Source-port logging

term

securityISP & telecom

Recording the remote source port and an accurate timestamp alongside the remote address, so that a report about an event remains attributable when the address is shared by many subscribers.

Without the port, an abuse report against a carrier-grade NAT address is unanswerable: the provider can only say that some hundreds of customers were behind that address at that moment. Most internet-facing services still log the address alone, which is why so many reports go nowhere and why blocking by address punishes a whole shared pool. It costs one extra field, and it is the single cheapest thing a service operator can do to make the abuse ecosystem work.

Also known as: rfc 6302, abuse logging, ip plus port plus timestamp

All glossary entries