It was my wife's iPhone that reacted to the UDP port scan, so I am limited in what I can check/verify.
I checked the SYSLOG for her iPhone's traffic before the event, and saw nothing out of the ordinary, except for that moment in time the UDP port scan occurred.
To me it appears that the UDP port scan started first. Then somehow something 'leaked' through and touched her iPhone, causing it to react with a small flood of UDP traffic directed back to the scanning node's public IP address.
Things that make you go: "Hmmmmmmmmmmm"
I checked the SYSLOG for her iPhone's traffic before the event, and saw nothing out of the ordinary, except for that moment in time the UDP port scan occurred.
To me it appears that the UDP port scan started first. Then somehow something 'leaked' through and touched her iPhone, causing it to react with a small flood of UDP traffic directed back to the scanning node's public IP address.
Things that make you go: "Hmmmmmmmmmmm"
"