2009-08-22

Why Is Google Port Scanning Me?

I’m used to the normal ‘Internet background radiation’ of hackers/bots scanning the common ports on my router (SSH, VNC, etc.) but recently I’ve noticed scans of multiple ports from IPs registered to Google.

e.g., I'm getting a few thousand a day of these:
[INFO] Sat Aug 22 11:43:44 2009 Blocked incoming TCP packet from 66.102.7.191:80 to xxx:47414 as ACK received but there is no active connection
[INFO] Sat Aug 22 11:43:44 2009 Blocked incoming TCP packet from 66.102.7.191:80 to xxx:15370 as ACK received but there is no active connection
[INFO] Sat Aug 22 11:43:44 2009 Blocked incoming TCP packet from 66.102.7.191:80 to xxx:63879 as ACK received but there is no active connection
[INFO] Sat Aug 22 11:43:44 2009 Blocked incoming TCP packet from 66.102.7.191:80 to xxx:7748 as ACK received but there is no active connection
Looking back I see these requests have been coming for months but have increased in frequency recently.

They come from a range of IPs which whois reports are assigned to Google:
66.102.7.101
66.102.7.191
74.125.15.22
74.125.15.93
74.125.15.100
74.125.15.157
74.125.19.118
74.125.103.33
74.125.103.96
74.125.103.97
etc.
So for what purpose is Google port scanning me?

UPDATE:
These are likely just delayed responses to a web page request made by your browser just before you quit your web browser.