Networking Security Fundamentals
Networking security is the practice of protecting data as it moves across and rests within networks. Because nearly every attack traverses a network at some point, understanding how packets flow, where trust boundaries live, and how attackers abuse protocols is foundational to defense. This guide is defensive: we cover how attacks work conceptually so you can detect and prevent them, and we practice only against systems you own or that explicitly permit testing.
The OSI and TCP/IP Models
Layered models let you reason about where a control belongs. A firewall filtering IPs lives at the network layer; a WAF inspecting HTTP lives at the application layer. Mapping a threat to a layer tells you which mitigation applies.
| OSI Layer | TCP/IP | Example | Threat / Control |
|---|---|---|---|
| 7 Application | Application | HTTP, DNS, TLS | Injection / WAF |
| 4 Transport | Transport | TCP, UDP | SYN flood / SYN cookies |
| 3 Network | Internet | IP, ICMP | Spoofing / firewall |
| 2 Data Link | Link | Ethernet, ARP | ARP spoof / DAI |
Common Ports
Knowing default ports speeds up both triage and hardening. Close or filter what you do not use.
| Port | Proto | Service | Secure Alternative |
|---|---|---|---|
| 22 | TCP | SSH | Key auth, no root |
| 53 | TCP/UDP | DNS | DoH/DoT, DNSSEC |
| 80 | TCP | HTTP | Redirect to 443 |
| 443 | TCP | HTTPS | TLS 1.3 |
| 3389 | TCP | RDP | VPN + MFA only |
| 3306 | TCP | MySQL | Bind localhost/TLS |
The TCP Three-Way Handshake
TCP establishes a reliable session with three packets. Understanding it explains scan behavior, SYN floods, and reset attacks.
Client Server
|------- SYN (seq=x) --------->| 1. Client requests connection
|<--- SYN-ACK (seq=y,ack=x+1)--| 2. Server acknowledges + replies
|------- ACK (ack=y+1) ------->| 3. Connection established
A SYN flood sends many SYNs without completing the handshake, exhausting the server's half-open connection table. The defense is SYN cookies, which encode connection state in the sequence number so no memory is reserved until the final ACK.
Common Network Attacks and Defenses
ARP Spoofing / MITM
ARP has no authentication, so an attacker on the same LAN can claim to own the gateway's IP and intercept traffic. Defenses: Dynamic ARP Inspection (DAI) on managed switches, DHCP snooping, static ARP for critical hosts, and end-to-end encryption (TLS, SSH) so intercepted traffic is unreadable.
DNS Spoofing / Cache Poisoning
Forged DNS responses redirect victims to malicious hosts. Defenses: DNSSEC validates records cryptographically; DNS over HTTPS (DoH) and DNS over TLS (DoT) encrypt the query path; use trusted resolvers and randomize source ports/query IDs.
DDoS
Volumetric, protocol, and application-layer floods aim to exhaust resources. Defenses: upstream scrubbing (Cloudflare, AWS Shield), rate limiting, anycast to spread load, and SYN cookies for protocol floods.
Port Scanning / Reconnaissance
Attackers map open services before exploiting them. Defenses: minimize the attack surface (close unused ports), deploy an IDS/IPS to alert on scan patterns, and drop rather than reject unsolicited packets so probes get no signal.
Legal note
Only scan hosts you own or that grant permission. scanme.nmap.org is provided by the Nmap project for practice. Unauthorized scanning can be a crime in many jurisdictions.
Firewalls
A stateless firewall filters each packet independently against rules. A stateful firewall tracks connection state, so return traffic for an established session is allowed automatically. Modern Linux uses nftables, which supersedes the older iptables.
# nftables: default-deny inbound, allow established + SSH + HTTPS
table inet filter {
chain input {
type filter hook input priority 0; policy drop;
ct state established,related accept
iif "lo" accept
tcp dport { 22, 443 } ct state new accept
ip protocol icmp icmp type echo-request limit rate 5/second accept
}
}
# Equivalent legacy iptables rules
iptables -P INPUT DROP
iptables -A INPUT -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT
iptables -A INPUT -i lo -j ACCEPT
iptables -A INPUT -p tcp -m multiport --dports 22,443 -j ACCEPT
Segmentation, VLANs, and Zero Trust
Flat networks let one compromised host reach everything. Segmentation divides the network into zones (DMZ, user, server, IoT) so lateral movement is contained. VLANs enforce logical separation at layer 2. Zero Trust assumes no implicit trust from network location: every request is authenticated, authorized, and encrypted regardless of where it originates. The principle is "never trust, always verify."
TLS and Why HTTPS Matters
TLS provides confidentiality, integrity, and authentication. TLS 1.3 (the 2018 standard, universal by 2026) simplified the handshake to a single round trip and removed legacy weak ciphers.
Client Server
|-- ClientHello (key share) -------->|
|<- ServerHello, cert, Finished -----| (1-RTT in TLS 1.3)
|-- Finished ----------------------->|
|==== encrypted application data ====|
HTTPS prevents on-path attackers from reading or tampering with traffic and authenticates the server via certificates. Enforce it with HSTS and redirect all HTTP to HTTPS.
VPNs: WireGuard and IPsec
WireGuard is a modern VPN using fixed, audited cryptography (Curve25519, ChaCha20-Poly1305) with a tiny codebase, making it fast and easy to audit. IPsec is the traditional standard with broad interoperability but more configuration complexity. Both create encrypted tunnels; WireGuard is the default choice for new deployments in 2026.
# WireGuard peer config (/etc/wireguard/wg0.conf)
[Interface]
PrivateKey = <your-private-key>
Address = 10.0.0.1/24
ListenPort = 51820
[Peer]
PublicKey = <peer-public-key>
AllowedIPs = 10.0.0.2/32
Endpoint = peer.example.com:51820
PersistentKeepalive = 25
Defensive Monitoring
IDS/IPS such as Suricata and Snort inspect traffic against signatures and anomalies; an IDS alerts, an IPS blocks. NetFlow/IPFIX records connection metadata (who talked to whom, how much) for after-the-fact investigation without capturing full payloads.
# Authorized lab scan of the Nmap project's test host
nmap -sV -T4 scanme.nmap.org
# Suricata rule to alert on a horizontal SYN scan
alert tcp any any -> $HOME_NET any (msg:"Possible port scan"; \
flags:S; threshold:type both, track by_src, count 20, seconds 5; \
sid:1000001; rev:1;)
Defense in depth
No single control is sufficient. Layer perimeter firewalls, segmentation, encryption, monitoring, and least privilege so that a bypass of one layer is caught by another.
Practice Exercises
- Capture a TCP three-way handshake in Wireshark on your own machine by browsing to a local web server, then identify the SYN, SYN-ACK, and ACK packets and their sequence numbers.
- Spin up a Linux VM and write default-deny
nftablesrules that allow only SSH and HTTPS inbound; verify withnft list ruleset. - Run an authorized
nmap -sVscan againstscanme.nmap.orgor a lab host on TryHackMe, and document the open services. - Configure a WireGuard tunnel between two VMs, then confirm encrypted connectivity by pinging across the tunnel and inspecting traffic in Wireshark (it should be opaque).
- Deploy Suricata on a lab network, scan a host you control, and confirm the IDS generates a port-scan alert in
fast.log. - Audit your home router: disable WPS and UPnP, enable WPA3, change default admin credentials, and update firmware; document each change and why it reduces risk.