Network port detail · UDP/TCP

558

Sdnskmp
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// if you see it open
No confirmed active real-world service was found using this port as of a September 2026 search, and no CVE or malware family is recorded against it in that search. There is no curated basis for classifying an intended exposure posture beyond a dormant registry assignment, so an open 558/tcp on any host should be treated as unexpected and worth investigating rather than assumed to be routine, since no modern service is known to legitimately listen there.
[ 01 ] — Context

About port 558/tcp.

Updated  ·  Confidence: Likely  ·  5 sources  ·  How this page is checked

Port 558/tcp is IANA-registered to the label sdnskmp with no confirmed active real-world deployment found, so it should not be exposed to the public internet, and any host found with it open should be investigated as unexpected rather than assumed routine.

The registration traces to sdnskmp, short for the SDNS Key Management Protocol. NIST IR 4262 (February 1990) compiled the NSA-developed Secure Data Network System (SDNS) key management specifications (SDN.601, SDN.902, SDN.903, SDN.906), an OSI-layer security architecture effort spanning the late 1980s into the 1990s that defined protocols for distributing key material to lower-layer security services. The IANA registry itself carries no reference document and no assignee organization for this port.

No current, verifiably-confirmed software or service was found using port 558 by name as of a September 2026 search. A small number of low-authority port-lookup aggregator sites list alternate, unofficial descriptions for the port, but these are unsourced, contradict the IANA sdnskmp assignment, and could not be corroborated against any vendor documentation, blog post, or forum thread describing actual observed traffic, so they are not repeated here.

Measured against the site's nmap-services-derived prevalence dataset, 558/tcp carries an open-frequency of exactly 0, a sampled reading rather than an absence of data, and consistent with a registered-but-effectively-unused assignment. The companion 558/udp entry shows a small nonzero frequency of 0.000461.

Exposure
No evidence of any current legitimate service running on 558/tcp was found; the assignment appears effectively dormant rather than actively deployed.
Scanning target status
No record found of port 558 being a notable internet-wide scanning target as of a September 2026 search.
Malware association
auditmypc.com's port 558 page carries no virus/trojan warning for this port, a sourced negative rather than a confirmed-safe verdict.
CVE
No CVE tied specifically to port 558 or sdnskmp is recorded in the NVD as of a September 2026 search.
If seen open
Treat an open 558/tcp as worth investigating rather than routine, given the absence of any confirmed modern service that should be listening there.
IANA Service Name
sdnskmp [Confirmed] (the IANA Service Name and Transport Protocol Port Number Registry)
IANA Description
SDNSKMP [Confirmed] (the IANA Service Name and Transport Protocol Port Number Registry)
IANA Reference
None listed in the registry [Confirmed] (the IANA Service Name and Transport Protocol Port Number Registry)
Dual Registration
Also registered as sdnskmp on 558/udp [Confirmed] (the IANA Service Name and Transport Protocol Port Number Registry)
Prevalence (tcp)
Measured open-frequency of 0 in the nmap-services-derived dataset [Confirmed] (this site's own tooling)
Prevalence (udp, for context)
Measured open-frequency of 0.000461 [Confirmed] (this site's own tooling)

Malware/trojan association

None found; auditmypc.com lists no warning for this port [Likely] (https://www.auditmypc.com/tcp-port-558.asp)

Port
558/tcp [Confirmed] (the IANA Service Name and Transport Protocol Port Number Registry)
Assignee Organization
Not recorded in the registry [Confirmed] (the IANA Service Name and Transport Protocol Port Number Registry)
Historical background (SDNS program)
sdnskmp derives from the NSA-developed Secure Data Network System (SDNS) project; NIST published its key management specification (SDN.601/902/903/906) as NIST IR 4262 in February 1990 [Likely] (https://csrc.nist.gov/pubs/ir/4262/final)
Current real-world usage
No specific software confirmed using this port as of a September 2026 search [Unknown]
[ 02 ] — Context

About port 558/udp.

Updated  ·  Confidence: Likely  ·  9 sources  ·  How this page is checked

Port 558/udp carries SDNSKMP, the SDNS Key Management Protocol, a legacy 1980s/1990s U.S. Secure Data Network System (SDNS) key-management service with no evidence of active modern deployment; it should not be treated as a service that legitimately needs public internet exposure.

The IANA registry lists the name "sdnskmp" for both TCP and UDP at port 558 but carries no RFC or reference document, and no description beyond the bare name. Third-party port-lookup sites echo the same registration without adding independent technical detail, consistent with a protocol that predates the modern IETF documentation convention.

No credible, dated report of a specific application or vendor product generating real-world traffic on 558/udp was found. Several port-lookup aggregators list unrelated legacy cross-references — OpenView Session Manager, QuickTime Streaming Server, and Apple Filing Protocol — but these read as coincidental aggregator noise tied to unrelated ports rather than sourced sightings of activity on 558/udp itself.

SANS Internet Storm Center records low-volume, unattributed scanning against port 558 as of a September 2026 check; the report does not separate TCP from UDP, consistent with generic internet background-radiation sweeps rather than exploitation of a known service. The port-data corpus records an open-frequency of 0.000461 for 558/udp and 0 for 558/tcp, both indicating the port is essentially never observed open in the wild. No CVE or malware/trojan association is recorded for 558/udp as of a September 2026 search.

Exposure
Anomalous — SDNS-KMP is an obsolete 1980s SDNS-era protocol with no documented modern deployment, so a host with 558/udp open should be treated as unusual and investigated rather than assumed to run a legitimate current service.
CVE
None recorded in the NVD as of a September 2026 search.
Recommendation
Treat an open 558/udp as anomalous on any host; no documented legitimate service requires it to be reachable, internally or externally.
IANA Service Name
sdnskmp [Confirmed] (the IANA Service Name and Transport Protocol Port Number Registry sdnskmp 558/udp)
IANA Reference
None — blank in the registry [Confirmed] (the IANA Service Name and Transport Protocol Port Number Registry sdnskmp 558/udp)
Registration Scope
Registered for both TCP and UDP at port 558 [Confirmed] (the IANA Service Name and Transport Protocol Port Number Registry sdnskmp 558/tcp and sdnskmp 558/udp)

Protocol Background

SDNS Key Management Protocol, tied to the 1980s/1990s U.S. Secure Data Network System security architecture; no IETF RFC documents it [Likely] (http://www.t1shopper.com/tools/port-number/558/)

Malware/Trojan Association

Not listed as malware-associated as of a September 2026 search [Likely] (https://www.auditmypc.com/udp-port-558.asp)

Port
558/udp [Confirmed] (the IANA Service Name and Transport Protocol Port Number Registry sdnskmp 558/udp)
Modern Application Use
No credible, dated sighting of specific software generating traffic on 558/udp found [Likely] (https://www.speedguide.net/port.php?port=558)
Scanning Activity
SANS ISC records only low-volume, unattributed background-scan traffic as of a September 2026 check [Likely] (https://isc.sans.edu/data/port/558)
Open-Frequency (UDP)
0.000461 measured in the port-data corpus [Confirmed] (this site's own tooling)
Open-Frequency (TCP)
0 measured in the port-data corpus [Confirmed] (this site's own tooling)
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
sdnskmp UDP — 0.05%
sdnskmp TCP — 0.00%
IANA name
sdnskmp
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.