Port 3702: Web Services Dynamic Discovery
WS-Discovery is a multicast discovery protocol for locating services on a local network. The OASIS specification assigns port 3702 with the IPv4 multicast address 239.255.255.250.
Port Details
Security Exposure
The protocol is designed for local use, but devices that respond to it from the internet can be abused for reflected DDoS. CISA's amplification alert lists WS-Discovery with an amplification factor of 10 to 500. Shadowserver notes it has been abused for reflected DDoS since 2019 and measured an average amplification factor of 293 in its 2023 scans.
Hardening
- +Block UDP 3702 from the public internet, as Shadowserver recommends.
- +Disable WS-Discovery on devices that do not need automatic discovery.
- +Keep discovery traffic within local segments and do not port-forward 3702 on edge routers.
Monitoring
Watch flow data for outbound UDP responses from source port 3702 to internet addresses, which should not occur on a well-configured network.
Tools for Auditing and Monitoring WS-Discovery
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Zeek
Open SourceNetwork security monitoring framework that translates raw packet traffic into structured transaction logs and network events.
Suricata
Open SourceHigh-speed network intrusion detection, prevention, and security monitoring engine with deep protocol parsing capabilities.
Related Tool Categories
Frequently Asked Questions
What is port 3702 used for?→
UDP 3702 carries WS-Discovery, a multicast protocol that devices use to announce and locate services on a local network.
Should port 3702 be reachable from the internet?→
No. Shadowserver advises blocking 3702/udp from the public internet because exposed WS-Discovery services are abused for amplified DDoS.
Is WS-Discovery TCP or UDP?→
Discovery messages are sent over UDP, using multicast to 239.255.255.250 on port 3702. IANA registers both transports.
Sources
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 3702 is not guaranteed to be WS-Discovery. Exploited-in-the-wild data from the CISA KEV catalog (CC0).