Network port detail · TCP/UDP

319

Ptp-event
Protocol(s)
TCP/UDP
Range
System (0-1023)

Summary

// typical exposure
Internal-only — PTP time-synchronization traffic is meant for trusted internal, telecom-operator, or OT/industrial network segments; the base protocol has no built-in authentication, so 319/tcp should never be exposed to the public internet, and a TCP listener is itself atypical since real deployments use UDP or raw Ethernet.
// analyst note
A responsive 319/tcp is atypical given PTP's UDP/Ethernet-centric real-world usage; verify it is genuine PTP tooling rather than an unrelated or anomalous service, and confirm it sits on a trusted internal/OT/telecom segment rather than facing the public internet.
// if you see it open
Base IEEE 1588-2008 PTP has little to no built-in authentication, exposing it to master-clock impersonation, sync-message injection, and delay-attack timing manipulation by an on-path or same-segment attacker. IEEE 1588-2019 added an optional security extension (Annex K) but adoption is not universal. Researchers have demonstrated these attacks degrading or disrupting dependent systems, including 5G base-station synchronization. PTP is intended for trusted internal, telecom, or OT network segments, not public exposure.
[ 01 ] — Context

About port 319/tcp.

Updated  ·  Confidence: Medium

Port 319/tcp is IANA-registered as ptp-event for IEEE 1588 Precision Time Protocol (PTP) event messages, but real-world PTP deployments run almost exclusively over UDP or raw Ethernet — a live TCP listener on 319 is atypical for the protocol, so this port should be treated as internal-only rather than something ever exposed to the public internet.

IANA lists 319 as dual-registered on both TCP and UDP with identical values: service name ptp-event, description "PTP Event," assignee and contact both Kang Lee, registered 2010-07-27. No RFC or other reference is cited in the registry for this entry, and that field is left blank rather than guessed.

Port 319 carries time-critical PTP "event" messages (Sync, Delay_Req, Pdelay_Req, Pdelay_Resp), paired with port 320 for general/management messages (Announce, Follow_Up, Delay_Resp, signaling). The IEEE 1588 standard and virtually all real deployments (default, telecom, and power profiles) transport PTP over UDP multicast/unicast or directly over Ethernet (Annex F / 802.1AS) — not TCP. IANA's tcp entry reads as a registry-level reservation rather than a reflection of common real-world TCP usage.

Typical software includes linuxptp (ptp4l/phc2sys), PTPd, and partial support in chrony, alongside PTP stacks built into telecom and networking gear (Cisco, Juniper, Nokia SR Linux) and industrial or utility equipment. Deployment contexts include telecom transport networks, financial-trading infrastructure needing precise timestamps, industrial automation/TSN, and power-grid substations running the IEC 61850-9-3 utility PTP profile.

IANA assignment
ptp-event — "PTP Event"; reference (blank — no RFC cited in IANA registry); assignee/contact Kang Lee; registered 2010-07-27; dual-registered 319/tcp + 319/udp with identical values [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry
Range class
well-known (0–1023)
Prevalence
Unknown — no nmap-services frequency or dated scanning/exposure statistics for 319/tcp were found in this pass [Unknown]
Related ports
320/udp (PTP general/management messages) [Confirmed] — Wireshark PTP protocol page

Primary use

IEEE 1588 Precision Time Protocol event messages (Sync, Delay_Req, Pdelay_Req, Pdelay_Resp), paired with port 320 for general/management PTP messages

[Confirmed] — Wireshark PTP protocol page, Wikipedia

Other/unofficial uses

IANA's TCP registration is atypical of real deployments — PTP standard profiles and virtually all implementations run over UDP or raw Ethernet (Annex F/802.1AS), not TCP

[Likely] — Wireshark PTP protocol page, Wikipedia

Security implications

base PTP (IEEE 1588-2008) lacks built-in authentication, enabling master-clock spoofing, sync injection, and delay-attack manipulation; optional Annex K security extension (IEEE 1588-2019) not universally adopted; demonstrated impact on 5G base-station sync

[Likely] — Springer/BMC Cybersecurity 2021 & 2023, MDPI Sensors 2022, arXiv 2510.06421

Typically seen on

telecom transport networks, industrial automation/TSN, power-grid substations (IEC 61850-9-3), financial-trading infrastructure requiring precise timestamps

[Likely] — Nokia SR Linux docs, Cisco Nexus 9000 config guide
Analyst note
A responsive 319/tcp is atypical given PTP's UDP/Ethernet-centric real-world usage; verify it is genuine PTP tooling rather than an unrelated or anomalous service, and confirm it sits on a trusted internal/OT/telecom segment rather than facing the public internet.
[ 02 ] — Context

About port 319/udp.

Updated  ·  Confidence: Medium

Port 319/udp carries ptp-event, the IEEE 1588 Precision Time Protocol (PTP) event-message channel used for sub-microsecond clock synchronization across a network; it should generally stay restricted to trusted LAN, data-center, or carrier segments rather than exposed to the public internet.

IANA registers the service name as ptp-event ("PTP Event"), dual-registered on both 319/tcp and 319/udp with identical assignee, contact, and a registration date of 2010-07-27 (assignee Kang Lee, IEEE Instrumentation & Measurement Society TC-9). The IANA Reference column is blank — no RFC is cited for this entry, and that blank is reported as-is rather than inferring IEEE 1588 as an RFC (it is an IEEE standard, not an IETF document).

319/udp specifically carries the timestamp-critical PTP event messages — Sync, Delay_Req, Pdelay_Req, and Pdelay_Resp. Its companion port, 320/udp, carries PTP general messages (Announce, Follow_Up, Delay_Resp, management/signaling). PTP operates in a master-slave (grandmaster) hierarchy, in both multicast and unicast modes.

Deployment is concentrated in trusted, purpose-built network segments rather than the open internet: telecom fronthaul/backhaul timing, financial-trading clock-sync requirements (MiFID II RTS 25), power-utility substation automation (IEC 61850-9-3 / IEEE C37.238), broadcast/pro-AV-over-IP (SMPTE ST 2059), and industrial automation. Reference implementations include the open-source linuxptp (ptp4l/phc2sys) and ptpd, alongside native support in carrier-grade switch/router platforms and dedicated grandmaster time-server appliances.

No confirmed Shodan/Censys internet-exposure statistics for 319/udp were found in this research pass; general port-database sites describe the port's function but not scan prevalence. That leaves internet-exposure prevalence Unknown rather than fabricated, pending a direct scan-data query.

IANA assignment
ptp-event — "PTP Event"; reference (blank — no RFC cited in IANA registry); assignee [Kang_Lee] (IEEE Instrumentation & Measurement Society TC-9); registered 2010-07-27; dual-registered 319/tcp + 319/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry-650, https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml
Range class
well-known (0–1023) [Confirmed]
Prevalence
Unknown — no confirmed Shodan/Censys internet-exposure statistics found in this pass [Unknown] — https://www.speedguide.net/port.php?port=319, https://portsmaster.net/port-319/
Related ports
320/udp (PTP general messages: Announce, Follow_Up, Delay_Resp, management/signaling) [Confirmed]

Primary use

IEEE 1588 Precision Time Protocol (PTP) event messages — Sync, Delay_Req, Pdelay_Req, Pdelay_Resp — for network clock synchronization; companion port 320/udp carries PTP general messages

[Confirmed] — https://en.wikipedia.org/wiki/Precision_Time_Protocol, https://wiki.wireshark.org/Protocols/ptp

Other/unofficial uses

none independently confirmed beyond core PTP event-message transport [Unknown]

Common software

linuxptp (ptp4l/phc2sys), ptpd; native support in Cisco NX-OS/IOS-XR and Juniper Junos; dedicated grandmaster appliances (e.g., Meinberg)

[Likely] — https://wiki.wireshark.org/Protocols/ptp

Security implications

BMCA/rogue-grandmaster spoofing, delay and asymmetric-delay attacks, Sync/Follow_Up message spoofing, DoS against PTP daemons; optional 1588-2008/2019 security extensions have documented gaps; 2025 research demonstrated OS/kernel-level exploits manipulating host time without altering observable network traffic [Likely] — https://arxiv.org/html/2510.06421v1, https://ieeexplore.ieee.org/document/8973494/, https://link.springer.com/article/10.1186/s42400-021-00080-y

Typically seen on

trusted LAN/data-center/carrier timing segments, not the open internet [Likely]

Deployment context
telecom fronthaul/backhaul timing, financial trading (MiFID II RTS 25), power-utility substations (IEC 61850-9-3 / IEEE C37.238), broadcast/pro-AV-over-IP (SMPTE ST 2059), industrial automation [Likely] — https://bst.cisco.com/quickview/bug/CSCvx09634
Analyst note
PTP's base profile lacks strong built-in authentication, so 319/320 should be filtered from untrusted/public networks; an internet-reachable 319/udp is unusual and worth investigating rather than assuming it is legitimate.
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
ptp-event TCP PTP Event 0.00%
ptp-event UDP PTP Event 0.00%
IANA name
ptp-event
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.