ESET Smart Security Premium – Table of Contents

Network threat blocked

This notification appears when ESET detects suspicious network activity, such as port scanning attempts, exploit attempts, or traffic patterns associated with malicious software. In some cases, the activity originates from an application running on your device. You can use logs and network monitoring tools to identify the source of the traffic.


Note

The Network threat blocked notification is generated by the Intrusion Detection System (IDS). Depending on the type of network event, the notification may not identify the specific application responsible for the traffic.

arrow_down_homeHow to identify the application generating the traffic

You can find the type of threat and the related device IP address in the notification. Click Change handling of this threat to show the following options:

Continue blocking—Blocks detected threat. If you want to stop receiving notifications about this type of threat from the specific remote address, select the radio button next to Do not notify before you click Continue blocking. This will create an Intrusion Detection Service (IDS) rule with the following configuration:

Option

Block

Notify

Log

Do not notify

Default

No

No

Allow—Creates an Intrusion Detection Service (IDS) rule to allow the detected threat. Select one from the following options before you click Allow to specify the rule settings:

Option

Block

Notify

Log

Notify only when this threat is blocked

No

No

No

Notify whenever this threat occurs

No

Default

Default

Do not notify

No

No

No

A Network threat blocked event does not always indicate a real attack. Common causes include:

Legitimate devices on the local network, such as home routers, mesh nodes, Wi-Fi extenders, NAS devices, smart TVs and multimedia devices.

Applications running on your device may open or probe multiple ports or communicate with other devices on the network (for example, file-sharing, streaming, remote administration utilities or update services)

Malicious activity, such as port scanning attacks, communication from an infected device on the same network, or unwanted or suspicious processes running on your device.


Note

The information shown in this notification window may vary depending on the type of threat detected.

For more information about threats and other related terms, see Types of remote attacks or Types of detections.

To resolve the Duplicate IP addresses on network event, see our ESET Knowledgebase article.


Note

For additional details, see the logs in Tools > Log files > Network protection or Detections, or in Tools > Running processes.