UDP Port 443 – HTTPS (HTTP over TLS)
About UDP Port 443
Port 443 carries the IANA assignment for https. The IANA description reads: ‘http protocol over TLS/SSL’. This port is referenced in 3 IDS rules and exhibits low malware activity in monitored traffic.
IDS Rule References
3 IDS / security rules reference UDP port 443. Presence in IDS rules does not mean traffic on this port is malicious. These are patterns security tools monitor.
Rule categories (top 1): trojan-activity (3).
Sample rule descriptions for UDP port 443:
- ET MALWARE Win32/PlugX Variant CnC Activity
- ET MALWARE BPFDoor V2 UDP Magic Packet Inbound
- ET MALWARE Suspected DinodasRAT Related Activity (UDP)
Malware Activity
Some malware indicators are observed on this port.
3 of 3 IDS rules for UDP port 443 involve malware activity.
Families observed (top 3): BPFDoor (1), DinodasRAT (1), Win32_DLOADR_TIOIBEPQ (1).
Data Sources
This information is compiled from: IANA Service Name and Transport Protocol Port Number Registry, Emerging Threats Open Ruleset (BSD 2-Clause / GPLv2 per SID range), Snort Community Rules (GPLv2), and MITRE ATT&CK (Apache 2.0).
