All alerts that have iv_alert.alertType = 20 are NTBA port scan alerts. Its iv_alert_data.typeSpecific data has following the format:
First byte contains the number of port information to follow. If there are five ports involved in the port scan, then the first byte of typeSpecific data will have a value of 5. Each subsequent pair of bytes will contain the actual port number values. Total length of typeSpecificData will be 1 + ( 5*2 ) + 8 = 19 bytes.
The details of the alert are as follows:
| Number of bytes | Value |
|---|---|
| 1 | Version information |
| 4 (IPv4) or 16 (Ipv6) | Proxy IP address |
| 1 | Total number of ports |
| 2 | Port details |
| Variable length | Packet logs |