comprehensively estimated based on the number of targets, scan depth, and estimated execution time. The task's resource requirements are compared with the available capacity of the target region. If capacity is sufficient, the task is directly allocated; if capacity is insufficient, the task is split into multiple sub-tasks and allocated to multiple regions. A balance check is performed on the allocation results to avoid overloading some regions while other regions are idle. The allocation target, execution path, and resource quota of each task are integrated to form the task allocation strategy. The task allocation strategy configuration includes the mapping relationship between tasks and regions, the task execution order, and the resource allocation scheme. When enterprises initiate full-network vulnerability scanning during quarterly security audits, the task allocation strategy must incorporate execution time constraints into the scheduling rules to avoid scanning tasks affecting the normal operation of business systems. Vulnerability verification tasks in security incident response scenarios require immediate execution, and the task allocation strategy should assign such tasks the highest scheduling priority and reserve a dedicated execution channel.

[0057] Step S140: Decompose the task allocation strategy into core detection sequence and edge detection sequence. Perform elastic capacity analysis on the edge detection sequence to extract candidate node set. Perform resource aggregation on the candidate node set to form hot standby node cluster.

[0058] Specifically, the task allocation strategy is broken down into core probe sequences and edge probe sequences. The task allocation strategy records the allocation target and execution path of each scanning task. The location of the target area of ​​each task in the network topology is the classification basis. Tasks are classified according to the network conditions of the target area in the task allocation strategy. Tasks located in data center intranet segments, backbone network directly connected nodes, and high-bandwidth access areas are classified as core probe tasks, and are sorted by execution priority to form core probe sequences. Tasks in the core probe sequences have the characteristics of superior network conditions and high execution reliability. Tasks located at cross-cloud platform boundaries, remote branch nodes, and low-bandwidth access areas are classified as edge probe tasks, and are sorted by priority to form edge probe sequences. Tasks in the edge probe sequences face challenges such as unstable network conditions and a higher risk of execution failure. Core probe sequences and edge probe sequences are stored separately in the form of task lists, with list elements including task number, target address, allocation area, and priority label. When an enterprise initiates a scanning task for assets located in a remote branch office, due to the limited bandwidth and poor link stability of the branch network, the task is classified into the edge detection sequence and configured with a longer timeout threshold; for asset discovery tasks between data centers in the same city, due to the stable network conditions, the task is classified into the core detection sequence and can be configured with a higher scan rate.

[0059] Elastic capacity analysis is performed on edge probing sequences to extract candidate node sets. Tasks in the edge probing sequence may time out or fail due to network limitations, requiring the reservation of backup execution resources. The total resource requirements of the edge probing sequence are calculated, including computing resources, network bandwidth, and storage space. The task retry probability is estimated based on the historical failure rate of the edge network corresponding to the edge probing sequence. The backup resource requirement Rbackup = Rtotal × Pfail × k, where Rtotal is the total resource requirement of the edge probing sequence, Pfail is the historical failure rate, and k is a redundancy coefficient, typically ranging from 1.2 to 1.5. The ability of all scanning nodes within the effective scanning coverage area to undertake edge tasks is evaluated, with evaluation dimensions including the node's available resource balance, network connectivity between the node and the edge region, and the node's historical task execution success rate. The evaluation results are comprehensively scored, and nodes with scores higher than the admission threshold are included in the candidate node set. The candidate node set is stored as a node list, with each element containing the node number, node address, capability score, and available resource quantity. Agent nodes deployed at the network boundary are typically included in the candidate node set because they are connected to both internal and external networks and have a higher edge task carrying capacity score. Nodes located deep in the core area of ​​the internal network have a lower score and are less likely to be included in the candidate node set because they have poor connectivity with the edge area.

[0060] In some embodiments, the step of performing resource aggregation to form a hot standby node cluster for the candidate node set includes: constructing a node availability timeline based on the candidate node set; mapping load peak points through the node availability timeline to form peak period labels; dividing the node availability timeline into idle periods and busy periods using the peak period labels as boundaries; and comparing the resource distribution characteristics of the idle periods and the busy periods to form a hot standby node cluster.

[0061] A node availability timeline is constructed based on the candidate node set. Historical load data for each node in the candidate node set records its resource usage over past periods. Time alignment is performed on the load data of each node in the candidate node set, unifying the sampling times of different nodes to a standard time scale. The available resource quantity of each node at each time point equals the node's total resource capacity minus its current resource usage. The available resource quantities of each node in the candidate node set at each time point are arranged chronologically to form the available resource time series for that node. The available resource time series of all nodes in the candidate node set are arranged in parallel by node number, forming a multi-dimensional node availability timeline. The node availability timeline is stored in a two-dimensional matrix, with rows corresponding to node numbers, columns corresponding to time scales, and matrix elements representing the available resource quantity of the corresponding node at the corresponding time point. Nodes undertaking scheduled batch scanning tasks experience a sharp increase in resource occupancy during fixed daily periods, resulting in a clear periodic fluctuation in the node availability timeline; while nodes undertaking real-time response tasks have relatively stable loads, with smaller fluctuations in the node availability timeline.

[0062] Peak period labels are generated by mapping load peak points to a node availability timeline. The node availability timeline is aggregated column-wise, summing the available resource quantities of all nodes at each time point to obtain the total available resource sequence of the cluster. Local minima are identified in the aggregated sequence of the node availability timeline; these local minima correspond to the time when the overall available resources of the cluster are at their lowest, i.e., when the load is highest. Significance filtering is performed on the identified local minima, retaining those with resource decreases exceeding a set percentage, and removing noise points with small fluctuations. Each significant minima is marked as a load peak point, and the occurrence time of the peak point and the corresponding cluster available resource quantity are recorded. Clustering detection is performed on the temporal distribution of load peak points, generating peak period labels for the time intervals where peak points occur in clusters. Peak period labels record the start and end times of the period, the number of peak points included, and the average available resource quantity within the period. Enterprises typically perform intranet scanning tasks concentrated between 9:00 AM and 11:00 AM on weekdays, during which peak period labels are densely distributed; between 2:00 AM and 5:00 AM, the business system load is lowest, and peak period labels are sparsely distributed or even blank.

[0063] The available timeline of nodes is divided into idle periods and busy periods, using peak period labels as boundaries. The start and end times of each peak period recorded in the peak period labels serve as the dividing boundaries on the timeline, segmenting the available timeline along the time dimension. The portion of the available timeline falling within the peak period label interval is classified as a busy period, while the portion falling outside is classified as an idle period. Continuity processing is applied to the segmentation results, merging adjacent periods of the same type into longer period segments to avoid excessive fragmentation. Statistical characteristics are calculated for each idle and busy period, including period duration, average available resources within the period, resource fluctuation amplitude within the period, and resource distribution uniformity of each node within the period. During idle periods, the overall cluster load is low, and each node has ample remaining resources available for hot standby; during busy periods, the cluster load is high, and hot standby resources are limited and require careful allocation. For multi-cloud scanning clusters deployed in different regions, since peak business periods in each region are staggered, continuous coverage of idle periods can be achieved through regional rotation, ensuring sufficient hot standby resources are available at any time.

[0064] For example, the step of comparing the resource distribution characteristics of the idle period and the busy period to form a hot standby node cluster includes: converting the load sequence of the idle period into a resource accumulation sequence; offsetting and merging the load sequence of the busy period into the resource accumulation sequence to form a resource difference map; extracting the resource fluctuation accumulation amount in the resource difference map; and forming a hot standby node cluster according to the distribution intensity of the resource fluctuation accumulation amount.

[0065] The load sequence during idle periods is converted into a resource accumulation sequence. The available resource time series of each node within each idle period undergoes cumulative transformation processing, using a prefix sum calculation method to replace the resource value at each moment in the sequence with the sum of the resource values ​​at that moment and all previous moments. The sequence after cumulative transformation during idle periods reflects the continuous accumulation effect of resource availability; a larger slope of the cumulative value growth indicates more abundant resources during that idle period. The cumulative transformation results of each node within the idle period are normalized to eliminate the impact of differences in resource capacity between nodes. The normalized cumulative sequences of all nodes are integrated to form a resource accumulation sequence, stored in matrix form, with rows corresponding to nodes, columns corresponding to moments, and element values ​​being the normalized cumulative resource amount. The slope of the resource accumulation sequence curve reflects the resource release rate of each node within the idle period. Reserved nodes dedicated to hot standby tasks have a near-constant slope in the resource accumulation sequence, while the slope of shared nodes undertaking multiple types of tasks fluctuates with task scheduling.

[0066] The load sequence offsets of busy periods are merged into the resource accumulation sequence to form a resource difference map. The available resource time series of each node within each busy period also undergoes cumulative transformation processing. The cumulative sequence of the busy period is time-shifted, aligning its start time to the start time of the corresponding resource accumulation sequence, achieving overlap and comparison between busy and idle periods on the time axis. The difference between the resource accumulation sequence value of the same node at the same time after alignment and the cumulative value of the busy period is calculated. This difference reflects the difference in resource supply for the node under the two load states. The differences of each node at each time point are integrated to form a resource difference map, which is stored in the form of a two-dimensional matrix. Positive values ​​in the resource difference map indicate that the idle period resources of the node are better than those in the busy period at that time, while negative values ​​indicate that the busy period resources are better. Cloud nodes configured with elastic scaling strategies can automatically expand to obtain more computing resources during peak business periods, and negative values ​​may appear in the resource difference map where the resources of the busy period exceed those of the idle period; while fixed-configuration physical server nodes show a stable positive value distribution in the resource difference map.

[0067] The cumulative resource fluctuation is extracted from the resource variance map. The resource variance map is statistically analyzed by node dimension. The absolute values ​​of the variances of each node in the resource variance map are summed over the entire time span. The sum represents the total resource fluctuation of that node; a larger total fluctuation indicates a more significant impact of the load cycle on the node's resource status. The positive cumulative value is obtained by summing the positive values ​​of the variances in the resource variance map, representing the cumulative resource advantage during idle periods relative to busy periods. A larger value indicates a stronger hot standby supply capacity of the node during idle periods. The total fluctuation and positive cumulative value of each node are integrated to form the cumulative resource fluctuation. The cumulative resource fluctuation is stored in a node attribute table, where each row corresponds to a node, and the columns include node number, total fluctuation, positive cumulative value, and negative cumulative value. The cumulative resource fluctuation quantitatively describes the resource elasticity characteristics of each candidate node. The positive cumulative value of dedicated hot standby nodes is significantly higher than that of shared nodes in the cumulative resource fluctuation, making them suitable as core members of the hot standby cluster.

[0068] Hot standby node clusters are constructed based on the distribution intensity of accumulated resource fluctuations. The positive cumulative value of each node in the accumulated resource fluctuations is a quantitative indicator of hot standby capability, and the nodes are sorted according to their positive cumulative value. A hot standby capability admission threshold is set, and nodes with positive cumulative values ​​exceeding the threshold are included in the hot standby candidate range. The hot standby candidate nodes are clustered based on factors including the node's network topology location, resource type composition, and available time period distribution. Nodes with similar network locations are grouped into the same cluster to reduce intra-cluster communication latency; nodes with complementary resource types are grouped into the same cluster to improve the overall task adaptability of the cluster; and nodes with overlapping available time periods are grouped into the same cluster to ensure the cluster's continuous service capability. Capacity assessment is performed on each cluster, and the total cluster capacity must not be less than the backup resource requirement Rbackup to ensure the hot standby requirements of the edge detection sequence. Each cluster is defined as a hot standby node cluster, and the hot standby node cluster records the cluster number, member node list, total cluster capacity, cluster service time period, and cluster activation conditions. Multiple virtual nodes deployed on the same physical rack should be distributed to different hot standby node clusters to avoid single point of failure causing the entire cluster to fail. Nodes that are geographically dispersed but have controllable network latency can be combined into hot standby node clusters to achieve higher disaster recovery capabilities.

[0069] Step S150: Implement anomaly monitoring for the core detection sequence to obtain node disconnection signals. Based on the node disconnection signals, select corresponding nodes from the hot standby node cluster to form a takeover node link. Seamlessly connect the takeover node link with the core detection sequence to generate a collaborative scanning grid.

[0070] Specifically, anomaly monitoring is implemented for the core probe sequence to obtain node disconnection signals. Each scanning task in the core probe sequence is assigned to a node in the core network region for execution. During the execution of the core probe sequence, the scheduler continuously monitors the running status of each node. The monitoring method employs a heartbeat detection mechanism. Each execution node corresponding to the core probe sequence sends a heartbeat message to the scheduler at a fixed interval, set to 5 seconds. The scheduler maintains the heartbeat reception record for each node. When no heartbeat message is received from a node for three consecutive heartbeat cycles, the node is determined to be in a disconnected state. A node disconnection signal is generated for the disconnected node, including the node number, the time of disconnection, the last heartbeat time before disconnection, and the list of tasks currently being carried by the disconnected node. After the node disconnection signal is triggered, a disconnection confirmation process is initiated. The scheduler sends an active probe message to the disconnected node for secondary confirmation. If there is still no response to the probe message within a set timeout period, the disconnection status is confirmed. Nodes confirmed to be disconnected are marked with a disconnection type, including network interruption, process crash, resource exhaustion, and hardware failure. Nodes undertaking large-scale port scanning tasks may crash due to excessive concurrent connections, triggering the operating system's connection limit. Such disconnections can usually be quickly recovered by restarting the process. However, network interruption-type disconnections caused by physical network card failures require migrating the task to other nodes for execution.

[0071] In some embodiments, the step of selecting a corresponding node from the hot standby node cluster to form a takeover node link based on the node disconnection signal includes: determining the upstream task dependency relationship of the disconnected node based on the node disconnection signal; performing topology proximity screening in the hot standby node cluster based on the upstream task dependency relationship to form candidate takeover nodes; performing hop count-latency joint sorting on the candidate takeover nodes to determine the takeover priority; and connecting the candidate takeover nodes in series step by step according to the takeover priority to form a takeover node link.

[0072] The upstream task dependencies of a lost node are determined based on its disconnection signal. The disconnection signal records the list of tasks currently being handled by the lost node, and each task in the signal has data transfer or execution order dependencies with other tasks in its execution flow. The task list in the disconnection signal is traversed, and for each task, its upstream dependent tasks are traced. Upstream dependent tasks are those preceding tasks whose execution results serve as input to the current task. The upstream dependent tasks and their execution nodes are recorded, forming the upstream task dependencies of the lost node. The upstream task dependencies are represented in a directed graph, where nodes are task numbers, directed edges represent dependency directions, and the starting point of an edge is an upstream task, and the ending point is a downstream task. A depth-first traversal is performed on the upstream task dependency graph to identify all direct and indirect upstream task nodes. The takeover node needs to establish a data channel with the upstream nodes in the upstream task dependencies to receive the output results of preceding tasks; therefore, the selection of the takeover node must consider network connectivity with the upstream nodes. In a distributed vulnerability scanning scenario, the results of port probing tasks serve as input for service identification tasks, and the results of service identification tasks serve as input for vulnerability detection tasks. These three tasks form a chain-like upstream task dependency relationship. When a service identification node becomes disconnected, the takeover node must be able to receive port probing results and output them to the vulnerability detection node.

[0073] In the hot standby node cluster, candidate takeover nodes are selected based on topology proximity according to upstream task dependencies. Each node in the hot standby node cluster has the resource capability to take over the tasks of the lost node. The node with the closest topological distance to the upstream dependent nodes of the lost node is selected as the takeover candidate. Topological distance is measured by network hop count; the fewer the hop count, the shorter the network path and the higher the communication efficiency between the two nodes. The hop count between each node in the hot standby node cluster and each upstream node in its upstream task dependency relationship is calculated, and the maximum hop count is taken as the topological distance index of that hot standby node. A topological distance threshold is set, and hot standby nodes with a topological distance less than the threshold are included in the candidate takeover node set. The actual connectivity between the candidate takeover nodes and each upstream node in their upstream task dependency relationship is verified. Test messages are sent to confirm that the network path is unobstructed, and nodes that fail the connectivity verification are removed. Candidate takeover nodes are stored in the form of a node list, and the list elements include node number, topological distance, available resources, and connectivity verification result. Hot standby nodes within the same availability zone share the local area network with the disconnected node, and the topological distance is usually only one or two hops, so they are given priority to be included as candidate takeover nodes; hot standby nodes across availability zones have a larger topological distance and are only used as a supplement when there are not enough candidate takeover nodes in the same area.

[0074] Candidate takeover nodes are ranked using a hop count-latency joint sorting method to determine takeover priority. Sorting solely based on hop count may ignore actual network latency differences; candidate takeover nodes with the same hop count may have latency differences of several times due to varying link quality. The actual round-trip latency between each candidate takeover node and its upstream dependent nodes is measured. Latency measurements are performed using multiple probes and averaged to eliminate the impact of instantaneous fluctuations. Hop count and latency are jointly scored: Score P = W1 × H + W2 × D, where H is the normalized hop count, D is the normalized latency, and W1 and W2 are weighting coefficients, with W1 + W2 = 1. Normalization maps hop count and latency to the zero-to-one range, eliminating dimensional differences. A lower score indicates a stronger takeover capability for the candidate node. Candidate takeover nodes are ranked in ascending order of score to form a takeover priority sequence. For real-time scanning tasks with extremely high timeliness requirements, the latency weight W2 should be appropriately increased to prioritize low-latency nodes; for bandwidth-sensitive high-volume scanning tasks, the hop count weight W1 should be appropriately increased to reduce intermediate routing overhead. The takeover priority sequence guides the order in which subsequent nodes are selected for takeover, with nodes having higher takeover priority being selected first to perform the takeover task.

[0075] Candidate takeover nodes are sequentially connected in series according to takeover priority to form a takeover node link. Candidate takeover nodes are selected in descending order of takeover priority, with the first selected candidate taking over as the primary takeover node, directly undertaking all tasks from the lost node. The resource capacity of the primary takeover node is assessed to determine if it is sufficient to handle the workload of the lost node. If the primary takeover node's capacity is insufficient, the next candidate takeover node is selected as an auxiliary takeover node according to takeover priority. The tasks of the lost node are split according to resource requirements, with the primary takeover node handling the core tasks with higher resource requirements, and the auxiliary takeover nodes handling the remaining tasks. A data synchronization channel is established between the primary takeover node and each auxiliary takeover node to transmit intermediate results and status information during task execution. The primary takeover node, each auxiliary takeover node, and their interconnection channels are integrated to form a takeover node link. The takeover node link is organized in a chain topology, with the primary takeover node at the head of the chain responsible for connecting with upstream nodes, and each auxiliary takeover node sequentially connected in series to distribute the workload. The takeover node link records the link number, member node sequence, inter-node channel configuration, and total link capacity. For nodes that have lost connectivity and are carrying out critical business scanning tasks, the takeover node link is typically configured with dual primary takeover nodes for hot standby of each other to ensure the high availability of the takeover node link itself.

[0076] In some embodiments, the step of seamlessly connecting the takeover node link with the core detection sequence to generate a collaborative scanning grid includes: converting the takeover node link into a node capability map; locating a balancing reference point in the node capability map; taking over the core detection sequence from the balancing reference point to form a preliminary takeover domain; and locking the boundaries of the preliminary takeover domain to generate a collaborative scanning grid.

[0077] The takeover node link is converted into a node capability map. Each member node in the takeover node link has different resource configurations and processing capabilities. The capability characteristics of each node in the takeover node link are quantified to form a unified capability description format. The capability dimensions include four aspects: computing power, network bandwidth, storage capacity, and concurrent connections. Normalized values ​​are used to represent the relative capability level of a node in each dimension. The four-dimensional capability vector of each node in the takeover node link is plotted as a radar chart, with each node corresponding to an independent radar chart. The radar charts of all nodes in the takeover node link are arranged in the link topology order to form a node capability map. The node capability map visually displays the capability distribution characteristics of each node in the link. Links with balanced capabilities have similar radar chart shapes, while links with significant capability differences show obvious differences in the shapes of the radar charts of each node. The overall capability mean and capability variance of the link are calculated for the node capability map. The mean reflects the average processing capability of the link, and the variance reflects the degree of capability difference between nodes in the link. The node capability map of a takeover node link composed of a mixture of high-performance physical servers and ordinary virtual machines exhibits obvious capability stratification characteristics. High-performance nodes are suitable for carrying computationally intensive tasks, while ordinary nodes are suitable for carrying lightweight tasks.

[0078] Locate the equilibrium benchmark point in the node capability map. The capability vectors of each node in the node capability map constitute a set of points in a multi-dimensional space. The benchmark position that balances the capability differences among the nodes is found within this set. The equilibrium benchmark point is defined as the position that minimizes the variance of the capability distance from each node to the benchmark point. It is calculated using the geometric center method, and the coordinates of the equilibrium benchmark point are equal to the arithmetic mean of the capability vectors of each node in the node capability map. The equilibrium benchmark point represents the overall capability level of the takeover node's link. Task allocation based on the equilibrium benchmark point can achieve relative load balancing among the nodes. Calculate the values ​​of the equilibrium benchmark point in each capability dimension. Higher values ​​indicate a capability advantage in that dimension, while lower values ​​indicate a capability weakness. Record the coordinates and values ​​of each dimension of the equilibrium benchmark point as a capability matching reference for subsequent task assignments. When the task assigned to the takeover node's link has high requirements for a certain capability dimension, and the equilibrium benchmark point happens to be a link weakness in that dimension, it is necessary to consider supplementing the link with nodes from other hot standby node clusters that excel in that dimension to enhance the overall carrying capacity of the link.

[0079] Starting from the equilibrium benchmark point, a preliminary takeover domain is formed by task transfer within the core detection sequence. Tasks originally carried by lost nodes in the core detection sequence need to be migrated to the takeover node's link for execution. The task migration of the core detection sequence is matched based on the capability characteristics of the equilibrium benchmark point. The resource requirement vector for each task of lost nodes in the core detection sequence is calculated, and the resource requirement vector and capability vector use the same four-dimensional representation. The matching degree between the resource requirement vector of each task in the core detection sequence and the equilibrium benchmark point is calculated. Where Rtask is the task resource requirement vector, and Pbase is the coordinate of the equilibrium baseline point. This represents the vector magnitude. A higher matching degree indicates a better match between the task and the link capacity, and tasks with higher matching degrees are prioritized. Tasks in the core detection sequence are assigned to takeover node links in descending order of matching degree. The assignment is dynamically adjusted based on the remaining capacity of each node, forming an initial takeover domain. The initial takeover domain includes the set of tasks that have been assigned, the execution node mapping for each task, and the maintenance of dependencies between tasks. Large-scale asset discovery tasks have high network bandwidth requirements due to the massive number of IP address probes. When the bandwidth dimension value of the balancing benchmark is low, the matching degree of such tasks is low, and they may be delayed or split into multiple nodes for parallel execution.

[0080] A collaborative scanning mesh is generated by boundary locking of the initial takeover domain. Task assignments within the initial takeover domain may have ambiguous boundaries, and the execution results of some tasks within the initial takeover domain need to be shared across nodes; therefore, the data exchange boundaries between nodes need to be clearly defined. Task dependencies within the initial takeover domain are analyzed to identify task pairs with cross-node data transfer. Dedicated data channels are established between the source and target nodes for data transfer, with channel configurations including transmission protocols, bandwidth quotas, and timeout thresholds. The task execution scope of each node, the data channels between nodes, and the data exchange protocols are integrated to form a clearly defined collaborative scanning mesh. The collaborative scanning mesh is organized in a mesh topology, with mesh nodes as execution nodes, mesh edges as data channels between nodes, and mesh cells as independent task execution domains. The collaborative scanning mesh is verified for integrity, confirming that all tasks have been assigned execution nodes, all dependencies have corresponding data channels, and all channels have completed connectivity testing. The collaborative scanning mesh records the mesh number, node list, channel configuration, and task distribution for subsequent feedback topology construction. Enterprises deploying collaborative scanning meshes across multiple data centers may cross the boundaries of different network regions. Cross-regional data channels need to be configured with encrypted transmission and access authentication to meet data security requirements.

[0081] Step S160: Build a node feedback topology based on the collaborative scanning mesh, and perform time delay calibration analysis on the node feedback topology to generate distributed scanning commands.

[0082] Specifically, a node feedback topology is built based on the collaborative scanning grid. The collaborative scanning grid defines the task distribution of each execution node and the data channel configuration between nodes. A feedback network for aggregating task execution results is constructed on the basis of the collaborative scanning grid. A result reporting channel is configured for each execution node within the collaborative scanning grid, transmitting the node's task execution results to the result aggregation node. The result aggregation node is responsible for receiving and integrating the reported data from each execution node in the collaborative scanning grid. The selection of the aggregation node is based on the centrality of the network location and the sufficiency of processing capacity. For larger collaborative scanning grids, a hierarchical aggregation architecture is adopted, setting up multiple regional aggregation nodes to be responsible for collecting the results from execution nodes within their respective regions. The regional aggregation nodes then report to the central aggregation node. A hierarchical feedback channel is established between the execution nodes, regional aggregation nodes, and the central aggregation node, forming a node feedback topology. The node feedback topology is organized in a tree structure, with leaf nodes being execution nodes, intermediate nodes being regional aggregation nodes, and the root node being the central aggregation node. A flow control mechanism is configured for the node feedback topology. When the flow received by a aggregation node exceeds its processing capacity, a backpressure signal is triggered, notifying downstream nodes to reduce their reporting rate. Enterprises deploy scanning clusters in multiple data centers. Due to the limited bandwidth of network exits in each region, the cross-regional reporting channels for node feedback topology need to be configured with bandwidth reservations to ensure timely transmission of result data.

[0083] Delay calibration analysis is performed on the node feedback topology to generate distributed scan commands. Due to their different network locations, the transmission delay from the execution node to the aggregation node varies among nodes in the node feedback topology. The actual transmission delay of each feedback channel within the node feedback topology is measured, covering the entire link from data transmission at the execution node to acknowledgment at the aggregation node. The feedback delays of each execution node in the node feedback topology are statistically analyzed to identify abnormal channels with significantly high delays. These abnormal channels are diagnosed and located to determine whether the high delay is caused by link congestion, bottlenecks in intermediate nodes, or excessive physical distance. Based on the delay diagnosis results, the node feedback topology is optimized and adjusted: bandwidth quotas are increased for congested links, load balancing is implemented for bottleneck nodes, and aggregation assignments are adjusted for nodes that are too far away. After delay calibration, the feedback delays of each execution node in the node feedback topology tend to be balanced, ensuring that the scan results of each node can be synchronously aggregated. Distributed scan commands are generated based on the calibrated node feedback topology. The distributed scan commands include the task parameters of each execution node, execution sequence, result reporting format, and reporting target node. Distributed scan commands are distributed to each execution node in the form of command packets, which are digitally signed to ensure they are not tampered with during transmission. For compliance scans of internal network assets, distributed scan commands must include scan authorization credentials and audit log configurations to ensure that scan activities are traceable and auditable.

[0084] To implement the above method embodiments, a distributed network scanning method based on multiple cloud nodes is proposed to achieve the corresponding functions and technical effects. See also... Figure 2 , Figure 2 This diagram illustrates a structural block diagram of a distributed network scanning system 200 based on multiple cloud nodes according to an embodiment of this application. For ease of explanation, only the parts relevant to this embodiment are shown. The distributed network scanning system 200 based on multiple cloud nodes provided in this embodiment includes:

[0085] The state awareness module 201 is used to acquire the network state parameters and node load signals of each scanning node in a multi-cloud environment, divide the available domain based on the network state parameters to generate a scanning reference threshold, and form a dynamic scheduling loop based on the scanning reference threshold and the node load signal.

[0086] The path reorganization module 202 is used to perform scan path reorganization processing according to the dynamic scheduling loop to form an enhanced detection channel, and to detect network blind spot nodes by means of the enhanced detection channel, and to build an effective scan coverage area by avoiding the network blind spot nodes.

[0087] The latency analysis module 203 is used to perform latency distribution analysis on the effective scanning coverage area to determine the low latency window, convert the low latency window into a priority scanning area to form a preferred scanning route, and generate a task allocation strategy along the preferred scanning route.

[0088] Task allocation module 204 is used to decompose the task allocation strategy into core detection sequence and edge detection sequence, perform elastic capacity analysis to extract candidate node set for the edge detection sequence, and perform resource aggregation to form hot standby node cluster for the candidate node set;

[0089] The fault takeover module 205 is used to perform abnormal monitoring to obtain node disconnection signals for the core detection sequence, extract corresponding nodes from the hot standby node cluster to form a takeover node link based on the node disconnection signal, and seamlessly connect the takeover node link with the core detection sequence to generate a collaborative scanning grid.

[0090] The instruction output module 206 is used to build a node feedback topology based on the collaborative scanning grid, and to perform time delay calibration analysis on the node feedback topology to generate distributed scanning instructions.

[0091] The aforementioned distributed network scanning system 200 based on multi-cloud nodes can implement one of the distributed network scanning methods based on multi-cloud nodes described in the above method embodiments. The options in the above method embodiments are also applicable to this embodiment and will not be detailed here. The remaining content of this application's embodiments can be referred to the content of the above method embodiments, and will not be repeated in this embodiment.

[0092] The above embodiments are not an exhaustive list based on the present invention, and there may be many other embodiments not listed. Any substitutions and improvements made without departing from the concept of the present invention are within the protection scope of the present invention.

Claims

1. A multi-cloud node based distributed network scanning method, characterized in that, The method comprises the following steps: obtaining network state parameters and node load signals of each scanning node in a multi-cloud environment, and performing available domain division on the network state parameters to generate a scanning reference threshold, including: performing available domain division and level evaluation on the network state parameters, setting task distribution constraint conditions for each level available domain, integrating the level division results of each available domain and the task distribution constraint conditions to form a scanning reference threshold, and constructing a dynamic scheduling loop according to the scanning reference threshold and the node load signal, including: generating a threshold fluctuation band according to the scanning reference threshold; associating the node load signal and the threshold fluctuation band to form a load-threshold coupling characteristic; extracting a smooth scheduling interval in the load-threshold coupling characteristic; and constructing a dynamic scheduling loop based on the scheduling weight of the smooth scheduling interval; implementing scanning path reorganization processing according to the dynamic scheduling loop to form an enhanced detection channel, detecting network blind area nodes by means of the enhanced detection channel, and building an effective scanning coverage domain by avoiding the network blind area nodes; implementing delay distribution analysis on the effective scanning coverage domain to determine a low-delay window, converting the low-delay window into a priority scanning area to form an optimal scanning route, and generating a task allocation strategy along the optimal scanning route; decomposing the task allocation strategy into a core detection sequence and an edge detection sequence, implementing elastic capacity analysis on the edge detection sequence to extract a candidate node set, and implementing resource aggregation on the candidate node set to form a hot standby node cluster; implementing abnormality monitoring on the core detection sequence to obtain a node disconnection signal, and constructing a takeover node link by adjusting corresponding nodes from the hot standby node cluster according to the node disconnection signal to form a cooperative scanning grid; constructing a node feedback topology according to the cooperative scanning grid, and implementing time delay calibration analysis on the node feedback topology to generate a distributed scanning instruction.

2. The method of claim 1, wherein, The method comprises the following steps: dividing the enhanced detection channel into a main detection section and a slave detection section; initiating a forward connectivity detection path from the main detection section to the slave detection section, and simultaneously initiating a reverse connectivity detection path from the slave detection section to the main detection section; comparing the response differences of the forward connectivity detection path and the reverse connectivity detection path to form a bidirectional breakpoint list; marking the points with missing bidirectional responses in the bidirectional breakpoint list as network blind area nodes.

3. The method of claim 1, wherein, The method comprises the following steps: locating and identifying a high-delay isolation section by performing time delay bottleneck positioning on the effective scanning coverage domain; forming an efficiency evaluation index by performing transmission efficiency evaluation on the high-delay isolation section; generating a continuous delay distribution by performing delay interpolation through the efficiency evaluation index; generating a low-delay window based on the continuous delay distribution.

4. The method of claim 1, wherein, The method comprises the following steps: constructing a node available time axis according to the candidate node set; mapping a load peak point on the node available time axis to form a peak time period label; splitting the node available time axis into an idle period and a busy period according to the peak time period label; comparing resource distribution characteristics of the idle period and the busy period to form a hot standby node cluster.

5. The method of claim 1, wherein, the seamless connection of the takeover node link and the core detection sequence to form a collaborative scanning grid, comprising: converting the takeover node link into a node capability map; locating a balance reference point in the node capability map; task acceptance of the core detection sequence from the balance reference point to form a preliminary takeover domain; boundary locking of the preliminary takeover domain to form a collaborative scanning grid.

6. The method of claim 1, wherein, the corresponding node from the hot standby node cluster according to the node disconnection signal to form a takeover node link, comprising: determining the upstream task dependency relationship of the disconnection node according to the node disconnection signal; topologically near filtering in the hot standby node cluster according to the upstream task dependency relationship to form a candidate takeover node; joint sorting of hop count and delay of the candidate takeover node to determine the takeover priority; According to the takeover priority, the candidate takeover node is connected in stages to form a takeover node link.

7. The method of claim 2, wherein, comparing the response differences of the forward connectivity detection path and the reverse connectivity detection path to form a bidirectional breakpoint list, comprising: According to the forward connectivity detection path and the reverse connectivity detection path, identify the response mutation characteristics to determine the detection window; Tracking the response change process along the detection window to form a response trajectory graph; Extracting the node coordinates of each breakpoint in the response trajectory graph; According to the node coordinates, arrange the generation of the bidirectional breakpoint list according to the interruption degree.

8. The method of claim 4, wherein, comparing the resource distribution characteristics of the idle period and the busy period to form a hot standby node cluster, comprising: Convert the load sequence of the idle period into a resource accumulation sequence; Offset and combine the load sequence of the busy period to the resource accumulation sequence to form a resource difference graph; Extracting the resource fluctuation accumulation in the resource difference graph; According to the distribution intensity of the resource fluctuation accumulation, a hot standby node cluster is formed.

9. A multi-cloud node based distributed network scanning system, characterized in that, comprising: The state perception module is used for acquiring the network state parameters and node load signals of each scanning node in the multi-cloud environment, dividing the available domain according to the network state parameters to generate a scanning reference threshold, comprising: dividing and grading the available domain according to the network state parameters, setting the task distribution constraint conditions of each level available domain, integrating the level division results and task distribution constraint conditions of each available domain to form a scanning reference threshold, and constructing a dynamic scheduling loop according to the scanning reference threshold and the node load signal, comprising: generating a threshold fluctuation band according to the scanning reference threshold; Associated processing of the node load signal and the threshold fluctuation band to form a load-threshold coupling characteristic; Extracting the smooth scheduling interval in the load-threshold coupling characteristic; Based on the scheduling weight of the smooth scheduling interval, a dynamic scheduling loop is formed. A path reorganization module is configured to implement a scanning path reorganization process according to the dynamic scheduling loop to form an enhanced detection channel, detect a network blind area node by means of the enhanced detection channel, and build an effective scanning coverage domain by avoiding the network blind area node; A delay analysis module is configured to implement a delay distribution analysis on the effective scanning coverage domain to determine a low-delay window, convert the low-delay window into a priority scanning area to form an optimal scanning route, and generate a task allocation strategy along the optimal scanning route; A task allocation module is configured to decompose the task allocation strategy into a core detection sequence and an edge detection sequence, implement an elastic capacity analysis on the edge detection sequence to extract a candidate node set, implement resource aggregation on the candidate node set to form a hot-standby node cluster; A fault takeover module is configured to implement an abnormality monitoring on the core detection sequence to obtain a node disconnection signal, extract a corresponding node from the hot-standby node cluster according to the node disconnection signal to form a takeover node link, implement seamless connection between the takeover node link and the core detection sequence to generate a cooperative scanning grid; An instruction output module is configured to build a node feedback topology according to the cooperative scanning grid, and implement a time delay calibration analysis on the node feedback topology to generate a distributed scanning instruction.

Citation Information

Patent Citations

  • Network version digital ocean ball public application and development integration method and system

    CN120282108A

  • Edge collaborative point cloud data modeling and building design collaborative management method and system, electronic equipment and storage medium

    CN121030883A