That is what we like to call the background noise of the internet. Scanners are always scanning. Try this as an experiment sometime: make a brand new instance on your favorite cloud provider, and just run tcpdump on it for a few hours. You'll see all kinds of cool things: from people scanning for HTTP, Telnet, people scanning for SSH servers with weak passwords, router exploits with shellcode embedded in a UDP packet, back-scatter from DDoS attacks, cool stuff. Honestly looking at each packet and trying to figure out what's going on is a pretty great way to learn.