Interpret CIDR remainders and saved port observations
Distinguish mathematical coverage from real allocations, and understand ambiguous states, timed-out hosts and blank service fields in an open-port inventory.
A computed set and a saved observation
CIDR subtraction starts from two sets you provide, so the remainder can be checked precisely by address. A Nmap table starts from observations saved during a scan; coverage also depends on scope, permissions, time and timeouts. Preserve that context so the receiver can interpret the handoff.
| Result | Checkable conclusion | External confirmation still needed |
|---|---|---|
| CIDR remainder | Addresses in A that B does not cover | Whether the allocation is permitted |
| Nmap open-port row | An explicit open observation in the report | Whether it remains open and whether the scan was complete |
Keep excluded gaps excluded
With A = 10.0.0.0/24 and B = 10.0.0.0/25, the remainder is 10.0.0.128/25 with 128 addresses. Writing it back as 10.0.0.0/24 for convenience would reintroduce the excluded half.
Duplicate networks do not add addresses, and exclusions outside A cannot enlarge A. Minimal CIDR representation compresses the same address set; it does not fill nearby space that was never allowed.
A: 10.0.0.0/24
B: 10.0.0.0/25
A − B: 10.0.0.128/25
addresses: 128Interpret the blanks behind a port row
The open|filtered state preserves uncertainty and therefore does not enter the confirmed-open table. A blank service or version means the report did not contain that value; inserting a familiar default would invent an observation.
An overall successful finish can still include timed-out hosts. Read scanStatus and timedOutHosts, and keep the original scan time, target scope and options in the handoff notes. A format converter cannot reconstruct that context by guessing.
Choose how the receiver will read the data
XLSX text cells make the table readable in spreadsheet software without treating a hostname as a formula. CSV is simpler for interchange, but spreadsheet applications interpret some leading characters, so formula-like CSV values receive an apostrophe.
Use JSON to compare original values when a later program needs them. The first 100 on-page records are a preview, not a basis for extrapolating totals. Open the downloaded file and compare record counts and quoted values to verify the handoff.
Make the handoff reproducible
- Attach A/B provenance, policy meaning and address-count checks to the CIDR output.
- Attach scan time, target scope and finish/timeout status to the port table.
- Compare JSON original values with CSV safety prefixes before consuming them as identifiers.
- Open XLSX in the receiving software and sample a record containing commas, quotes or non-ASCII text.
References
- Python ipaddress
Independent reference for network arithmetic and exact range representation.
- Nmap XML output
Official Nmap XML host and port structure; not evidence of demand size.