I was thinking of filtering by packet length. Since I am the only one knowing the magic length and so if someone wants to do a port scan, it is unlikely he is going to try 65496 different packet length for each port....
Tho, somehow, I don't see the traffic coming in in dmesg, which the script...