{"schema":"https://ver.cy/schemas/card/1.0.0","id":"vr.wm-sft-018","code":"wm-sft-018-network-endpoint","url":"https://ver.cy/models/wm-sft-018-network-endpoint/","name":"Network / Endpoint","alternateNames":[],"kind":"world-model","status":"published","version":"0.1.0-reviewable-draft","language":"en","classifiers":{"family":"World Models","category":"Information and virtual systems","entryKind":"entity","plane":"","domain":["INF.SFT.NET"],"industry":["Cross-industry"],"navPath":"NAV.INF.SFT.NET","tags":["network","endpoint","inf.sft.net"],"facets":{}},"whatItIs":"A network endpoint is a stable logical identity for a point where a system can be reached over a network, such as a service address, API endpoint or device interface. It holds effective-dated bindings to concrete addresses (host names, IP addresses, ports), its connectivity and bounded assertions about how it is exposed. The software running behind it, the physical device and the traffic flowing to it are separate subjects.","purpose":"Describe one stable logical network endpoint with effective-dated address bindings, contextual connectivity and bounded exposure assertions.","scope":{"in":["Endpoint identity, accountable roles, classification and contextual service, runtime and interface bindings","Effective-dated locator sets, protocol properties, discovery evidence and expected versus presented service identity","Topology references, bounded exposure declarations, reachability evidence links, local assessments and record continuity"],"out":["Whole network inventory or routing engine; device, software, runtime and interface contract masters","Traffic collection, telemetry lifecycle, credentials, certificate issuance, access-policy enforcement and operational security decisions","Active scans, network writes, production changes, deployment, universal availability guarantees and compliance certification"],"boundaries":[{"neighbor":"WM-SFT-002","distinction":"Candidate ledger edge: software identity and lifecycle stay software-owned; retain service reference and effective binding only."},{"neighbor":"WM-SFT-010","distinction":"Candidate ledger edge: runtime identity and capacity stay runtime-owned; retain hosting and network-context references only."},{"neighbor":"WM-SFT-003","distinction":"Candidate ledger edge, including reciprocal incoming reference: bind interface contract revisions without owning their semantics, operations or compatibility."},{"neighbor":"WM-SFT-017","distinction":"Candidate ledger edge: reference traffic and reachability evidence; telemetry occurrence, collection lifecycle and signal identity stay telemetry-owned."}]},"distinguishingFeatures":["The logical endpoint stays stable while its concrete address bindings change over time.","Exposure is stated as bounded, verifiable assertions rather than assumed.","Distinct from the software service behind it, its parent context, and from the device that hosts it.","Distinct from network flow telemetry, which records traffic rather than the endpoint's identity."],"structure":{"bundles":[{"id":"SFT018-B1","name":"Endpoint identity","description":"What the endpoint is and who owns it.","layers":[{"id":"SFT018-B1-L1","name":"Logical endpoint","description":"The stable identity, owner and purpose of the endpoint.","findings":[{"id":"SFT018-F01","name":"Identity and owner","description":"The endpoint's identifier, owner and the service it fronts.","questions":[{"text":"Which stable identifier names this endpoint, and who owns it?","id":"SFT018-Q01"},{"text":"Which service or system does the endpoint front?","id":"SFT018-Q02"}]}]}]},{"id":"SFT018-B2","name":"Address bindings","description":"Where the endpoint currently resolves.","layers":[{"id":"SFT018-B2-L1","name":"Effective-dated bindings","description":"Host names, addresses and ports with validity periods.","findings":[{"id":"SFT018-F02","name":"Current binding","description":"The addresses and ports the endpoint uses now.","questions":[{"text":"Which host names, IP addresses and ports does the endpoint resolve to now?","id":"SFT018-Q03"},{"text":"Since when is this binding valid, and which binding did it replace?","id":"SFT018-Q04"}]},{"id":"SFT018-F03","name":"Protocol and certificate","description":"The protocols and certificates presented.","questions":[{"text":"Which protocols and versions does the endpoint accept?","id":"SFT018-Q05"},{"text":"Which certificate does it present, and when does it expire?","id":"SFT018-Q06"}]}]}]},{"id":"SFT018-B3","name":"Exposure and connectivity","description":"Who can reach it and how far it is exposed.","layers":[{"id":"SFT018-B3-L1","name":"Exposure assertion","description":"Bounded statements about reachability and controls.","findings":[{"id":"SFT018-F04","name":"Reachability","description":"Networks from which the endpoint can be reached.","questions":[{"text":"Is the endpoint reachable from the internet, a private network or only locally?","id":"SFT018-Q07"},{"text":"Which authentication and access controls protect it?","id":"SFT018-Q08"}]},{"id":"SFT018-F05","name":"Verification","description":"Evidence that the exposure assertion is true.","questions":[{"text":"When was the exposure last verified, and by what scan or test?","id":"SFT018-Q09"},{"text":"Do observed open ports match the declared exposure?","id":"SFT018-Q10"}]}]}]}]},"agentConduct":{"may":["Keep an inventory of endpoints with owners, bindings and validity periods.","Verify exposure of endpoints the owner is authorized to test.","Report expiring certificates, stale bindings and unexpected open ports to the owner.","Resolve an endpoint to its current binding for authorized clients."],"mustNot":["Scan, probe or attack endpoints without the owner's authorization.","Open firewall rules or expose endpoints beyond the declared exposure.","Publish internal endpoint inventories that help attackers.","Rebind an endpoint to a new address without change control.","Disable authentication or encryption on an endpoint."],"requiresHuman":["Exposing an endpoint to the internet.","Changing bindings of production endpoints.","Approving penetration tests against endpoints."]},"ethics":{"considerations":["Exposed endpoints are the main entry point for attacks that harm users and their data.","Endpoint addresses can identify people and devices, so inventories need protection.","Scanning other people's systems without consent can be unlawful and harmful."],"affectedParties":["Users of the services behind the endpoints","System owners and operators","People whose devices are addressed"]},"owners":{"steward":"The team that operates the service behind the endpoint owns its identity, bindings and exposure assertions.","roles":[{"name":"Endpoint steward","responsibilities":["Resolve identity, namespace and binding disputes within delegated authority."]},{"name":"Network policy approver","responsibilities":["Approve bounded exposure declarations; external enforcement remains separately controlled."]},{"name":"Evidence curator","responsibilities":["Link permitted observations with scope, provenance and freshness; do not rewrite telemetry masters."]},{"name":"Profile reviewer","responsibilities":["Review schema constraints, neighbor pins and projection losses before operational adoption."]},{"name":"Authorized consumer","responsibilities":["Read or export only purpose-approved views and report ambiguity."]}],"masterSystems":["IP address management systems","DNS zones","Configuration management databases","API gateways and service registries"]},"relations":[{"target":"WM-SFT-002","type":"references","note":"Candidate ledger edge: software identity and lifecycle stay software-owned; retain service reference and effective binding only."},{"target":"WM-SFT-010","type":"references","note":"Candidate ledger edge: runtime identity and capacity stay runtime-owned; retain hosting and network-context references only."},{"target":"WM-SFT-003","type":"references","note":"Candidate ledger edge, including reciprocal incoming reference: bind interface contract revisions without owning their semantics, operations or compatibility."},{"target":"WM-SFT-017","type":"references","note":"Candidate ledger edge: reference traffic and reachability evidence; telemetry occurrence, collection lifecycle and signal identity stay telemetry-owned."},{"target":"RFC 8345 network topology","type":"aligned","note":"Optional versioned mapping from an endpoint binding to topology references; no universal equivalence to a termination point."},{"target":"DCAT 3 endpointURL and endpointDescription","type":"aligned","note":"Optional data-service projection; the endpoint root is not a dataset or the full service description."},{"target":"OpenAPI 3.1.1 Server Object","type":"aligned","note":"Optional HTTP interface binding projection with pinned variables and selector semantics; no executable conformance claim."},{"target":"WM-SFT-002","type":"neighbor","note":"Candidate ledger edge: software identity and lifecycle stay software-owned; retain service reference and effective binding only."},{"target":"WM-SFT-010","type":"neighbor","note":"Candidate ledger edge: runtime identity and capacity stay runtime-owned; retain hosting and network-context references only."},{"target":"WM-SFT-003","type":"neighbor","note":"Candidate ledger edge, including reciprocal incoming reference: bind interface contract revisions without owning their semantics, operations or compatibility."},{"target":"WM-SFT-017","type":"neighbor","note":"Candidate ledger edge: reference traffic and reachability evidence; telemetry occurrence, collection lifecycle and signal identity stay telemetry-owned."},{"target":"WM-SFT-002","type":"parent"}],"interaction":{"identity":{"applicability":"required","items":["An endpoint is identified by a stable logical name or URI that outlives its address bindings.","Bindings use DNS host names, IP addresses and port numbers.","Certificates presented by the endpoint are identified by issuer and serial number or fingerprint."]},"properties":{"applicability":"not-applicable","items":[]},"recognition":{"applicability":"optional","items":["An addressable point that accepts connections on a protocol and port, with a known owner.","Often confused with the host machine, the service behind it, or a DNS name that points to several endpoints."]},"capabilities":{"applicability":"required","items":["Accepts connections over defined protocols and returns responses.","Bindings can be changed while the logical identity stays the same."]},"hazards":{"applicability":"required","items":["Unintended internet exposure of internal services.","Expired or misissued certificates enabling interception.","Stale bindings that send traffic to addresses now controlled by others."]},"interfaces":{"applicability":"required","items":["DNS, IP and TCP or UDP port numbers as defined by the IETF and IANA.","X.509 certificates and TLS for endpoint authentication.","OpenAPI descriptions for HTTP API endpoints."]},"context":{"applicability":"required","items":["Found in data centres, cloud platforms, enterprise networks and devices.","Security frameworks require inventories of exposed services."]}},"sources":[{"title":"Uniform Resource Identifier (URI): Generic Syntax","url":"https://www.rfc-editor.org/rfc/rfc3986","note":"Internet Engineering Task Force"},{"title":"A YANG Data Model for Network Topologies","url":"https://www.rfc-editor.org/rfc/rfc8345","note":"Internet Engineering Task Force"},{"title":"Data Catalog Vocabulary (DCAT) - Version 3","url":"https://www.w3.org/TR/vocab-dcat-3/","note":"World Wide Web Consortium"},{"title":"Zero Trust Architecture","url":"https://csrc.nist.gov/pubs/sp/800/207/final","note":"National Institute of Standards and Technology"},{"title":"Domain names - concepts and facilities","url":"https://www.rfc-editor.org/rfc/rfc1034","note":"Internet Engineering Task Force"},{"title":"IPv6 Scoped Address Architecture","url":"https://www.rfc-editor.org/rfc/rfc4007","note":"Internet Engineering Task Force"},{"title":"Service Identity in TLS","url":"https://www.rfc-editor.org/rfc/rfc9525","note":"Internet Engineering Task Force"},{"title":"Service Name and Transport Protocol Port Number Registry","url":"https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml","note":"Internet Assigned Numbers Authority"},{"title":"OpenAPI Specification v3.1.1","url":"https://spec.openapis.org/oas/v3.1.1.html","note":"OpenAPI Initiative"},{"title":"PROV-O: The PROV Ontology","url":"https://www.w3.org/TR/prov-o/","note":"World Wide Web Consortium"},{"title":"RFC 3986 Uniform Resource Identifier: Generic Syntax, IETF"},{"title":"Service Name and Transport Protocol Port Number Registry, IANA"},{"title":"NIST Cybersecurity Framework, NIST"}],"openQuestions":["Complete independent source verification with response metadata, version and errata review, claim support and applicability checks; restore external provider review before canonical promotion.","Develop nested instance schemas and pinned mappings with fixtures for shared addresses, concurrent bindings, conflicting resolver views, scoped IPv6, stale evidence, identity mismatch, retirement and redacted export.","Review specialist protocol, mediation, authorization, privacy and retention profiles with accountable operators before any operational adoption.","Independent external provider review is absent; this Codex result can only be a reviewable draft.","Direct HTTP checks were not run because the owner reports sandbox blocking; response status, final URLs and body digests remain unmeasured. Browser readings cover selected sections only; latest versions and all errata are not certified.","Nested instance schemas, mandatory profile fields, loss-aware executable mappings and adverse-instance fixtures remain unimplemented.","Protocol-specific discovery beyond the selected DNS concepts, non-IP transports, multicast or anycast behavior, complex mediation and full certificate lifecycle need specialist profiles.","Legal authority for testing, privacy, retention, export, licensing and sector requirements need adopting-context review."],"resources":{"spec":"/models/wm-sft-018-network-endpoint/spec.yaml","agents":"/models/wm-sft-018-network-endpoint/AGENTS.md","source":"https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-sft-018"},"provenance":{"origin":"world-models research","builtFrom":["models/wm-sft-018-network-endpoint/spec.yaml","ver-cy/world-models/card-supplements/wm-sft-018-network-endpoint.json"],"providers":["Codex"],"researchStatus":"reviewable-draft","generatedAt":"2026-10-06T12:41:13Z","builder":"tools/build_cards.py@1.0.0"},"completeness":{"sections":{"classifiers":"filled","whatItIs":"filled","purpose":"filled","distinguishingFeatures":"filled","structure":"filled","agentConduct":"filled","ethics":"filled","owners":"filled","relations":"filled","interaction.identity":"filled","interaction.properties":"not-applicable","interaction.recognition":"filled","interaction.capabilities":"filled","interaction.hazards":"filled","interaction.interfaces":"filled","interaction.context":"filled","sources":"filled"},"notes":{"interaction.properties":"A network endpoint is a logical identity, not a physical object; latency and throughput are measured on the traffic, not on the endpoint itself.","_supplement":"Sections authored in card supplement 1.0.0 by Claude (Opus 5.5) (2026-10-06, unreviewed). Written from the card's existing content and established practice in the field; no new sources were read. Unreviewed."},"score":1.0}}