contentintech
Learn/cybersecurity/Networking Security
Intermediate~22 min read

Networking Security

Network fundamentals, the OSI model, common network attacks, firewalls, segmentation, TLS, VPNs, and defensive monitoring.

TCP/IPFirewallsTLSVPN

Networking Security Fundamentals

Networking security is the practice of protecting data as it moves across and rests within networks. Because nearly every attack traverses a network at some point, understanding how packets flow, where trust boundaries live, and how attackers abuse protocols is foundational to defense. This guide is defensive: we cover how attacks work conceptually so you can detect and prevent them, and we practice only against systems you own or that explicitly permit testing.

The OSI and TCP/IP Models

Layered models let you reason about where a control belongs. A firewall filtering IPs lives at the network layer; a WAF inspecting HTTP lives at the application layer. Mapping a threat to a layer tells you which mitigation applies.

OSI LayerTCP/IPExampleThreat / Control
7 ApplicationApplicationHTTP, DNS, TLSInjection / WAF
4 TransportTransportTCP, UDPSYN flood / SYN cookies
3 NetworkInternetIP, ICMPSpoofing / firewall
2 Data LinkLinkEthernet, ARPARP spoof / DAI

Common Ports

Knowing default ports speeds up both triage and hardening. Close or filter what you do not use.

PortProtoServiceSecure Alternative
22TCPSSHKey auth, no root
53TCP/UDPDNSDoH/DoT, DNSSEC
80TCPHTTPRedirect to 443
443TCPHTTPSTLS 1.3
3389TCPRDPVPN + MFA only
3306TCPMySQLBind localhost/TLS

The TCP Three-Way Handshake

TCP establishes a reliable session with three packets. Understanding it explains scan behavior, SYN floods, and reset attacks.

text
Client                          Server
  |------- SYN (seq=x) --------->|   1. Client requests connection
  |<--- SYN-ACK (seq=y,ack=x+1)--|   2. Server acknowledges + replies
  |------- ACK (ack=y+1) ------->|   3. Connection established

A SYN flood sends many SYNs without completing the handshake, exhausting the server's half-open connection table. The defense is SYN cookies, which encode connection state in the sequence number so no memory is reserved until the final ACK.

Common Network Attacks and Defenses

ARP Spoofing / MITM

ARP has no authentication, so an attacker on the same LAN can claim to own the gateway's IP and intercept traffic. Defenses: Dynamic ARP Inspection (DAI) on managed switches, DHCP snooping, static ARP for critical hosts, and end-to-end encryption (TLS, SSH) so intercepted traffic is unreadable.

DNS Spoofing / Cache Poisoning

Forged DNS responses redirect victims to malicious hosts. Defenses: DNSSEC validates records cryptographically; DNS over HTTPS (DoH) and DNS over TLS (DoT) encrypt the query path; use trusted resolvers and randomize source ports/query IDs.

DDoS

Volumetric, protocol, and application-layer floods aim to exhaust resources. Defenses: upstream scrubbing (Cloudflare, AWS Shield), rate limiting, anycast to spread load, and SYN cookies for protocol floods.

Port Scanning / Reconnaissance

Attackers map open services before exploiting them. Defenses: minimize the attack surface (close unused ports), deploy an IDS/IPS to alert on scan patterns, and drop rather than reject unsolicited packets so probes get no signal.

Legal note

Only scan hosts you own or that grant permission. scanme.nmap.org is provided by the Nmap project for practice. Unauthorized scanning can be a crime in many jurisdictions.

Firewalls

A stateless firewall filters each packet independently against rules. A stateful firewall tracks connection state, so return traffic for an established session is allowed automatically. Modern Linux uses nftables, which supersedes the older iptables.

bash
# nftables: default-deny inbound, allow established + SSH + HTTPS
table inet filter {
  chain input {
    type filter hook input priority 0; policy drop;
    ct state established,related accept
    iif "lo" accept
    tcp dport { 22, 443 } ct state new accept
    ip protocol icmp icmp type echo-request limit rate 5/second accept
  }
}

# Equivalent legacy iptables rules
iptables -P INPUT DROP
iptables -A INPUT -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT
iptables -A INPUT -i lo -j ACCEPT
iptables -A INPUT -p tcp -m multiport --dports 22,443 -j ACCEPT

Segmentation, VLANs, and Zero Trust

Flat networks let one compromised host reach everything. Segmentation divides the network into zones (DMZ, user, server, IoT) so lateral movement is contained. VLANs enforce logical separation at layer 2. Zero Trust assumes no implicit trust from network location: every request is authenticated, authorized, and encrypted regardless of where it originates. The principle is "never trust, always verify."

TLS and Why HTTPS Matters

TLS provides confidentiality, integrity, and authentication. TLS 1.3 (the 2018 standard, universal by 2026) simplified the handshake to a single round trip and removed legacy weak ciphers.

text
Client                                Server
  |-- ClientHello (key share) -------->|
  |<- ServerHello, cert, Finished -----|   (1-RTT in TLS 1.3)
  |-- Finished ----------------------->|
  |==== encrypted application data ====|

HTTPS prevents on-path attackers from reading or tampering with traffic and authenticates the server via certificates. Enforce it with HSTS and redirect all HTTP to HTTPS.

VPNs: WireGuard and IPsec

WireGuard is a modern VPN using fixed, audited cryptography (Curve25519, ChaCha20-Poly1305) with a tiny codebase, making it fast and easy to audit. IPsec is the traditional standard with broad interoperability but more configuration complexity. Both create encrypted tunnels; WireGuard is the default choice for new deployments in 2026.

text
# WireGuard peer config (/etc/wireguard/wg0.conf)
[Interface]
PrivateKey = <your-private-key>
Address = 10.0.0.1/24
ListenPort = 51820

[Peer]
PublicKey = <peer-public-key>
AllowedIPs = 10.0.0.2/32
Endpoint = peer.example.com:51820
PersistentKeepalive = 25

Defensive Monitoring

IDS/IPS such as Suricata and Snort inspect traffic against signatures and anomalies; an IDS alerts, an IPS blocks. NetFlow/IPFIX records connection metadata (who talked to whom, how much) for after-the-fact investigation without capturing full payloads.

text
# Authorized lab scan of the Nmap project's test host
nmap -sV -T4 scanme.nmap.org

# Suricata rule to alert on a horizontal SYN scan
alert tcp any any -> $HOME_NET any (msg:"Possible port scan"; \
  flags:S; threshold:type both, track by_src, count 20, seconds 5; \
  sid:1000001; rev:1;)

Defense in depth

No single control is sufficient. Layer perimeter firewalls, segmentation, encryption, monitoring, and least privilege so that a bypass of one layer is caught by another.

Practice Exercises

  1. Capture a TCP three-way handshake in Wireshark on your own machine by browsing to a local web server, then identify the SYN, SYN-ACK, and ACK packets and their sequence numbers.
  2. Spin up a Linux VM and write default-deny nftables rules that allow only SSH and HTTPS inbound; verify with nft list ruleset.
  3. Run an authorized nmap -sV scan against scanme.nmap.org or a lab host on TryHackMe, and document the open services.
  4. Configure a WireGuard tunnel between two VMs, then confirm encrypted connectivity by pinging across the tunnel and inspecting traffic in Wireshark (it should be opaque).
  5. Deploy Suricata on a lab network, scan a host you control, and confirm the IDS generates a port-scan alert in fast.log.
  6. Audit your home router: disable WPS and UPnP, enable WPA3, change default admin credentials, and update firmware; document each change and why it reduces risk.

Section navigation