Something is listening on a port you do not recognise, and ss is the tool that will tell you what. This guide uses ss to list listening services, identify the process behind a socket, narrow results to a protocol or port, and inspect useful TCP state without changing anything. The examples use the ss supplied by the local iproute2 package. Allow about 10 minutes for the first pass.
You need a shell on the Linux machine you want to inspect. Ordinary socket listings work as your normal user. Some process details, security contexts, BPF information, and sockets owned by other users may require elevated privileges, so use sudo only for the particular command that needs it.
Check the installed version first. Version matters because ss is shipped as part of iproute2, and its available socket families and output fields follow that package rather than a separate ss release.
ss --version
dpkg-query -W -f='${Package} ${Version}\n' iproute2
On this host the installed package reports iproute2 6.1.0-1ubuntu6.4. Your output may differ. Treat the output from your own machine as the authority when a field is absent or formatted differently.
Start with listening TCP sockets. The -l option selects listeners, -t selects TCP, and -n keeps addresses, ports, and service numbers numeric. Numeric output avoids a distracting reverse lookup and makes repeated checks easier to compare.
ss -ltn
Typical output has columns for state, receive and send queues, local address and port, and peer address and port:
State Recv-Q Send-Q Local Address:Port Peer Address:Port
LISTEN 0 4096 127.0.0.1:8080 0.0.0.0:*
A listener bound to 127.0.0.1 accepts local connections only. A listener on 0.0.0.0 can accept IPv4 connections on the machine's interfaces, subject to firewall rules and the service configuration. Do not read a listening row as proof that a service is reachable from the network.
To include the owning process, add -p:
sudo ss -ltnp
The process column can show a process name, PID, and file descriptor. A blank process column often means that your user cannot inspect that process, so try the command with sudo before concluding that the socket has no owner.
ss -t selects TCP, but the default view omits listening sockets and shows established non-listening connections. Add -a when you need both listening and non-listening entries.
ss -tan
ss -tln
The first command shows all TCP entries in numeric form. The second is a compact listener check. For a quick count rather than a long list, use the summary mode:
ss -s
The summary is collected without parsing a full socket listing. This makes it useful on a busy machine where printing every row would be slow or unwieldy.
Filters are placed after the options. State names include established, listening, time-wait, close-wait, and syn-sent. This finds established TCP connections involving HTTPS on either end:
ss -tn state established '( dport = :https or sport = :https )'
Use a numeric port when you need an unambiguous result that does not depend on the services database:
ss -tn state established '( dport = :443 or sport = :443 )'
To find connections reaching a particular destination network, combine a destination filter with a port filter. The CIDR prefix in this example matches the documented host syntax:
ss -tn dst 192.0.2.0/24 dport = :443
192.0.2.0/24 is reserved for documentation. Replace it with the network you are investigating. Quote expressions containing parentheses so the shell does not interpret them before ss receives them. Adjacent predicates imply and; you can also write and, or, or not explicitly.
TCP state does not apply to every socket. Use -u for UDP, and include -a if you want unconnected and listening-style entries as well as connected ones:
ss -uan
For local inter-process communication, use Unix domain sockets:
ss -x -a
You can filter a Unix socket by its path. The address is a glob pattern, and Unix addresses do not have a port:
ss -x src /tmp/.X11-unix/*
Other selectors include -4 and -6 for IP version, -w for raw sockets, and -S for SCTP. The installed manpage lists the families supported by this version, including unix, inet, inet6, link, netlink, vsock, tipc, xdp, and MPTCP-related queries.
Once a filter has reduced the list, add detail deliberately. -o displays TCP timer information, which helps explain retransmission or closing behaviour. -i adds internal TCP information such as round-trip time, congestion window, retransmission timeout, and bytes sent or received.
ss -ntoi state established dst 192.0.2.10
ss -nto state time-wait
For ownership, use -p. For socket memory counters, use -m. These options can make the output wide, so keep the query narrow and add -o to place each socket on one line when copying results into a ticket:
sudo ss -ntopm state established dport = :443
The -e option adds extended fields such as the owning UID, socket inode, and kernel socket cookie. These identifiers are diagnostic values, not stable application names.
Most ss commands are read-only. Do not use -K casually: it attempts to forcibly close matching IPv4 and IPv6 sockets. Closing a production connection can interrupt a request, replication stream, or remote session, and there is no general undo command. Before using it, run the same filter without -K, save the output, confirm the addresses and ports, and obtain approval for the interruption.
Remember that -a means all sockets for the selected tables, not only active connections. Conversely, the no-option default hides listeners, so an empty result does not prove that no network service exists. Add -l or -a when checking that assumption.
Name resolution can also mislead an investigation. The default may display service names such as https instead of 443. Use -n for stable numeric output, and use -r only when resolved names are useful to you.
iproute2 and ss versions.ss -ltn and identify owners with sudo ss -ltnp.-o, -i, -m, or -p for investigation.-K filter without it before closing sockets.