A useful oversimplification for network surveillance?

Also, this seems like a good time to mention a couple of
additionl resources on trending specific TCP and UDP port
probes (if you haven't already seen them):

http://www.dshield.org/
http://www.mynetwatchman.com/

- ferg