320
Summary
- // typical exposure
- Internal-only — PTP is a low-latency, hardware-timestamped time-synchronization protocol built for internal OT/telecom/industrial LANs, documented as vulnerable to stealthy sync-degradation attacks with only partial mitigations, so it should never be exposed to the public internet.
- // if you see it open
- Peer-reviewed literature documents that PTP time-sync infrastructure is vulnerable to attacks that can stealthily degrade clock accuracy or disrupt synchronization, and that existing PTP security extensions only partially mitigate this. Despite dual TCP/UDP IANA registration, operational PTP traffic runs almost entirely over UDP or Layer-2 Ethernet for hardware-timestamping latency reasons, so TCP/320 activity does not match documented normal PTP behavior. No port-320-specific CVE or exploit was identified in this pass.
About port 320/tcp.
Port 320/tcp carries ptp-general, IANA's dual-registered (TCP and UDP) channel for Precision Time Protocol (PTP, IEEE 1588) general messages; it should stay on internal, trusted OT/telecom networks rather than be exposed to the public internet.
IANA's Service Names and Port Numbers registry lists 320 as ptp-general ("PTP General"), assigned to Kang_Lee, registered 2010-07-27, with an identical row for UDP/320 confirming true dual registration. The Reference column is blank — the assignment cites a named contact rather than an RFC, so no IANA RFC reference is reported.
PTP's "general" category covers Announce, Follow_Up, management, and signaling messages, distinct from the time-critical Sync/Delay_Req exchanges carried on the paired port 319 (ptp-event). PTP is deployed for sub-microsecond clock synchronization in telecom, power-grid/smart-grid, financial-exchange, and industrial-automation environments.
Despite IANA registering ptp-general for both TCP and UDP, real-world PTP traffic runs almost entirely over UDP (or raw Ethernet in some profiles) to preserve the low-latency hardware timestamping the protocol depends on; TCP/320 traffic is not a documented normal pattern, so a responsive TCP/320 host is unusual on its own terms even where PTP is legitimately deployed.
- IANA assignment
ptp-general— "PTP General"; reference blank (named contact [Kang_Lee], not an RFC); registered 2010-07-27; dual-registered 320/tcp + 320/udp, identical entries [Confirmed] — IANA Service Names and Port Numbers Registry- Range class
- well-known (0–1023)
- Prevalence/scanning stats
- Unknown — no dated, sourced count of internet-exposed 320/tcp or 320/udp hosts was found in this pass; not estimated [Unknown]
- Related ports
- 319/udp and 319/tcp (
ptp-event, time-critical PTP messages)
Primary use
Precision Time Protocol (IEEE 1588) general (non-time-critical) messages: Announce, Follow_Up, Delay_Resp, Pdelay_Resp_Follow_Up, management/signaling; paired with 319 (ptp-event) for time-critical messages
Security implications
peer-reviewed research documents attacks that can stealthily degrade PTP time-sync accuracy or disrupt clocks/networks, with existing security extensions only partially mitigating; no port-320-specific CVE found
Typically seen on
telecom, OT/industrial, power-grid, and financial-exchange internal networks running PTP grandmaster/slave devices
- Transport nuance
- TCP is IANA-registered but operational PTP traffic runs almost exclusively over UDP or Layer-2 Ethernet for hardware-timestamping latency reasons; TCP/320 is not a documented normal pattern [Likely] — Wikipedia PTP
- Deployment context
- telecom, power-grid/smart-grid, financial exchanges, industrial automation requiring sub-microsecond sync, typically on internal/OT networks [Confirmed] — Springer Cybersecurity journal (2021)
About port 320/udp.
Port 320/udp carries IEEE 1588 Precision Time Protocol (PTP) "general" messages, and it should stay restricted to trusted internal timing networks rather than being exposed to the public internet. It is the companion port to 319/udp: 319 carries timestamp-critical "event" messages (Sync, Delay_Req, Pdelay_Req, Pdelay_Resp), while 320 carries the non-timestamp-critical "general" messages (Announce, Follow_Up, Delay_Resp, Pdelay_Resp_Follow_Up, management, and signaling).
IANA registers 320/udp (and the dual-registered 320/tcp) as ptp-general, "PTP General," assignee [Kang_Lee], registered 2010-07-27. The IANA registry lists no RFC reference for this entry — the Reference column is genuinely blank, not an omission — so this page cites no RFC number for the assignment itself.
PTP synchronizes clocks across a network to sub-microsecond accuracy and is deployed in telecom backhaul (including 5G timing), financial trading (regulatory timestamp accuracy such as MiFID II), industrial automation, power-grid substation protection, and broadcast/AV-over-IP systems. Common implementations include the open-source ptp4l/phc2sys (linuxptp), Meinberg PTP software and grandmaster appliances, Chrony, and PTP stacks built into telecom-grade Cisco, Juniper, and Arista gear.
- IANA assignment
ptp-general— "PTP General"; reference blank (no RFC cited in registry); assignee[Kang_Lee]; dual-registered 320/tcp + 320/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry- Range class
- well-known (0–1023)
- Registration date
- 2010-07-27 [Confirmed] — IANA the IANA Service Name and Transport Protocol Port Number Registry
- Prevalence
- no verifiable scan-prevalence figure found for this pass [Unknown]
- Related ports
- 319/udp (PTP event messages) [Confirmed]
Primary use
IEEE 1588 Precision Time Protocol (PTP) "general" messages (Announce, Follow_Up, Delay_Resp, Pdelay_Resp_Follow_Up, management/signaling), paired with 319/udp's timestamp-critical "event" messages
Other/unofficial uses
none beyond PTP identified in this pass [Unknown]
Security implications
PTP is designed for trusted/local timing networks, not public internet exposure; base IEEE 1588 has no default authentication/integrity; RFC 7384 documents spoofing, replay, and rogue-master threats
Typically seen on
telecom backhaul (incl. 5G timing), financial trading systems (e.g. MiFID II timestamp accuracy), industrial automation, power-grid substations, broadcast/AV-over-IP
- Common implementations
- linuxptp (
ptp4l,phc2sys), Meinberg PTP software/appliances, Chrony, telecom-grade Cisco/Juniper/Arista PTP stacks [Likely] — https://wiki.wireshark.org/Protocols/ptp - Analyst note
- A responsive 320/udp on a public-facing host is unusual outside dedicated timing infrastructure and warrants checking whether the network segment should be internal-only.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| ptp-general | TCP | PTP General | 0.00% |
| ptp-general | UDP | PTP General | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.