20 Feb
2007
20 Feb
'07
2:49 a.m.
Interesting analysis Perry. What makes you certain that actual people are generating use on these ports vs trojans, worms and the like?
Well, since I only look at traffic *from* the DSL customers, it should avoid counting scans/virii etc from out on the "big bad internet". Customers could be infected with stuff, but generally virii scan only for one particular port, so it would show up as one port for one customer. If you looked at the "top ports" you'll see 135, 139, 445 make an appearance which are used by various windows worms, so obvious some users are infected with virii. However this isn't going to push peoples port counts up to the 1,000's like p2p will.