In my internet Worm Protection log, I notice that 1-2 times nearly everyday I get the following alert
Portscan agains (my machine) detected and blocked
Intruder 192.168.0.1 (Domain (53) )
Risk- medium
Attacked IP My PC
attack port 49911 (this number varies though)
I knbow that 192.168.0.1 is my DSL router. I know that at times they say that this is maybe overload, but I wonder if since incoming goes through my DSL box, is this a legit attack and it shows 192.168.0.1 because it's filtered through my DSL box ?
Its blocked so that is cool. I use NAV2008 and do not want to change at this time. Just curious if I'm getting attacked nearly everyday or is this a "false positive"