Network port detail · UDP/TCP

499

Iso-ill
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// typical exposure
Anomalous (rarely legitimately open) — Measured open-frequency for 499/tcp is 0 and the one identified real-world ISO-ILL application uses a different port (1611) entirely, so a legitimately open port 499 is not expected and any observed traffic should be investigated.
// analyst note
an open port 499 has no measured baseline (frequency 0) and no confirmed legitimate application; treat it as anomalous and investigate rather than assume interlibrary-loan traffic.
// if you see it open
No confirmed software binds to port 499 as of an August 2026 search. The one identified ISO-ILL-speaking product, Atlas Systems/OCLC's ILLiad (paired with Ex Libris Alma/Rapido), documents its ISO ILL traffic on TCP port 1611 (Alma side uses 9001), not 499 — a registered-vs-observed mismatch. Malware association is unconfirmed: AuditMyPC's port-499 pages could not be verified for a specific verdict, and no CVE/NVD or IDS-vendor record references port 499. A claim that SNPP uses port 499 was checked and is false (SNPP is port 444).
[ 01 ] — Context

About port 499/tcp.

Updated  ·  Confidence: Medium

Port 499/tcp is registered with IANA as iso-ill for the ISO ILL Protocol, a library interlibrary-loan messaging standard, but it should not be treated as expected public-internet traffic: no software has been confirmed running on this port as of an August 2026 search, and its measured open-frequency reading is zero.

The IANA registry lists iso-ill on both 499/tcp and 499/udp, with assignee Mark H. Needleman and a blank Reference column — there is no RFC to point to, and no registration date is recorded.

The underlying protocol is ISO ILL (Interlibrary Loan), standardized as ISO 10160/10161, which lets library systems exchange peer-to-peer requests for loanable or copyable items across different ILL software platforms. This appears to be an early registration tied to that ISO standard rather than an IETF-defined protocol.

The one identifiable real-world ISO-ILL-speaking product line — Atlas Systems/OCLC's ILLiad, paired on the other side with Ex Libris Alma/Rapido — documents its ISO ILL traffic running on TCP port 1611 (with port 9001 used on the Alma side), not port 499. That is a documented mismatch between the IANA-registered port and the port actually used by known ILL software.

A separate search result claiming that SNPP (Simple Network Paging Protocol) uses port 499 was checked and found incorrect; SNPP is registered to port 444, not 499, so that association was excluded from these findings.

IANA assignment
iso-ill — "ISO ILL Protocol"; reference (blank — no RFC cited in IANA registry); assignee Mark H. Needleman; dual-registered 499/tcp + 499/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry iso-ill 499/tcp
Range class
well-known (0–1023) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry iso-ill 499/tcp
Prevalence
nmap-services open-frequency 499/tcp = 0 (sampled, not observed open); 499/udp ≈ 0.000511 [Confirmed] — this site's own tooling
Related ports
1611/tcp (ILLiad's actual ISO ILL port, per vendor docs); 444/tcp (snpp, a distinct protocol ruled out as a port-499 association) [Likely] — https://help.oclc.org/Resource_Sharing/ILLiad/Troubleshooting/What_ports_are_required_for_ILLiad

Primary use

ISO ILL (Interlibrary Loan) peer-to-peer messaging protocol, standardized as ISO 10160/10161, for exchanging interlibrary-loan requests between library systems

[Likely] — https://en.wikipedia.org/wiki/ISO_10161

Other/unofficial uses

none identified as of an August 2026 search [Unknown]

Security implications

no confirmed software binds to port 499 today; the one identified ISO-ILL product (Atlas/OCLC ILLiad) uses TCP 1611 instead; malware association unconfirmed

[Likely] — https://help.oclc.org/Resource_Sharing/ILLiad/Troubleshooting/What_ports_are_required_for_ILLiad

Typically seen on

no confirmed hosts as of an August 2026 search; legacy/library ILL contexts only per the protocol's registration [Unknown]

Analyst note
an open port 499 has no measured baseline (frequency 0) and no confirmed legitimate application; treat it as anomalous and investigate rather than assume interlibrary-loan traffic.
[ 02 ] — Context

About port 499/udp.

Updated  ·  Confidence: Medium

Port 499/udp is IANA-registered as iso-ill for the ISO ILL (Interlibrary Loan) Protocol; it is a legacy library-systems assignment that should stay internal to trusted library networks rather than sit open on the public internet. IANA lists no RFC reference for this assignment, and no vendor documentation confirms which product, if any, binds to the UDP variant on the wire today.

The ISO ILL protocol (ISO 10160 service definition, ISO 10161 protocol specification, first published 1993) defines peer-to-peer messaging between library systems to request and manage interlibrary loans — one library's system asking another to lend or supply an item. IANA registers iso-ill identically on both 499/tcp and 499/udp under assignee Mark H. Needleman, with a blank Reference field.

Library resource-sharing software families implement the ISO ILL protocol, but no vendor documentation reviewed confirms a binding to port 499 on either transport. The one identified ISO-ILL-speaking product, Atlas Systems/OCLC's ILLiad (paired with Ex Libris Alma/Rapido), documents its ISO ILL traffic running on TCP port 1611 (Alma side on 9001) — not port 499. The port association asserted by some third-party listings comes only from the shared IANA service name, not from confirmed on-the-wire vendor evidence.

No CVE or malware family is recorded against 499/udp in the sources checked as of an August 2026 search. A general auditmypc.com summary carries the site's standard disclaimer template rather than a substantive verdict and is not treated as evidence either way; a separately-sourced trojan-port reference table (chebucto.ns.ca, dated 2004-07-25) does not list port 499 among commonly-probed or trojan-associated ports.

IANA assignment
iso-ill — "ISO ILL Protocol"; reference (blank); assignee Mark H. Needleman; dual-registered 499/tcp + 499/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry iso-ill 499/udp
Range class
system/well-known (0–1023) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry
Prevalence
nmap-services open-frequency 499/udp = 0.000511 (~0.05%); 499/tcp = 0 (sampled, not observed open) [Confirmed] — this site's own tooling
Related ports
499/tcp (identical iso-ill assignment); see the /port/ hub for adjacent system-range assignments

Primary use

ISO ILL (Interlibrary Loan) Protocol — peer-to-peer library resource-sharing messaging per ISO 10160/10161

[Confirmed] — https://en.wikipedia.org/wiki/ISO_10161

Other/unofficial uses

none documented; UDP registration appears to be a paired reservation alongside the TCP assignment rather than a distinct documented UDP-specific use

[Likely] — the IANA Service Name and Transport Protocol Port Number Registry

Security implications

no CVE or malware family recorded as of an August 2026 search; not listed in the chebucto.ns.ca trojan-port table

[Likely] — http://www.chebucto.ns.ca/~rakerman/trojan-port-table.html

Typically seen on

no confirmed hosts as of an August 2026 search; legacy/library ILL contexts only per the protocol's registration, not a confirmed vendor binding to this port

[Unknown] — https://help.oclc.org/Resource_Sharing/ILLiad/Troubleshooting/What_ports_are_required_for_ILLiad
Analyst note
An open 499/udp outside a confirmed library-systems deployment is statistically rare and unverified against specific vendor port bindings — treat as worth confirming rather than assuming malicious or benign.
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
iso-ill UDP ISO ILL Protocol 0.05%
iso-ill TCP ISO ILL Protocol 0.00%
IANA name
iso-ill
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.