All alerts that has iv_alert.alertType = 4 are port scan alerts. Its iv_alert_data.typeSpecific data has the following format:
First byte contains number of port information to follow. If there are five ports involved in port scan then first byte of typeSpecificData will contain value 5. Each subsequent 2 bytes will contain the actual port number values.
Total length of typeSpecificData will be 1 + ( 5*2) = 11 bytes.
The source and destination VLAN ID follow with each being 4 bytes. These fields are applicable only for NTBA alerts.
The details of the alert are as follows:
| Number of bytes | Value |
|---|---|
| 1 | Version information |
| 4 (IPv4) or 16 (Ipv6) | IP address |
| 1 | Total number of ports |
| 2 | Port information |
| Variable length | Packet logs |
