448
Summary
- // typical exposure
- Internal-only — ddm-ssl is the TLS-encrypted variant of IBM's plaintext DDM/DRDA remote-database-access protocol (446/tcp ddm-rdb); encryption protects credentials and query data in transit but does not change its nature as a raw database wire protocol, so like its plaintext sibling it belongs on a trusted internal or VPN-protected network rather than facing the public internet directly.
- // analyst note
- treat an open 448/tcp as a probable TLS-secured DDM/DRDA database channel best confined to a trusted or VPN-connected network; investigate any listener not tied to a known IBM i or DB2 deployment.
- // if you see it open
- As of an August 2026 check, SANS Internet Storm Center's port-448 tracker showed only routine background scanning (daily top-source hit counts in the single digits to low 30s), with no CVE entries or abuse reports tied to the port. No malware or trojan association is documented for port 448 as of that check. 448/tcp adds SSL/TLS to the same DRDA channel that runs in plaintext on 446 (ddm-rdb) and 447 (ddm-dfm); the encryption protects credentials and query data in transit but does not change its underlying nature as a raw database wire protocol, so it belongs behind a firewall or VPN rather than facing the public internet directly.
About port 448/tcp.
Port 448/tcp carries ddm-ssl, the SSL/TLS-encrypted variant of IBM's Distributed Data Management (DDM) remote-database access protocol; like its plaintext sibling on 446/tcp, it belongs on a trusted internal or VPN-protected network rather than being exposed directly to the public internet.
IANA's Service Names and Port Numbers registry dual-registers 448 as ddm-ssl on both TCP and UDP, description "DDM-Remote DB Access Using Secure Sockets," assignee and contact Steven Ritland. The Reference column is blank — no RFC documents this assignment — and no registration or modification date is recorded for the entry.
DDM is IBM's architecture for remote access to host data resources; DRDA (Distributed Relational Database Architecture) is the relational-database application built on it. IANA registers two companion ports: 446 (ddm-rdb, the base plaintext DRDA channel) and 447 (ddm-dfm, distributed file management) — 448 adds SSL/TLS to the same DRDA traffic. Generic port-reference sources tie the service to IBM i (AS/400/iSeries) database connectivity, consistent with the IANA description, but this is not independently corroborated by primary IBM documentation.
As of an August 2026 check, SANS Internet Storm Center's port-448 tracker recorded only routine background scanning — daily top-source hit counts in the single digits to low 30s — with no CVE entries or abuse reports tied to the port. No malware or trojan association is documented for port 448 as of that check.
- IANA assignment
ddm-ssl— "DDM-Remote DB Access Using Secure Sockets"; Reference column blank; assignee and contact Steven Ritland; dual-registered 448/tcp + 448/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry ddm-ssl 448/tcp, ddm-ssl 448/udp- Range class
- well-known (0–1023); source artifact labels this the "system" range [Confirmed] — this site's own tooling (port 448 entry)
- Registration/modification dates
- both blank in the IANA registry for this entry — left null, not fabricated [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry ddm-ssl 448/tcp
- Prevalence
- nmap-services open-frequency 448/tcp = 0.00005 (~0.005%); 448/udp = 0.000511 (~0.0511%) [Confirmed] — this site's own tooling (port 448 entry)
- Related ports
- 446/tcp
ddm-rdb(unencrypted DDM remote relational database access — the base protocol this port secures); 447/tcpddm-dfm(DDM distributed file management) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry ddm-rdb 446/tcp, ddm-dfm 447/tcp
Primary use
SSL/TLS-encrypted IBM DDM/DRDA remote database access — the secure counterpart to the plaintext ddm-rdb service on 446/tcp [Confirmed/Likely] — the IANA Service Name and Transport Protocol Port Number Registry ddm-ssl 448/tcp, https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml?search=448
Other/unofficial uses
none corroborated as of an August 2026 search; a single uncorroborated SEO-style port-list mention of a Windows "DDEKit"/Dynamic Data Exchange association was found but excluded for lack of independent sourcing [Unknown]
Security implications
SANS ISC shows only routine background scanning as of an August 2026 check, no CVE or abuse-report entries; no malware/trojan association documented
Typically seen on
IBM i (AS/400/iSeries) hosts using DDM/DRDA database connectivity over SSL/TLS, per generic secondary port-reference sources — not independently corroborated by primary IBM vendor documentation in this search
- Analyst note
- treat an open 448/tcp as a probable TLS-secured DDM/DRDA database channel best confined to a trusted or VPN-connected network; investigate any listener not tied to a known IBM i or DB2 deployment.
About port 448/udp.
Port 448/udp carries ddm-ssl, IBM's TLS-secured member of the DDM database-access port family; it should stay restricted to authenticated, trusted-network or VPN-connected clients rather than sit exposed to the open internet.
IANA's Service Name and Transport Protocol Port Number Registry lists ddm-ssl as "DDM-Remote DB Access Using Secure Sockets," dual-registered on both 448/tcp and 448/udp under the same name, assignee Steven Ritland, with a blank Reference column — no RFC defines the protocol, and no registration or modification date is recorded for either row.
The ddm-ssl name mirrors 446/ddm-rdb ("DDM-Remote Relational Database Access," plaintext) as its SSL/TLS-secured counterpart; the adjacent port 447/ddm-dfm ("DDM-Distributed File Management") is a related but distinct plaintext DDM-family service, not itself database access.
IBM's own support and documentation pages describe enabling SSL/TLS for DDM on IBM i (AS/400/iSeries/System i) systems to secure remote DB2 for i database connections, though direct retrieval of those pages returned HTTP 403 in this search, so the identification is tagged Likely rather than Confirmed.
No non-IBM software was found using port 448 in an August 2026 search; the IBM i DDM/DRDA server and its DB2 for i database engine are the only applications documented against this port, consistent with an IBM-associated registry assignee rather than a broadly adopted general-purpose protocol.
Measured prevalence is low: the nmap-services open-frequency data bundled with this site records 448/udp at approximately 0.000511 (about 0.05% of scanned hosts) and 448/tcp at approximately 0.00005 (about 0.005%). Third-party lookup sites rate the SSL-secured variant as lower risk than its plaintext siblings, and no CVE or malware association was found for this port as of an August 2026 search.
- IANA assignment
ddm-ssl— "DDM-Remote DB Access Using Secure Sockets"; reference (blank — no RFC cited in IANA registry); assignee Steven Ritland; dual-registered 448/tcp + 448/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry ddm-ssl 448/udp- Range class
- well-known (System Ports, 0–1023) [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry
- Prevalence
- nmap-services open-frequency 448/udp ≈ 0.000511 (~0.051%); 448/tcp ≈ 0.00005 (~0.005%) [Confirmed] — this site's own tooling
- Related ports
- 448/tcp (same
ddm-sslservice name, dual-registered); 446/tcp+udp (ddm-rdb, plaintext DB access); 447/tcp+udp (ddm-dfm, plaintext file management) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry ddm-rdb 446/tcp, the IANA Service Name and Transport Protocol Port Number Registry ddm-dfm 447/tcp
Primary use
SSL/TLS-secured DDM (Distributed Data Management) remote database access — the encrypted counterpart to 446/ddm-rdb — used by IBM i (AS/400/iSeries/System i) systems to reach DB2 for i databases [Likely] — https://www.ibm.com/support/pages/ssltls-enablement-ddm-ibm-i-ibm-i, https://www.ibm.com/docs/en/i/7.2.0?topic=network-ports-port-restrictions
Other/unofficial uses
none found beyond the IBM i DDM/DRDA server as of an August 2026 search
Security implications
third-party lookup sites rate DDM-SSL low-risk due to TLS encryption; no CVE or malware association found as of an August 2026 search; DShield/SpeedGuide scan-activity data could not be retrieved (HTTP 403)
Typically seen on
IBM i (AS/400, iSeries, System i) database servers using SSL-secured DDM for remote DB2 for i access
- Analyst note
- Treat 448/udp as IBM i/DB2-for-i remote database traffic and restrict it to trusted networks or VPN — encryption reduces eavesdropping risk relative to plaintext DDM/DRDA but does not make broad internet exposure of a database-access port appropriate.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| ddm-ssl | UDP | ddm-byte | 0.05% |
| ddm-ssl | TCP | ddm-byte | 0.01% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.