dashboard radar bug_report school newspaper sensors

Learning Hub › Foundational Security › Network Security 101

Foundations 02 · Interactive guide

Network Security 101

Every attack crosses a network at some point. This guide explains how traffic is structured (layers, ports, packets), then puts you in charge of the tools that control and watch it: a firewall you configure yourself and an IDS/IPS you can switch between modes.

01

The layers: OSI and TCP/IP

Networking is built in layers, each relying on the one below. The 7-layer OSI model is the vocabulary security people use ("a layer-7 attack"); the 4-layer TCP/IP model is what the internet actually runs. Click a layer to see what lives there and how it gets attacked.

02

Ports and the TCP handshake

An IP address finds the machine; a port finds the service on it (0–65535). Many old protocols send everything in clear text, and each has a secure replacement. Attackers scan for open ports first, so every open port is part of your attack surface.

TCP three-way handshake

Press Connect to open a TCP connection to a web server on port 443.

03

Firewall lab: fix the rule base

A firewall checks each packet against an ordered list of rules. The first matching rule wins, and anything that matches nothing hits the implicit deny at the bottom. One badly placed "allow any" rule silently opens everything below it.

Your task · Only HTTPS should reach the web server from the internet; SSH only from the admin subnet; DNS only from inside. Run the test traffic, find why 3 packets get through that shouldn't, then fix the rules (disable or move them) until all 6 tests pass. Teaching model

Rule base (top to bottom)

Test traffic

Press Run tests.

Packet filter

Looks at each packet's addresses, ports and protocol. Fast, but has no memory of conversations.

Stateful firewall

Tracks connections, so replies to your outbound requests are allowed back in automatically. The standard today.

Next-gen firewall / WAF

Understands applications and users (layer 7). A web application firewall inspects HTTP for attacks like SQL injection.

04

IDS vs IPS: watch or block?

An intrusion detection system watches a copy of the traffic and raises alerts. An intrusion prevention system sits inline and can drop bad packets, at the cost that its mistakes block real users. Each detects with signatures (known patterns) or anomalies (unusual behaviour). Switch the mode and send traffic.

Mode

Send traffic

What a signature looks like (Suricata syntax, simplified sample)

alert http any any -> $HOME_NET any (
  msg:"Possible SQL injection - UNION SELECT";
  flow:to_server,established;
  http.uri; content:"union"; nocase; content:"select"; nocase; distance:0;
  classtype:web-application-attack; sid:1000001; rev:1; )
05

Packet anatomy: what Wireshark shows you

Each layer wraps the data from the layer above with its own header, like envelopes inside envelopes. Click any field to see what it means and why defenders care. Then flip to HTTPS and see what an eavesdropper loses.

06

Myth or fact?

Five things people often get wrong about network defences.

07

Sources & further reading

Next: see why perimeter firewalls are not enough on their own in the Zero Trust deep dive, and how TLS keeps packets private in Cryptography Basics.