UDP Port 80 – HTTP (Hypertext Transfer Protocol)
About UDP Port 80
Port 80 carries the IANA assignment for http. The IANA description reads: ‘World Wide Web HTTP’. This port is referenced in 2 IDS rules and exhibits low malware activity in monitored traffic.
IDS Rule References
2 IDS / security rules reference UDP port 80. Treat that number as context, not a danger score. Many detection rules are written against groups of ports rather than one service, web ports especially, so common web alternate ports inherit large counts while genuinely sensitive services can show few rules or none. Presence in IDS rules does not mean traffic on this port is malicious.
Rule categories (top 1): trojan-activity (2).
Sample rule descriptions for UDP port 80:
- ET MALWARE Win32/PlugX Variant CnC Activity
- ET MALWARE BPFDoor V2 UDP Magic Packet Inbound
Malware Rule References
A small share of the IDS rules that reference this port are malware related.
2 of the 2 IDS rules that reference UDP port 80 are malware related. That describes detection coverage across the whole internet, not anything about your machine or your network.
Families observed (top 2): BPFDoor (1), Win32_DLOADR_TIOIBEPQ (1).
Data Sources
This information is compiled from: IANA Service Name and Transport Protocol Port Number Registry, Emerging Threats Open Ruleset (BSD 2-Clause / GPLv2 per SID range), Snort Community Rules (GPLv2), and MITRE ATT&CK (Apache 2.0).
