An attack or bad source packet?

I've been watching a computer over the past week attempt to connect to a few high level ports (3094, 3095, 3093) on my small home network (AT&T@Home). My Debian firewall is running Ipchains, which I think is set up right and blocks most ports. All the traffic is coming from port 80 with an IP address resolving to an odd host at compaq.com. Could a poorly configured web server return packets for days? I've definitely visited Compaq's web site in the past month, so perhaps it's a left over session? Or perhaps it's an attack or just my mis-configured firewall? Thank you for your help.


