OSI Model & TCP/IP Explained: The 7 Layers of Networking for Cybersecurity


 HELLO FRIENDS

WELCOME TO MY CYPHER LOG

   Guys, in our past blog we have seen about basic safety measures in cyber security, types of attacks and viruses can happen in the virtual world and now we are going to dive deep into how security systems work in cyberspace.
And we can know more about this in our upcoming blogs.
Today I have learned about THE OSI models & TCP / IP and I am going to explain it by how I understood it.

LET'S GET INTO THE TOPICS

THE OSI MODEL

         The OSI model is nothing but The open system interconnection.
It is a conceptual framework of a computing system or telecommunication,
By seeing the interconnection in its name we can know that this could not be single protection to protect data, yeah it have 7 distinct layer and everything will be connected with one another to execute a safe and secure communications.
They are,
  • APPLICATION LAYER
  • PRESENTATION LAYER
  • SESSION LAYER
  • TRANSPORT LAYER
  • NETWORK LAYER
  • DATA LINK LAYER
  • PHYSICAL LAYER
It may look but difficult to memorize the order of these layers, so here is a cheat code for it,
All People Seem To Need Data Processing
In this we can use the first letters to not forgot the order of the layers.
In this we always starts with the last layer and move into one another,

Layer 7 : Application layer

   Application layer is where we interact with the network we can take the mobile applications as an example for this.
This is where the attacks like phishing and SQL injection takes place because the data will be decrypted here.

Layer 6 : Presentation layer

     Here is where the translation happens for the application to understand the data, decryption and encryption were handled by this layer.
This is the most important factor because if the encryption is weak attackers can decrypt it and use it as they want and here's where man in the middle attack takes place.

Layer 5 : Session layer

     It works as a manager who establish, maintains & terminates connection between application.
      Session hijacking is the attack happen here, if an attacker steals a session token they can take over the connection without needing the password, we have seen about this in our past blogs.

Layer 4 : Transport layer

     It ensures reliable data delivery uses ports, it actually actually works like a post man who delivering things through ports.
It's main protocols are TCP and UDP.
Port scanning and DDoS attack will Target this layer. Firewalls would primarily operate here by blocking specific ports.

Layer 3 : Network layer

    The network layer handles logical addressing and routing to find the best path to access the Internet and it's main protocol is IP.
Here the IP spoofing, DDoS and network segmentation can happen here.

Layer 2 : Data link layer

    Like network layer, it handles addressing too but in but it's physical addressing, The MAC addresses.
And it also detecting errors on the local network which we call LAN.
It's main protocol is Ethernet.
In this layer ARP spoofing, MAC flooding and Evil twin Wi-fi attacks can happen here and switches operate at this layer.

Layer 1 : Physical layer

     The physical layer plays the main role which will connect with the other system through cables, radio waves [ Wi-fi ], Fiber optics & hubs.
   The main attacks which can happen here are cable tapping, Physical theft of servers or jamming Wi-fi signals.

Let's move into next topic

THE TCP / IP MODEL 

      The OSI models which we have seen before was used for teaching tools.
The TCP / IP models is what we actually use in real time.
It compresses the 7 layers into 4  layers, let's how it works.

APPLICATION LAYER

     It also starts with the application layer but here it combines the 5, 6, 7 layers into single layer, which are the application, presentation and session layer in OSI models.
It uses HTTP, DNS, SMTP, SSH.

TRANSPORT LAYER

    It works same as the Transport layer in the OSI model which is the 4th layer in it.
It uses TCP, UDP.

INTERNET LAYER

    It works the same as the 3rd layer which is the Network layer.
It uses IP, ICMP.

NETWORK ACCESS LAYER

It combines the last two layers in OSI model which are Data link layer and The Physical layer.
It uses Ethernet, Wi-fi, MAC addresses.

Here we comes to the best part

THE INVESTIGATIONS

    When the investigators seizes packet capture file from a compromised network, they will read it layer by layer.
They would start checking the source or destination MAC addresses to identify is the traffic coming from an unauthorised device on the local network.
Then check the IP addresses to identify is that it is an malicious IP addresses.
Then they would check ports to know if the user's computer is transferring data through any unknown port.
They must inspect the payload is there a clear text password, a SQL injection attempt or a malicious script.

That's it guys this is what I have learned today, I hope you guys understood it well.

If you want study guide to know more you can get through this link.

                     THANK YOU

Comments

Popular posts from this blog

Day 2: Understanding the CIA Triad, AAA

Cryptography Basics: Encryption Types & Hashing Explained

Cyber Security Day 4: Understanding Layered Security & Defence in Depth