"Sometimes, if a computer system is affected too much by a port scan, one can argue that the port scan was, in fact, a denial-of-service (DoS) attack, which is usually an offense. "
http://www.sans.org/security-resources/idfaq/port_scanning_l...
http://www.sans.org/security-resources/idfaq/port_scanning_l...