Network port detail · UDP/TCP

198

Dls-mon
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// if you see it open
No documented malware family or scanning campaign tied specifically to this port. A low-authority site (auditmypc.com) carries generic templated 'no known virus/trojan' disclaimer language, not treated as a verified finding.
// analyst note
dls-mon is an obscure, apparently-dormant legacy registration with no confirmed modern usage; an open port 198 is statistically unusual and merits investigation rather than being assumed benign.
[ 01 ] — Context

About port 198/tcp.

Updated  ·  Confidence: Likely

Port 198/tcp is registered with IANA as dls-mon, described as "Directory Location Service Monitor," with assignee Scott Bellew and a blank reference field; the registration is dual-listed on both TCP and UDP (198/udp carries the identical name, description, and assignee). No RFC or other IETF specification document is attached to this entry in the registry, and no reference number is listed — that blank is left blank here rather than invented. The name and its numeric proximity to port 197/tcp+udp (dls, "Directory Location Service") strongly suggest dls-mon was intended as a monitoring or status-check companion channel for that service, though no protocol document or independent source confirms the exact relationship, so this pairing is treated as a likely inference rather than a confirmed fact. No mainstream server or client software, open-source or commercial, is documented as implementing dls-mon today, and it does not appear as an active service in common service-fingerprint databases such as nmap-services beyond the bare name inherited from the IANA list. No credible, named malware family or documented internet-wide scanning campaign is tied specifically to this port; a low-authority consumer site (auditmypc.com) carries generic templated "no known virus/trojan" boilerplate that is repeated across many of that site's port pages and is not treated as a verified security finding. Given its obscurity and the total absence of documented real-world deployment, port 198/tcp should be treated by an analyst as an essentially unused legacy registration — a responsive listener on this port is unusual and worth investigating as an anomaly rather than assumed to be the registered service.

IANA assignment
dls-mon — "Directory Location Service Monitor"; reference (blank — no RFC cited in IANA registry); assignee Scott Bellew; dual-registered 198/tcp + 198/udp [Confirmed] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml
Range class
well-known (0–1023) [Confirmed]
Prevalence
no authoritative open-frequency figure located for this port; assessed as extremely rare/essentially unused given the absence of any documented real-world deployment [Unknown]
Related ports
197/tcp + 197/udp (dls, Directory Location Service — the likely paired registration)

Primary use

legacy IANA registration with no attached RFC; name and numeric adjacency to port 197 (dls, Directory Location Service) suggest it was meant as a monitoring/status companion channel for that service, but no protocol document confirms this

[Likely] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml

Other/unofficial uses

none identified; no modern software or protocol implementation documented [Unknown]

Security implications

no documented malware family or scanning campaign tied to this port specifically; a low-authority site (auditmypc.com) carries generic templated "no known virus/trojan" disclaimer language not treated as a verified finding

[Likely] — https://www.auditmypc.com/tcp-port-198.asp

Typically seen on

not documented as deployed on any current OS or software package; a responsive instance would be an anomaly [Unknown]

Analyst note
dls-mon is an obscure, apparently-dormant legacy registration with no confirmed modern usage; an open port 198 is statistically unusual and merits investigation rather than being assumed benign.
[ 02 ] — Context

About port 198/udp.

Updated  ·  Confidence: Medium

Port 198/udp is registered with IANA as dls-mon, "Directory Location Service Monitor," under assignee and contact Scott Bellew, with no registration date, modification date, or RFC/reference recorded in the registry — an artifact of IANA's early service-name assignment era rather than a gap in our data. The registration is dual: 198/tcp carries the identical name, description, and assignee, a pattern common to services registered before transport protocols were tracked separately. The name implies dls-mon was intended as a monitoring or status-check companion to a "Directory Location Service" (DLS) — presumably an early enterprise directory or name-resolution product from the 1990s IANA registration era — but no IETF RFC, vendor manual, or independent technical description of the protocol surfaced during research; the bare registry line (name, one-sentence description, registrant) is the only first-party documentation available. Third-party port-lookup mirrors (t1shopper, adminsub.net, auditmypc) simply republish the same IANA text without adding software attribution, so "common software" for this port should be treated as unknown rather than asserting a specific product. No CVEs, malware-family associations, or notable internet-scanning campaigns reference port 198 in current security literature, and its footprint in available scan data is slight — the nmap-services dataset records an observed open-frequency of ≈ 0.001252 for 198/udp (roughly 1 in 1,000 sampled hosts) against 0 for 198/tcp, consistent with a legacy, rarely-if-ever-implemented registration answering the occasional scan. For an analyst, a host responding on 198/udp is unusual enough to warrant investigation as a fingerprint or anomaly rather than routine traffic, though absent further evidence this remains a low-visibility, low-confidence corner of the port space.

IANA assignment
dls-mon — "Directory Location Service Monitor"; reference (blank — no RFC cited in IANA registry); assignee/contact [Scott_Bellew]; dual-registered 198/tcp + 198/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry (matching 198/tcp at line 482); cross-checked against https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.txt
Range class
well-known (0–1023) [Confirmed]
Prevalence
nmap-services observed open-frequency 198/udp ≈ 0.001252 — very low (roughly 1 in 1,000 sampled hosts), 298th of 5,615 UDP entries; the TCP sibling 198/tcp records 0. The figure measures how often the port answers a scan, not dls-mon use — no source identifies what is listening
[Likely] — nmap-services dataset
Related ports
198/tcp (identical dual registration, same assignee/contact, same blank date/reference fields) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry

Primary use

presumed monitoring/status companion to an unspecified "Directory Location Service" product

[Likely] — no independent RFC or vendor spec found to confirm; name/description are the only evidence

Other/unofficial uses

none documented

[Unknown] — no software attribution found beyond the bare IANA line

Security implications

no CVEs, malware associations, or notable scanning campaigns documented for port 198 as of 2026-07-11; absence of evidence, not a confirmed zero-risk finding [Unknown]

Typically seen on

unknown — no current or historical client/server software confirmed [Unknown]

Analyst note
A responsive port 198/udp is a legacy, low-footprint registration with no known modern usage; treat an unexpected open instance as an anomaly worth investigating rather than routine traffic.
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
dls-mon UDP Directory Location Service Monitor 0.13%
dls-mon TCP Directory Location Service Monitor 0.00%
IANA name
dls-mon
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.