Network port detail · UDP/TCP

27

Nsw-fe
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// if you see it open
Not associated with any known malware family or trojan backdoor; a curated trojan-port table (chebucto.ns.ca, accessed June 2026) does not list port 27. No documented significant scanning campaign specifically targets port 27. As a well-known system port (0-1023), an unexpected service answering on 27/tcp on a modern host is anomalous and should be investigated, but no specific exploit or signature is tied to it.
// analyst note
A blank IANA reference and blank dates mean no original spec or date can be cited; the assignment is a legacy reservation with no known active protocol. Legitimate use today is unlikely.
[ 01 ] — Context

About port 27/tcp.

Updated  ·  Confidence: Medium

Port 27/tcp is registered with IANA as nsw-fe with the description "NSW User System FE," assignee Robert Thomas, and a blank reference field — the registry carries no RFC for this entry. It is dual-registered on TCP and UDP (the 27/udp row is identical). The "NSW" in the service name refers to the National Software Works, an early-1970s ARPANET research project that aimed to build a distributed operating environment letting users at one host run programs and access files across the heterogeneous machines of the ARPANET; "FE" is the Front End component through which a user's terminal session entered that system. The assignment is a historical artifact of that era and has no modern practical use: no contemporary software is documented as listening on 27/tcp for this service, and the entry survives in the registry as a legacy reservation rather than an active protocol. For an analyst the port is unremarkable — it sits in the well-known range (0–1023) but is not associated with any known malware family, trojan backdoor, or documented high-volume scanning campaign in the security literature reviewed (a curated trojan-port table accessed June 2026 does not list port 27). Because it is a low-numbered system port that is effectively never used legitimately, any service found answering on 27/tcp on a modern host is anomalous and worth investigating, but there is no specific exploit or signature tied to it. The IANA Reference, Registration Date, and Modification Date columns are all blank, so no original specification or assignment date can be cited; treating those as Unknown is the honest position rather than inventing a date or RFC.

IANA assignment
nsw-fe — "NSW User System FE"; reference (blank — no RFC cited in IANA registry); assignee Robert Thomas; dual-registered 27/tcp + 27/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (the IANA Service Name and Transport Protocol Port Number Registry, rows 61 tcp / 62 udp)
Range class
well-known (0–1023) [Confirmed] — IANA registry
Registration / modification dates
blank in IANA registry — Unknown (not cited; no date fabricated) [Unknown] — IANA registry
Related ports
other low-numbered legacy/historical system-port assignments in the 0–1023 range

Primary use

legacy ARPANET-era "NSW User System FE" — the Front End of the National Software Works distributed-computing project; no modern active use

[Likely] — IANA registry description; https://en.wikipedia.org/wiki/List_of_TCP_and_UDP_port_numbers

Other/unofficial uses

none documented

[Unknown] — no source found associating modern software with 27/tcp

Security implications

not listed as a trojan/backdoor port and no documented significant scanning campaign specifically targets port 27; as a well-known system port, an unexpected listener on 27/tcp should be treated as anomalous and investigated

[Likely] — http://www.chebucto.ns.ca/~rakerman/trojan-port-table.html (port 27 absent)

Typically seen on

nothing in normal modern deployment; a responsive 27/tcp is an anomaly worth investigating

Analyst note
A blank IANA reference and blank dates mean no original spec or date can be cited; the assignment is a legacy reservation with no known active protocol. Legitimate use today is unlikely.
[ 02 ] — Context

About port 27/udp.

Updated  ·  Confidence: High

Port 27/udp is registered with IANA as nsw-fe with the description "NSW User System FE," assignee Robert Thomas, and blank reference, registration-date, and modification-date fields (it is dual-registered identically on 27/tcp and 27/udp). The name refers to the National Software Works (NSW), a DARPA-funded distributed operating-system project of the mid-to-late 1970s built primarily by Bolt Beranek and Newman (BBN); the "FE" is the user-facing Front End component. NSW aimed to give uniform access to software tools spread across heterogeneous ARPANET hosts — a 1977 ACM paper describes an early version spanning TENEX, MULTICS, and IBM 360 machines in regular operation since May 1977, and a 1983 BBN technical report (DTIC ADA132320) gives the full architecture. The assignee name "Robert Thomas" is consistent with BBN personnel of that era. For a present-day analyst the assignment is of historical interest only: the NSW system has been defunct for decades, and no current software is known to use 27/udp for its registered purpose, so any UDP traffic on port 27 on a modern host should be treated as anomalous and investigated rather than expected. There is no RFC cited in the IANA record (the reference field is blank, not omitted), and the registry records no registration or modification date for this entry. Legacy IDS/firewall catalogs still carry detection rules for nsw-fe — for example, Clavister's COS application-control signature set lists it as an Application-Layer-Protocols family signature flagged on malformed traffic — but those rules classify activity on this port as anomalous, not as a live, expected service. No public CVE or security advisory specifically targets port 27/udp.

IANA assignment
nsw-fe — "NSW User System FE"; reference (blank — no RFC cited in IANA registry); assignee Robert Thomas; dual-registered 27/tcp + 27/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml); local registry cache the IANA Service Name and Transport Protocol Port Number Registry line 62
Range class
well-known / System Port (0–1023); assignment via IETF Review / IESG Approval [Confirmed] — IANA registry
Registration date
Unknown — blank in IANA registry; no date is recorded for this entry (not fabricated) [Confirmed] — IANA registry
Prevalence
nmap-services observed open-frequency 27/udp ≈ 0.000395 — very low (roughly 4 in 10,000 scanned hosts in the nmap-services sample); the paired 27/tcp row is lower at ≈ 0.000138. The figure records scan-observed openness, not surviving NSW use [Confirmed for the figures; Likely for the reading] — nmap-services dataset
Related ports
27/tcp (identical dual registration, same nsw-fe service name and description)

Primary use

IANA-assigned to the National Software Works (NSW) User System Front End, an ARPANET-era DARPA/BBN distributed network operating system; the system is long defunct and the port is effectively obsolete [Confirmed] — ACM 1977 "The National Software Works: A Distributed Processing System" (https://dl.acm.org/doi/10.1145/800179.810177); DTIC ADA132320 (https://archive.org/details/DTIC_ADA132320)

Other/unofficial uses

none verified; no current software is known to use this port for its registered purpose [Likely] — Clavister COS signature catalog lists a legacy nsw-fe detection signature only (https://docs.clavister.com/repo/cos-stream-application-control-signatures/4.10/doc/ch20s376.html)

Security implications

no public CVE or advisory specific to port 27/udp; any UDP traffic on port 27 on a modern host should be treated as anomalous and investigated. Third-party port databases (e.g. AuditMyPC) carry a generic "a Trojan or Virus has used this port in the past" notice but name no specific malware and list "Virus/Trojan: No" — treated as unsubstantiated

[Likely/Threat-reported] — https://www.auditmypc.com/udp-port-27.asp

Typically seen on

historically NSW/ARPANET research hosts (TENEX, MULTICS, IBM 360); on a modern network, an anomaly worth investigating

Analyst note
The NSW project is defunct; a responsive port 27/udp is statistically rare today and should be treated as anomalous (decoy, misconfiguration, or unrelated application) rather than a legitimate NSW front end.
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
nsw-fe UDP NSW User System FE 0.04%
nsw-fe TCP NSW User System FE 0.01%
IANA name
nsw-fe
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.