TCP Port 990 – ftps
About TCP Port 990
Port 990 is registered with the Internet Assigned Numbers Authority (IANA) for ftps. The IANA description reads: ‘ftp protocol, control, over TLS/SSL’. This port appears in 5 IDS rules and does not have notable malware activity indicators in our data.
IDS Rule References
5 IDS / security rules reference TCP port 990. Presence in IDS rules does not mean traffic on this port is malicious. These are patterns security tools monitor.
Rule categories (top 1): bad-unknown (5).
Sample rule descriptions for TCP port 990:
- ET EXPLOIT Possible OpenSSL HeartBleed Large HeartBeat Response from Common SSL Port (Outbound from Server)
- ET EXPLOIT Possible OpenSSL HeartBleed Large HeartBeat Response from Common SSL Port (Outbound from Client)
- ET EXPLOIT Possible TLS HeartBleed Unencrypted Request Method 4 (Inbound to Common SSL Port)
- ET EXPLOIT Possible TLS HeartBleed Unencrypted Request Method 3 (Inbound to Common SSL Port)
- ET EXPLOIT FREAK Weak Export Suite From Server (CVE-2015-0204)
Data Sources
This information is compiled from: IANA Service Name and Transport Protocol Port Number Registry, Emerging Threats Open Ruleset (BSD 2-Clause / GPLv2 per SID range), and MITRE ATT&CK (Apache 2.0).
