428
Summary
- // typical exposure
- Anomalous (rarely legitimately open) — IANA documents no functional protocol or legitimate application for this port, and no source that resolves attributes an application or malware association to it, so any observed traffic is anomalous rather than expected service activity.
- // analyst note
- absent a documented protocol or corroborated application, an open port 428 should be flagged for investigation rather than assumed benign.
- // if you see it open
- No confirmed CVE or malware family is documented for this port. No source that resolves attributes a trojan or malware association to it.
About port 428/tcp.
Port 428/tcp carries no documented protocol beyond an IANA registry entry for a service named ocs-cmu; with no confirmed application tied to it and no functional specification on file, it should be treated as unused by default and any observed traffic investigated rather than assumed legitimate.
IANA's registry lists ocs-cmu as the current, well-formed name, replacing an older alias ocs_cmu that the registry marks historic and unusable with many modern service-discovery mechanisms. The entry is dual-registered on both TCP and UDP, but the assignee and reference fields are both blank — no RFC, URL, or named organization is on file.
The only description string in the registry is the bare label "OCS_CMU," with no expansion or protocol description given. Web research turned up nothing beyond this: no vendor spec, no protocol write-up describing actual protocol behavior.
No source that resolves attributes any application or malware association to this port. The previously-checked aggregator pages (auditmypc.com, SpeedGuide, portsmaster.net) either serve a generic tool page with no per-port content, redirect off-domain, or were never actually read, so no third-party claim about this port is carried forward.
- IANA assignment
ocs-cmu(current);ocs_cmu(alias, marked historic) — description "OCS_CMU"; assignee blank; reference blank; dual-registered 428/tcp + 428/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry lines 849-857- Range class
- well-known (0–1023) [Confirmed]
- Prevalence
- nmap-services open-frequency 0.000013 [Confirmed] — this site's own tooling; no dated scanning-prevalence or exposure telemetry found beyond that figure [Unknown]
- Related ports
- no directly related cluster identified in research; contrast with the small well-known-service ports (7/9/11/13/17/19) as a general reference point for rarely-used low ports
Primary use
no documented protocol; IANA gives only the bare service name with no functional description
Other/unofficial uses
none found — no source that resolves attributes an application to this port [Unknown]
Security implications
no confirmed CVE or malware family; no source that resolves attributes a trojan or malware association to this port [Unknown]
Typically seen on
not established by any source found; treat an open port 428 as an anomaly warranting investigation [Unknown]
- Analyst note
- absent a documented protocol or corroborated application, an open port 428 should be flagged for investigation rather than assumed benign.
About port 428/udp.
Port 428/udp is registered with IANA as ocs-cmu, but no RFC, vendor specification, or independently verified deployment has ever surfaced for it; it should not be assumed to run any specific service, and a host answering on this port is anomalous rather than expected on the public internet or an internal network.
IANA's registry lists the current service name as ocs-cmu, with an older underscore-form alias ocs_cmu now marked historic and unsuitable for name-based service lookups. The description field contains only the literal text "OCS_CMU," with no reference/RFC cited and no listed assignee, and the assignment is dual-registered across both 428/tcp and 428/udp.
No protocol document, client, server, or vendor integration guide describing actual OCS_CMU behavior could be located.
No source that resolves attributes malware to port 428, and no scanning or honeypot telemetry source consulted calls out UDP/428 as actively probed or exploited.
- IANA assignment
ocs-cmu(current); historic aliasocs_cmu(deprecated underscore form); description literally "OCS_CMU"; reference blank; assignee Unknown; dual-registered 428/tcp + 428/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry- Range class
- well-known (0–1023) [Confirmed]
- Prevalence
- nmap-services open-frequency 0.000329 [Confirmed] — this site's own tooling; no scanning/honeypot telemetry found beyond that figure [Unknown]
- Related ports
- no established related-port cluster identified for this assignment [Unknown]
Primary use
Unknown — no RFC, spec, or vendor documentation describing actual protocol behavior found [Unknown]
Other/unofficial uses
None found [Unknown]
Security implications
no confirmed CVE or named malware family; no source that resolves attributes malware to this port; no scanning/honeypot telemetry flags this port [Unknown]
Typically seen on
no known production deployments identified [Unknown]
- Analyst note
- 428/udp is a registered-but-undocumented IANA name; a responsive host on this port is unusual and should be treated as a signal to investigate rather than a recognized service.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| ocs_cmu | UDP | — | 0.03% |
| ocs_cmu | TCP | ocs-cmu | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.