I have a similar smattering of these as well but they come in the form ether.IP.UDP.unknown ...1.2048.17.?
I see these packets all over the place and generally associated with external addresses. I'm concerned simply because i see many external sources associated with this coming inbound. I've noted that in some cases this is a long list of potential udp ports, but the ? mark in the protocol port reall throws me. Running version 2.1.1
These are protocol ports not listed in the file of known TCP ports from IANA. All ports not listed will be grouped into a .?/unknown port. The reason why these are grouped is to avoid tens of thousands of port numbers to store, swamping the memory of the probe.
Usually, when you seen many of these .? ports it is either filesharing, Skype, or other VoIP protocols. They use random ports.