196
Summary
- // if you see it open
- No CVE or authoritative advisory found, and no confirmed malware association for port 196 on either transport: no CVE, vendor advisory, or named threat-intelligence source ties a malware family to it.
About port 196/tcp.
Port 196/tcp is registered with IANA under the service name dn6-smm-red, described as "DNSIX Session Mgt Module Audit Redir," with Lawrence Lebahn listed as both assignee and contact. The entry is dual-registered — 196/udp carries an identical service name and description — and the registry's Registration Date, Modification Date, and Reference (RFC) columns are all blank for this row, so no date or RFC can be honestly attached to the assignment. The name points to DNSIX, the Defense Data Network/DoD Security for Information Exchange suite proposed in the 1980s–90s to add security and audit extensions to DDN hosts; "Session Management Module Audit Redirector" reads as the component that redirected session-audit trail records to a central management module, though no publicly available protocol spec or RFC documents its wire format. No mainstream client, server, or open-source project currently implements this service, and internet-scan telemetry (nmap's shipped nmap-services frequency file) puts the observed-open probability at roughly 0.000025 for tcp and 0.000428 for udp — vanishingly rare, consistent with a dormant historical DoD reservation rather than an active service. No malware or trojan association is confirmed for port 196 on either transport: no CVE, vendor advisory, or named threat-intelligence source ties a malware family to it.
- IANA assignment
dn6-smm-red— "DNSIX Session Mgt Module Audit Redir"; assignee/contact Lawrence Lebahn; dual-registered 196/tcp + 196/udp [Confirmed] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.txt (also cached local registry CSV, lines 478-479)- Registration/Modification date
- blank in the IANA registry for this row — not reported, no date invented [Confirmed] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.txt
- IANA reference (RFC)
- none listed; field stays blank per no-fabrication rule [Confirmed] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.txt
- Range class
- well-known (0–1023) [Confirmed] — IANA range convention
- Prevalence
- nmap-services open-frequency ≈0.000025 (tcp), ≈0.000428 (udp) — very rarely observed open [Likely] — https://svn.nmap.org/nmap/nmap-services
- Related ports
- 195/tcp
dn6-nlm-aud("DNSIX Network Level Module Audit") is the only other DNSIX-named registration in this neighborhood [Confirmed] — cached IANA registry CSV. The adjacent 197/198 (dls/dls-mon, "Directory Location Service"/"...Monitor") and 190–194 (gacp,prospero,osu-nms,srmp,irc) are unrelated services with different assignees — not a DNSIX cluster
Primary use
legacy DoD DNSIX suite component — session-audit-trail redirector; no public protocol spec found, name/port reservation only [Likely] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.txt, http://www.t1shopper.com/tools/port-number/196/
Common software
none documented; no known active implementation [Unknown]
Security implications
no confirmed malware association for 196/tcp or 196/udp, and no CVE or authoritative advisory found tying a vulnerability to this port
Typically seen on
legacy/historical DoD DNSIX-era hosts, if ever seen open at all; otherwise an anomaly given near-zero scan prevalence
About port 196/udp.
Port 196/udp is registered with IANA as dn6-smm-red, described as "DNSIX Session Mgt Module Audit Redir," with assignee and contact both listed as [Lawrence_Lebahn]. It is dual-registered: 196/tcp carries the identical service name, description, and assignee/contact, and the IANA Reference column is blank for both — no RFC underlies this entry, so none is cited here. DNSIX ("DoD Network Security for Information Exchange," also rendered "DODIIS Network Security Information Exchange") was a legacy U.S. Department of Defense framework for embedding security-attribute tokens — classification, role, and origin metadata — into network sessions for multi-level-security environments. The only other DNSIX-named registration in this neighborhood is 195 (dn6-nlm-aud, "DNSIX Network Level Module Audit"); 196 specifically corresponds to the "Session Management Module" audit-redirect function. The nearby ports are not part of a DNSIX cluster — 190–194 are unrelated services (gacp, prospero, osu-nms, srmp, irc) with different assignees, and 197/198 are dls/dls-mon ("Directory Location Service"/"...Monitor"), a separate service family. No evidence surfaced of any current, widely-deployed software or daemon that actively implements or listens on dn6-smm-red today — this reads as a dormant legacy DoD-era registration rather than a live protocol in mainstream use. Third-party port-lookup sites list the port as officially IANA-assigned with no current malware association and no CVE tied specifically to 196; any live traffic seen on this port today is far more plausibly scanner noise or non-standard reuse than genuine DNSIX traffic. Because the IANA registry carries no per-entry date field for this legacy System Port, no assignment or modification date is available or invented.
- IANA assignment
dn6-smm-red— "DNSIX Session Mgt Module Audit Redir"; reference blank (no RFC cited); assignee/contact [Lawrence_Lebahn]; dual-registered 196/tcp + 196/udp with identical name/description/contact [Confirmed] — cached local IANA Service Names and Port Numbers Registry CSV (lines 478–479) and https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml- Range class
- well-known (0–1023) [Confirmed]
- Registration/modification dates
- blank in the IANA registry for this entry; no date field exists for this legacy System Port, so left null rather than fabricated [Confirmed absence] — IANA registry
- Current status / prevalence
- no CVE or active-exploitation reporting tied specifically to port 196; third-party scan sites show it as officially assigned with current "no known virus/trojan" status [Likely] — https://www.auditmypc.com/udp-port-196.asp, https://www.speedguide.net/port.php?port=196
- Related ports
- 195
dn6-nlm-aud("DNSIX Network Level Module Audit") is the only other DNSIX-named port; the adjacent 190–194 (gacp,prospero,osu-nms,srmp,irc) and 197/198 (dls/dls-mon) are unrelated services with different assignees — not a DNSIX cluster [Confirmed] — cached IANA registry CSV
Primary use
DNSIX Session Management Module audit-redirect sub-function, part of a legacy DoD multi-level-security session-tagging framework [Likely] — https://www.acronymfinder.com/DODIIS-Network-Security-Information-Exchange-(DNSIX).html, https://www.allacronyms.com/DNSIX/DoD_Network_Security_for_Information_Exchange
Other/unofficial uses
none identified; no evidence of an active modern implementation [Unknown]
Security implications
dormant legacy registration; live traffic on 196/udp today is more plausibly scanner noise or opportunistic reuse than genuine dn6-smm-red traffic; some trojan/virus families have historically used ports across this general low range opportunistically, but this is a generic caveat, not evidence specific to 196
Typically seen on
no confirmed active deployments found; would be legacy DoD/DNSIX-era systems if ever exercised in practice [Unknown]
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| dn6-smm-red | UDP | DNSIX Session Mgt Module Audit Redir | 0.04% |
| dn6-smm-red | TCP | DNSIX Session Mgt Module Audit Redir | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.