Skip to main content

Port Details

Port
3702
Transport
UDP
Service
WS-Discovery
IANA service name
ws-discovery
Range
User port (1024-49151)

Security Exposure

The protocol is designed for local use, but devices that respond to it from the internet can be abused for reflected DDoS. CISA's amplification alert lists WS-Discovery with an amplification factor of 10 to 500. Shadowserver notes it has been abused for reflected DDoS since 2019 and measured an average amplification factor of 293 in its 2023 scans.

Hardening

  • +Block UDP 3702 from the public internet, as Shadowserver recommends.
  • +Disable WS-Discovery on devices that do not need automatic discovery.
  • +Keep discovery traffic within local segments and do not port-forward 3702 on edge routers.

Monitoring

Watch flow data for outbound UDP responses from source port 3702 to internet addresses, which should not occur on a well-configured network.

Tools for Auditing and Monitoring WS-Discovery

Nmap

Free / Commercial
Penetration Testing Tools

Network discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.

LicenseNPSL-0.95 (Nmap Public Source License, not OSI-approved)
PlatformLinux, macOS, Windows

Zeek

Open Source
Network Monitoring Tools

Network security monitoring framework that translates raw packet traffic into structured transaction logs and network events.

LicenseBSD-3-Clause
PlatformLinux, FreeBSD, macOS, OpenBSD

Suricata

Open Source
Network Monitoring Tools

High-speed network intrusion detection, prevention, and security monitoring engine with deep protocol parsing capabilities.

LicenseGPL-2.0-only
PlatformLinux, FreeBSD, macOS, Windows

Frequently Asked Questions

What is port 3702 used for?→

UDP 3702 carries WS-Discovery, a multicast protocol that devices use to announce and locate services on a local network.

Should port 3702 be reachable from the internet?→

No. Shadowserver advises blocking 3702/udp from the public internet because exposed WS-Discovery services are abused for amplified DDoS.

Is WS-Discovery TCP or UDP?→

Discovery messages are sent over UDP, using multicast to 239.255.255.250 on port 3702. IANA registers both transports.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 3702 is not guaranteed to be WS-Discovery. Exploited-in-the-wild data from the CISA KEV catalog (CC0).