It's for SMB traffic (windows fle sharing and SAMBA). I don't know why your getting hit with a lot of it, but it would usually come from a random port above 1024 destined to upd or tcp 137 on your machine. There are a few other netbios ports as well, 138, 139, etc. If you are not running windows or SAMBA, I wouldn't worry much about it. Check to see if those ports are in fact open on your box. If they are open, and you need them, try to figure out the origin of the packets and why they are trying to connect to you. Normally, all netbios traffic should never be allowed to pass from your LAN to the WAN, unless its running through a VPN link.