catcamstar
Known around here
- Jan 28, 2018
- 1,656
- 1,196
Everything gets scanned 24x7 these days. Common ports get hit more frequently but trying to obscure things on high ports doesn't do anything now beyond maybe delaying it being found for some number of days. e.g., From my logs just now over a couple of minutes (DPT= destination port):
And once something gets tagged as begin open you can often watch multiple remote hosts then start to target that host/port specifically.
I fully agree with your statement, but I do hope the logs you show are NOT from a device sitting in the network of your IPC/NVR. There is a reason why I have put all my IPC/NVR gear in a seperate vlan, which is not exposed to the internet. All hammering/port scanning on my WAN ports are trashed, and for sure not forwarded to the inner network. Even on my internal LAN, intervlan port scans are intercepted and trashed when they occur. Only specific IPs in specific vlans have routed access towards other vlans.