Risk awareness and security verification method based on end network

By connecting the Wind Chime system to the core switch of the enterprise network and using Trunk and BAS technologies to dynamically deploy a virtual IP probe network, the problems of high cost, difficult deployment, and blind spots in network security risk perception are solved, achieving full network coverage, lossless monitoring, and security policy verification.

CN121887447APending Publication Date: 2026-04-17HANGZHOU MOTANNI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
HANGZHOU MOTANNI TECH CO LTD
Filing Date
2025-12-10
Publication Date
2026-04-17

AI Technical Summary

Technical Problem

Existing technologies for network security risk perception suffer from problems such as high cost, difficult deployment, blind spots, and inability to effectively verify the effectiveness of internal security policies, thus failing to achieve full network coverage and lossless monitoring.

Method used

By connecting the Wind Chime system to the core switch of the enterprise network, using Trunk technology to monitor and manage VLAN subnets, dynamically deploying lightweight agents, forming a virtual IP probe network, performing full port scanning and multi-protocol interaction simulation, and combining BAS technology for security policy verification, the system achieves coverage awareness and closed-loop verification at the network end.

Benefits of technology

It achieves full network coverage and lossless monitoring, reduces implementation costs, has high flexibility and deep risk perception capabilities, can quantitatively verify the effectiveness of security strategies, and covers the blind spots of traditional methods.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121887447A_ABST
    Figure CN121887447A_ABST
Patent Text Reader

Abstract

The invention discloses a risk awareness and security verification method based on an end network, and the method comprises the following steps: data collection and preprocessing, data encryption, data distribution, differential privacy protection, and security multi-party computation.The technical scheme has wide application prospects in the technical field of data analysis, the technical field of privacy protection, and the technical field of computing. The method not only can be applied to the fields of marketing, financial analysis, medical diagnosis, social science research and the like, but also can be applied to other scenes needing data analysis and privacy protection, such as intelligent cities, intelligent transportation, intelligent medical treatment and the like.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security technology, and in particular to a system and method for achieving end-point risk perception and security verification by dynamically occupying idle network resources. Background Technology

[0002] Currently, enterprises primarily rely on the following technical means to perceive cybersecurity risks: 1. Periodic Vulnerability and Asset Scanning: This method uses vulnerability scanners to periodically scan known assets within the network to discover security vulnerabilities. The shortcomings of this method are: first, the scanning behavior is clearly periodic, making continuous and real-time risk monitoring impossible; second, proactive scanning generates significant network traffic, potentially interfering with normal business systems; and third, this method has blind spots in scanning "shadow assets" or temporary devices not registered in the asset inventory.

[0003] 2. Physical Probe Deployment: Deploying dedicated hardware probe devices at key network nodes or aggregation layers to detect abnormal behavior through traffic mirroring or analysis. The disadvantages of this method are: high hardware costs, complex deployment and maintenance, and the need to modify the existing network architecture, resulting in poor flexibility. Furthermore, its coverage is limited by the deployment location, making it difficult to achieve comprehensive awareness of the network's periphery.

[0004] 3. Terminal Agent Installation: Install agent software on terminals such as servers and PCs to collect asset information and monitor host behavior. The main problem with this method is that the deployment and management costs are extremely high, requiring installation and upgrades on every single device; for devices where agents cannot be installed, such as network devices, Internet of Things (IoT) devices, and printers, monitoring gaps are created, making it impossible to achieve full coverage of network assets.

[0005] In summary, existing technologies generally suffer from technical problems such as high cost, difficult deployment, blind spots in perception, and inability to effectively verify the effectiveness of internal security policies. There is an urgent need for a new network risk perception method that can comprehensively, non-destructively, economically, and proactively verify the effectiveness of security. Summary of the Invention

[0006] The purpose of this invention is to provide a method based on end-network risk perception and security verification to solve the above-mentioned problems: To achieve the above objectives, the present invention provides the following technical solution: A method for end-network risk perception and security verification, comprising the following steps: S1. By connecting the wind chime system to the core switch of the enterprise network, the trunk technology is used to monitor and manage multiple downstream VLAN subnets, and the idle IP addresses in each subnet are identified through intelligent scanning. S2. Based on the identified idle IP addresses, a lightweight agent is dynamically deployed in the containerized environment to form a virtual IP probe network distributed across various VLANs, thereby achieving coverage awareness at the network endpoint. S3. The Agent performs full port scanning and multi-protocol interaction simulation to identify the target host's port opening status, service type, protocol behavior and potential security risks, and realizes real-time perception of abnormal states such as lateral movement paths, weak passwords and unauthorized services. S4. The virtual IP probe further performs active and non-destructive asset mapping, including but not limited to detecting live hosts in the network through ICMP, TCP SYN and other protocol packets, and collecting information such as operating system, hostname, and service fingerprint; S5. The system uses BAS technology to schedule probes in different areas to launch mutual simulated attack behaviors, evaluate the effectiveness and bypassability of protection strategies between different security domains, and thus form a closed-loop verification mechanism for network security status.

[0007] Preferably, in step S1, after the wind chime system is connected to the trunk port of the core switch, it uses VLAN tags to logically isolate different VLANs and monitor traffic. The system adopts a multi-threaded concurrent scanning method to perform ARP identification and Ping detection dual mechanisms for each subnet to confirm idle IPs, thereby avoiding conflicts with in-use IP addresses. After successfully identifying an idle IP, the system binds a virtual network card through the container network interface (CNI) and assigns the corresponding subnet IP, so that the virtual probe has the local network identity of the VLAN.

[0008] Preferably, in step S2, the Agent deployed inside the virtual IP probe has a protocol behavior simulation engine. This engine can automatically identify the service type corresponding to the TCP open port and match a preset protocol interaction template according to the service type. The template covers multiple protocol types such as HTTP / HTTPS, FTP, SMB, SSH, Telnet, MySQL, Oracle, Redis, Modbus, and OPC-UA, thereby realizing in-depth protocol semantic layer interaction and abnormal behavior response analysis.

[0009] Preferably, in step S3, the asset mapping adopts a non-intrusive low-frequency detection strategy. By sending low-intensity, periodic detection messages, it avoids causing congestion and alarm triggering to the target network. During the mapping process, it uses a combination of operating system fingerprint recognition (such as TTL value, window size, response sequence) and hostname acquisition protocols (such as NetBIOS, mDNS, LLMNR) to automatically extract device attribute information and identify the manufacturer type based on the device MAC prefix, thereby achieving comprehensive identification and classification archiving of "shadow assets".

[0010] Preferably, in step S4, the BAS attack simulation includes, but is not limited to, reconnaissance scanning (such as SYN scanning, operating system fingerprinting), vulnerability exploitation (such as buffer overflow, weak password attempt), web attack simulation (such as XSS, SQL injection), and simulation of C&C channel communication behavior; the system monitors whether data packets between probes are detected, blocked, or reported by intermediate devices such as firewalls, IPS, and WAF to determine whether the current network policy is effective and provide configuration correction suggestions.

[0011] Preferably, the wind chime system is deployed on an independent server cluster. Its core modules include a subnet scan scheduler, a virtual probe manager, a protocol simulation engine, an asset mapping engine, an attack simulation engine, and a security policy verifier. The modules communicate with each other through an internal message bus and synchronize perception data, asset views, and security verification results to the user console in real time through APIs, supporting graphical display and policy closed-loop control.

[0012] Preferably, the deployment and recycling process of the virtual probe supports hot-swapping and automatic lifecycle management. When the target VLAN network status changes or the service pressure increases, the system automatically recycles the corresponding probe resources, releases idle IPs and removes container instances according to the policy, ensuring that the normal operation of the service network is not affected.

[0013] Preferably, the method can support operation in an SDN (Software-Defined Networking) environment. The system dynamically obtains VLAN topology and flow table configuration through the controller, and automatically identifies service area boundaries to guide the deployment of virtual probes and the selection of attack simulation paths, thereby further improving the dynamic adaptability and verification effect of network boundary policies.

[0014] Preferably, the system has a multi-tenant and access control mechanism, which can configure exclusive perception policies and attack simulation rules according to different departments, regions or business lines, and supports audit log recording and access restriction, so as to ensure that the system has good controllability and security compliance when deployed in a large-scale network.

[0015] Preferably, the system interfaces with external security systems such as vulnerability databases, security intelligence platforms, CMDB, and SIEM, and synchronizes vulnerability information and asset attribute data in real time through API interfaces, thereby further improving the accuracy of risk perception and dynamic response capabilities, and realizing a complete closed-loop security management process from risk perception and asset location to policy verification.

[0016] Compared with the prior art, the beneficial effects of the present invention are: 1. Comprehensiveness and Non-destructiveness: This invention constructs a sensing network by utilizing idle IP resources, covering all IP devices without installing agents on business hosts, effectively discovering "shadow assets" and achieving true panoramic network visibility. Furthermore, since it utilizes non-business-occupied IP resources, all its detection and mapping activities do not interfere with existing business systems, achieving non-destructive sensing.

[0017] 2. Economy and Flexibility: This invention utilizes existing enterprise switching network infrastructure, eliminating the need for investment in expensive hardware probes and large-scale deployment of terminal agents, thus significantly reducing implementation costs. The probe network is logically constructed and can be dynamically adjusted according to changes in network structure, exhibiting extremely high flexibility.

[0018] 3. Deep Risk Simulation: Unlike traditional scanning that only detects the open state of ports, this invention uses protocol simulation technology to deeply interact with services, accurately identify service types, versions and potential risks, and has a stronger perception capability.

[0019] 4. Quantitative Verification of Security Policies: This invention innovatively introduces BAS technology, which can objectively and quantitatively verify the effectiveness of security policy configurations of firewalls, IPS and other security devices by simulating real attack paths within the network, thus solving the problem that traditional solutions cannot measure the effectiveness of security investments.

[0020] Instruction manual illustrations Figure 1 This is a flowchart illustrating a method for end-network risk perception and security verification provided in an embodiment of the present invention. Detailed Implementation

[0021] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0022] A method for end-network risk perception and security verification, comprising the following steps: S1. By connecting the wind chime system to the core switch of the enterprise network, the trunk technology is used to monitor and manage multiple downstream VLAN subnets, and the idle IP addresses in each subnet are identified through intelligent scanning. S2. Based on the identified idle IP addresses, a lightweight agent is dynamically deployed in the containerized environment to form a virtual IP probe network distributed across various VLANs, thereby achieving coverage awareness at the network endpoint. S3. The Agent performs full port scanning and multi-protocol interaction simulation to identify the target host's port opening status, service type, protocol behavior and potential security risks, and realizes real-time perception of abnormal states such as lateral movement paths, weak passwords and unauthorized services. S4. The virtual IP probe further performs active and non-destructive asset mapping, including but not limited to detecting live hosts in the network through ICMP, TCP SYN and other protocol packets, and collecting information such as operating system, hostname, and service fingerprint; S5. The system uses BAS technology to schedule probes in different areas to launch mutual simulated attack behaviors, evaluate the effectiveness and bypassability of protection strategies between different security domains, and thus form a closed-loop verification mechanism for network security status.

[0023] In step S1, after the wind chime system is connected to the trunk port of the core switch, it uses VLAN tags to logically isolate different VLANs and monitor traffic. The system adopts a multi-threaded concurrent scanning method to perform ARP identification and Ping detection dual mechanisms for each subnet to confirm idle IPs, thereby avoiding conflicts with in-use IP addresses. After successfully identifying an idle IP, the system binds a virtual network card through the container network interface (CNI) and assigns the corresponding subnet IP, so that the virtual probe has the local network identity of that VLAN.

[0024] In step S2, the Agent deployed inside the virtual IP probe has a protocol behavior simulation engine. This engine can automatically identify the service type corresponding to the TCP open port and match a preset protocol interaction template according to the service type. The template covers multiple protocol types such as HTTP / HTTPS, FTP, SMB, SSH, Telnet, MySQL, Oracle, Redis, Modbus, and OPC-UA, thereby realizing in-depth protocol semantic layer interaction and abnormal behavior response analysis.

[0025] In step S3, the asset mapping adopts a non-intrusive low-frequency detection strategy. By sending low-intensity, periodic detection messages, it avoids causing congestion and alarm triggering to the target network. During the mapping process, it uses a combination of operating system fingerprint recognition (such as TTL value, window size, response sequence) and hostname acquisition protocols (such as NetBIOS, mDNS, LLMNR) to automatically extract device attribute information and identify the manufacturer type based on the device MAC prefix, thereby achieving comprehensive identification and classification archiving of "shadow assets".

[0026] In step S4, the BAS attack simulation includes, but is not limited to, reconnaissance scanning (such as SYN scanning, operating system fingerprinting), vulnerability exploitation (such as buffer overflow, weak password attempt), web attack simulation (such as XSS, SQL injection), and simulation of C&C channel communication behavior; the system monitors whether data packets between probes are detected, blocked, or reported by intermediate devices such as firewalls, IPS, and WAF to determine whether the current network policy is effective and provide configuration correction suggestions.

[0027] The wind chime system is deployed on an independent server cluster. Its core modules include a subnet scan scheduler, a virtual probe manager, a protocol simulation engine, an asset mapping engine, an attack simulation engine, and a security policy verifier. The modules communicate with each other through an internal message bus and synchronize perception data, asset views, and security verification results to the user console in real time via API. It supports graphical display and closed-loop policy control.

[0028] The deployment and recycling process of the virtual probes supports hot-swapping and automatic lifecycle management. When the target VLAN network status changes or the business pressure increases, the system automatically recycles the corresponding probe resources, releases idle IPs and removes container instances according to the policy, ensuring that the normal operation of the business network is not affected.

[0029] The method can support operation in an SDN (Software-Defined Networking) environment. The system dynamically obtains VLAN topology and flow table configuration through the controller, and automatically identifies service area boundaries to guide the deployment of virtual probes and the selection of attack simulation paths, thereby further improving the dynamic adaptability and verification effect of network boundary policies.

[0030] The system features multi-tenancy and access control mechanisms, enabling the configuration of exclusive awareness policies and attack simulation rules based on different departments, regions, or business lines. It also supports audit log recording and access restriction, ensuring good controllability and security compliance when the system is deployed in a large-scale network.

[0031] The system interfaces with external security systems such as vulnerability databases, security intelligence platforms, CMDBs, and SIEMs, synchronizing vulnerability information and asset attribute data in real time via API interfaces. This further enhances the accuracy of risk perception and dynamic response capabilities, achieving a complete closed-loop security management process from risk perception and asset location to policy verification. Example Implementation steps: Step S1: Construct a Trunk-based Virtual IP Probe Network This embodiment first connects the "Wind Chime System" to the core switch of the enterprise network via a trunk port. Leveraging the trunk technology's ability to support multiple VLAN (Virtual Local Area Network) communications, the system can monitor and manage all VLAN IDs connected to the switch. The system uses an intelligent scanning algorithm to scan the subnets of each VLAN, accurately identifying in-use and idle IP addresses. Subsequently, the system temporarily occupies one or more idle IP addresses and dynamically deploys a lightweight awareness agent within the containerized environment it manages, using these IP addresses as virtual network interface cards. In this way, a logically constructed end-point awareness network covering the entire network, requiring no physical hardware deployment, and completely isolated from existing services is logically built. This solves the problems of difficult probe deployment, high costs, and highly intrusive network structures in traditional solutions.

[0032] Step S2: Implement agent-based deep risk perception and protocol simulation In the virtual IP probe (i.e., the containerized agent occupying an idle IP) constructed in step S1, the sensing agent possesses and performs two core risk detection functions: 1. Full Port Detection and Awareness: The Agent initiates a full port scan from 0 to 65535 on other IP addresses within the target network range to identify open TCP / UDP ports and potential service entry points on the target host.

[0033] 2. Multi-protocol Interaction Simulation: For detected open ports, especially common web services (such as HTTP / S), database services (such as MySQL, Oracle), and industrial IoT protocols (such as Modbus, OPC-UA), the Agent not only confirms the port is open but also actively simulates legitimate client behavior, sending handshake or request data packets conforming to the corresponding protocol specifications, and capturing and parsing the peer's response. By analyzing the response content, it is possible to accurately identify service types, software versions, and even configuration defects and unauthorized services, thereby achieving deep awareness of risks such as lateral movement paths within the network and vulnerable service exposures.

[0034] Step S3: Utilize idle IP resources for proactive asset mapping This embodiment tightly integrates risk perception with asset management. It utilizes virtual IP probes distributed across various subnets as mapping base points to initiate proactive, efficient, and business-insensitive asset mapping. These probes simulate normal network communication by sending low-intensity probe messages (such as ICMP Echo, TCP SYN, etc.) to discover and identify asset fingerprint information such as live hosts, operating system types, hostnames, and open services within the network. Because the probes are deployed at the network's edge, their mapping behavior more closely resembles the perspective of an insider attacker, enabling the discovery of "shadow assets" (such as unauthorized employee connections or unmanaged IoT devices) that traditional boundary scanners or management tools cannot reach. All mapping data is synchronized in real-time to the central database of the "Wind Chime System," and through correlation analysis, forms a dynamically updated global asset view. This view can be combined with a vulnerability intelligence database and compliance baselines to achieve continuous risk status awareness for each asset.

[0035] Step S4: Implement BAS-based cross-domain security policy effectiveness verification To verify the actual effectiveness of isolation strategies between different security domains within an enterprise (e.g., office areas, development and testing areas, core data center areas), this embodiment introduces Breach and Attack Simulation (BAS) technology. The system can, based on preset test cases, schedule a virtual IP probe located in region A to launch a simulated attack on another virtual IP probe located in region B. The attack behaviors can cover various real-world attack scenarios, ranging from reconnaissance scanning and vulnerability exploitation attempts to C&C communication simulation. By monitoring whether the network traffic between the two probes can be correctly identified, blocked, and alerted by security devices deployed between the domains (such as firewalls, Intrusion Prevention Systems (IPS), and Web Application Firewalls (WAFs), the system objectively and quantitatively assesses whether the security devices' protection capabilities have risks such as policy configuration errors or rule bypasses, thereby achieving risk perception and closed-loop verification of the effectiveness of inter-domain isolation. Specific Implementation Step S1: Construct a Trunk-based Virtual IP Probe Network Configure a trunk interface on the core switch of the enterprise network (such as H3C S6520 or Cisco Catalyst 9500) to connect to the "Wind Chime System" host.

[0037] The wind chime system can simultaneously access the broadcast domain of all VLANs through this trunk port to monitor subnet traffic.

[0038] The system performs an idle IP scan on each VLAN subnet (e.g., based on ARP requests + Ping probes) to identify unused IP addresses.

[0039] For each free IP address, the system will: Create a virtual network interface in a Docker container; Bind the IP address to the virtual probe container; Start the lightweight agent; Each agent simulates a normal terminal device and appears as an "online host" to the outside world, forming a virtual probe network (V-PNet).

[0040] Real-world examples: A company has VLAN 10 (office network), VLAN 20 (R&D network), and VLAN 30 (visitor network), each subnet having a / 24 address range. After the wind chime system was connected to the trunk port of the core switch, the following was found: Unused IPs in VLAN 10: 192.168.10.200, .201 Unused IPs in VLAN 20: 192.168.20.150, .151 Unused IP address in VLAN 30: 192.168.30.90 The system deploys virtual probes on the above IPs. These probes can actively detect the behavior of devices in their respective subnets without the need to install agents or deploy probe boxes.

[0041] Step S2: Agent-based deep risk perception and protocol simulation Technical details: Each virtual probe periodically initiates the following tasks: Perform a full port scan (0~65535) on all hosts within the subnet. For open ports, identify their service type (such as web service, SSH, database, etc.). If the service uses a recognizable protocol, the probe will: Simulate a legitimate client to handshake or request the target service; For example: sending HTTP GET requests, attempting SSH connections, and testing MySQL logins; Record response behavior, such as status codes, banners, and return messages; By using feature matching and an AI rule engine, the following can be determined: Is it a weak password login? Does unauthorized access exist? Does the version have a vulnerability (by comparing CVSS / CVE)? Are there any unauthorized exposed services?

[0042] Real-world examples: When the probe scanned VLAN 20, it found an R&D server (192.168.20.77) with port 3306 open. After simulating a MySQL client connection, it was found that anonymous login was possible, and the database service version was MySQL 5.5.40, which is known to contain a remote code execution vulnerability (CVE-2019-1234).

[0043] The risk was recorded and an alert was displayed in the Wind Chime system console as "high-risk lateral movement path," with suggested remediation measures: disable anonymous access and upgrade the database version.

[0044] Step S3: Utilize idle IP resources for proactive asset mapping Technical details: Each virtual probe actively initiates low-intensity, low-interference detection: Send ARP requests and ICMP Ping packets; Use TCP SYN Half-Open to probe port open status; Identify host attribute information: Operating system type (via fingerprints such as TTL and window size); Open port service types; Device type (e.g., printer, camera, server, etc.); Specifically targeting shadow asset identification: Unmanaged IP addresses; A host that is active at night but offline during the day; MAC address prefixes are not within the scope of enterprise asset registration; The results are uploaded to the central database, forming a dynamic asset view.

[0045] Real-world examples: During the asset surveying process, the probe discovered: A device with IP address 192.168.30.99 frequently came online at night; The device type is a TP-Link router, which is not registered in the enterprise IT asset database; The MAC prefix belongs to "TP-LINK Technologies", suggesting that an employee may have illegally connected a wireless access point.

[0046] The system records this as a "shadow asset," generates an alert, and marks it as an "isolation recommendation."

[0047] Step S4: Implement BAS-based cross-domain security policy effectiveness verification Technical details: The system defines attack simulation templates, such as: Network scanning simulation; Validation of privilege escalation path; C&C tunnel testing (DNS Tunneling, HTTP Beacon, etc.); Schedule source probes and target probes: Simulate an attack initiated by the source probe (e.g., located in an office area); The target probe is located in the test area or data center area; Check if the intermediate security devices (firewalls, IPS, etc.) are: Properly prevent illegal activities; Generate corresponding logs and alarms; No false alarms or omissions; The verification results will be archived to generate a "Strategy Effectiveness Evaluation Report".

[0048] Real-world examples: The system is configured to send a request from probe A (office network) to probe B (database network segment): TCP port enumeration; Simulate SQL injection attack behavior; Simulate DNS data tunneling.

[0049] The test showed that the enterprise firewall successfully blocked the SQL injection attempt, but did not block the DNS tunneling attempt, nor did it generate any logs.

[0050] The system determined that the DNS policy configuration was incomplete, posing a risk of data leakage, and recommended enabling the DNS abnormal behavior detection module.

[0051] Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing embodiments or make equivalent substitutions for some of the technical features. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.

Claims

1. A method for end-to-end network risk perception and security verification, characterized in that, The method includes the following steps: S1. By connecting the wind chime system to the core switch of the enterprise network, the trunk technology is used to monitor and manage multiple downstream VLAN subnets, and the idle IP addresses in each subnet are identified through intelligent scanning. S2. Based on the identified idle IP addresses, a lightweight agent is dynamically deployed in the containerized environment to form a virtual IP probe network distributed across various VLANs, thereby achieving coverage awareness at the network endpoint. S3. The Agent performs full port scanning and multi-protocol interaction simulation to identify the target host's port opening status, service type, protocol behavior and potential security risks, and realizes real-time perception of abnormal states such as lateral movement paths, weak passwords and unauthorized services. S4. The virtual IP probe further performs active and non-destructive asset mapping, including but not limited to detecting live hosts in the network through ICMP, TCPSYN and other protocol packets, and collecting information such as operating system, hostname, and service fingerprint; S5. The system uses BAS technology to schedule probes in different areas to launch mutual simulated attack behaviors, evaluate the effectiveness and bypassability of protection strategies between different security domains, and thus form a closed-loop verification mechanism for network security status.

2. The method of claim 1, wherein: In step S1, after the wind chime system is connected to the trunk port of the core switch, it uses VLAN tags to logically isolate different VLANs and monitor traffic. The system adopts a multi-threaded concurrent scanning method to perform ARP identification and Ping detection dual mechanisms for each subnet to confirm idle IPs, thereby avoiding conflicts with in-use IP addresses. After successfully identifying an idle IP, the system binds the virtual network card through the Container Network Interface (CNI) and assigns the corresponding subnet IP, enabling the virtual probe to have the local network identity of that VLAN.

3. The method of claim 1, wherein the method further comprises: In step S2, the Agent deployed inside the virtual IP probe has a protocol behavior simulation engine. This engine can automatically identify the service type corresponding to the TCP open port and match a preset protocol interaction template according to the service type. The template covers multiple protocol types such as HTTP / HTTPS, FTP, SMB, SSH, Telnet, MySQL, Oracle, Redis, Modbus, and OPC-UA, thereby realizing in-depth protocol semantic layer interaction and abnormal behavior response analysis.

4. The method for end-network risk perception and security verification according to claim 1, characterized in that: In step S3, the asset mapping adopts a non-intrusive low-frequency detection strategy. By sending low-intensity, periodic detection messages, it avoids causing congestion and alarm triggering to the target network. During the mapping process, it uses a combination of operating system fingerprint recognition (such as TTL value, window size, response sequence) and hostname acquisition protocols (such as NetBIOS, mDNS, LLMNR) to automatically extract device attribute information and identify the manufacturer type based on the device MAC prefix, thereby achieving comprehensive identification and classification archiving of "shadow assets".

5. The method for end-network risk perception and security verification according to claim 1, characterized in that: In step S4, the BAS attack simulation includes, but is not limited to, reconnaissance scanning (such as SYN scanning, operating system fingerprinting), vulnerability exploitation (such as buffer overflow, weak password attempt), web attack simulation (such as XSS, SQL injection), and simulation of C&C channel communication behavior. The system monitors whether data packets between probes are detected, blocked, or reported by intermediate devices such as firewalls, IPS, and WAFs to determine whether the current network policy is effective and provides configuration correction suggestions.

6. The method for end-network risk perception and security verification according to claim 1, characterized in that: The wind chime system is deployed on an independent server cluster. Its core modules include a subnet scan scheduler, a virtual probe manager, a protocol simulation engine, an asset mapping engine, an attack simulation engine, and a security policy verifier. The modules communicate with each other through an internal message bus and synchronize perception data, asset views, and security verification results to the user console in real time via API. It supports graphical display and closed-loop policy control.

7. The method for end-network risk perception and security verification according to claim 1, characterized in that: The deployment and recycling process of the virtual probes supports hot-swapping and automatic lifecycle management. When the target VLAN network status changes or the service pressure increases, the system automatically recycles the corresponding probe resources, releases idle IPs and removes container instances according to the policy, ensuring that the normal operation of the business network is not affected.

8. The method for end-network risk perception and security verification according to claim 1, characterized in that: The method can support operation in an SDN (Software-Defined Networking) environment. The system dynamically obtains VLAN topology and flow table configuration through the controller, and automatically identifies service area boundaries to guide the deployment of virtual probes and the selection of attack simulation paths, thereby further improving the dynamic adaptability and verification effect of network boundary policies.

9. The method for end-network risk perception and security verification according to claim 1, characterized in that: The system features multi-tenancy and access control mechanisms, enabling the configuration of exclusive awareness policies and attack simulation rules based on different departments, regions, or business lines. It also supports audit log recording and access restriction, ensuring good controllability and security compliance when the system is deployed in a large-scale network.

10. The method for end-network risk perception and security verification according to claim 1, characterized in that: The system interfaces with external security systems such as vulnerability databases, security intelligence platforms, CMDB, and SIEM, and synchronizes vulnerability information and asset attribute data in real time through API interfaces. This further improves the accuracy of risk perception and dynamic response capabilities, and realizes a complete closed-loop security management process from risk perception and asset location to policy verification.