CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice
Network Basics and Security: formula sheet
Key formulas
- Classification by size
- PAN (personal, few metres) < LAN (building or campus) < MAN (city) < WAN (country or world)
- Use this order to answer any comparison question. Range, cost and speed differences follow from it.
- Mesh links needed (full mesh)
- Links = n(n − 1) ÷ 2
- n is the number of nodes. Each node needs n − 1 ports. Use it to show why full mesh is costly.
- Device and OSI layer
- Hub: Layer 1 | Switch and bridge: Layer 2 | Router: Layer 3 | Gateway: up to Layer 7
- A basic switch works on MAC addresses. A router works on IP addresses.
- Topology failure point
- Bus: main cable | Star: central device | Ring: any node or link (single ring) | Mesh: none single
- Almost every topology question asks about the effect of one failure.
- OSI layers, top to bottom
- Application → Presentation → Session → Transport → Network → Data Link → Physical
- Memory aid: All People Seem To Need Data Processing. Layers are numbered 7 down to 1.
- TCP/IP layers, top to bottom
- Application → Transport → Internet → Link (Network Access)
- Some texts show five layers by splitting Link into Data Link and Physical. State which version you use.
- Layer mapping
- OSI 5-6-7 = TCP/IP Application; OSI 4 = Transport; OSI 3 = Internet; OSI 1-2 = Link
- Use this to compare the two models in one line.
- Data unit at each layer
- Application/Presentation/Session: data; Transport: segment (TCP) or datagram (UDP); Network: packet; Data Link: frame; Physical: bits
- Questions often ask for the name of the data unit.
- Addressing at each layer
- Transport: port number; Network: IP address; Data Link: MAC address
- Port identifies the application, IP identifies the host, MAC identifies the device on the local network.
- IPv4 address size
- 32 bits = 4 octets × 8 bits; each octet 0 to 255; total addresses = 2^32
- 2^32 is about 4.3 billion. Written in dotted decimal.
- IPv6 address size
- 128 bits = 8 groups × 16 bits; total addresses = 2^128
- Written in hexadecimal separated by colons. :: may replace one run of zero groups, only once per address.
- Common default ports (1)
- HTTP 80 | HTTPS 443 | FTP 21 (control) and 20 (data) | SSH 22 | SFTP 22
- SFTP runs over SSH, so it shares port 22.
- Common default ports (2)
- SMTP 25 | DNS 53 | DHCP 67/68 | POP3 110 | IMAP 143
- These are default ports. Services can be configured on other ports.
- HTTPS composition
- HTTPS = HTTP + TLS/SSL encryption
- Gives confidentiality, server authentication and integrity.
- CIA triad
- Confidentiality + Integrity + Availability
- Map each attack to the goal it breaks. DoS/DDoS: availability. MITM: confidentiality and integrity. Ransomware: mainly availability.
- DoS vs DDoS
- DoS = one source; DDoS = many sources (botnet)
- Same aim: make a service unavailable. The difference is the number of attacking sources.
- Virus vs worm vs trojan
- Virus = needs host file; Worm = self-spreads; Trojan = disguised, no self-replication
- This is the usual three-way comparison asked in exams.
- Phishing vs spoofing
- Phishing = tricking a person; Spoofing = faking an identity
- Phishing commonly uses spoofing, but not all spoofing is phishing.
- Firewall vs IDS vs IPS
- Firewall = filter by rules; IDS = detect + alert; IPS = detect + block
- IDS is passive and out of the traffic path. IPS is active and inline.
- Types of firewall
- Packet filter → Stateful inspection → Proxy/application → NGFW
- Inspection gets deeper at each stage, with more processing cost.
- Detection methods
- Signature-based (known attacks) | Anomaly-based (unusual behaviour)
- Signature misses new attacks. Anomaly gives more false positives.
- Access control (AAA)
- Authentication → Authorisation → Accounting
- Who are you, what can you do, what did you do.
- Least privilege
- Access granted = minimum needed for the role
- Reduces damage from errors, misuse and compromised accounts.
- VPN purpose
- Public network + encryption tunnel = private communication
- Gives confidentiality and integrity of data in transit. It does not remove malware.
- Symmetric encryption
- Ciphertext = Encrypt(Plaintext, K); Plaintext = Decrypt(Ciphertext, K)
- Same key K at both ends. Fast. Key sharing is the problem.
- Asymmetric encryption for confidentiality
- Sender encrypts with receiver's public key; receiver decrypts with receiver's private key
- Only the receiver can read the message.
- Digital signature creation
- Signature = Encrypt(Hash(Message), Sender's private key)
- Gives authenticity, integrity and non-repudiation. It does not hide the message.
- Digital signature verification
- Decrypt(Signature, Sender's public key) = Hash(Message received) ⇒ valid
- Any mismatch means the message or signature was altered or the signer is different.
- Hashing vs encryption
- Hash: one-way, no key to reverse, fixed length. Encryption: two-way, key needed, output size varies with input
- Use this as your comparison line.
- Digital certificate contents
- Certificate = Holder's name + Public key + Validity period + CA's digital signature
- The CA's signature lets others trust the binding.
- CIA triad
- Confidentiality + Integrity + Availability
- Core security goals. Name each, define it, and give one control for each.
- Risk
- Risk = Threat × Vulnerability × Impact (or Likelihood × Impact)
- A conceptual relationship, not a precise calculation. Use it to explain prioritising risks.
- Residual risk
- Residual risk = Inherent risk − Risk reduced by controls
- Conceptual. Management decides whether residual risk is acceptable.
- NIST CSF core functions
- Identify → Protect → Detect → Respond → Recover (Govern added in version 2.0)
- State the version if you list six functions.
- ISO 27001 cycle
- Plan → Do → Check → Act
- Continual improvement of the ISMS. Certification is by an independent body.
- Incident response phases
- Prepare → Detect and analyse → Contain → Eradicate → Recover → Post-incident review
- Common NIST-style sequence. Other models merge or rename phases.
Quick revision
- A network is a set of connected devices that share data and resources.
- Know the main network types by size and reach, and the common topologies.
- The OSI model has seven layers and the TCP/IP model has fewer; be able to map one to the other.
- An IP address identifies a device on a network, and you must know the difference between IPv4 and IPv6.
- Protocols are agreed rules for communication; link each common protocol to its purpose.
- Malware, phishing, denial of service and interception are different attacks, so define each separately.
- Firewalls filter traffic, while intrusion detection systems alert and intrusion prevention systems block.
- Encryption protects confidentiality; digital signatures support authenticity, integrity and non-repudiation.
- Symmetric encryption uses one shared key; asymmetric encryption uses a public and private key pair.
- Frameworks and standards give an organisation a structured way to manage security risk.
- In a case answer, name the threat, name the control, then give the compliance recommendation.
Common mistakes
- Calling the internet a LAN or treating every office network as a WAN. Fix: Decide by coverage and ownership. One site under one owner is a LAN. Linked sites across cities form a WAN.
- Saying a hub and a switch work the same way. Fix: A hub sends data to all ports. A switch learns addresses and sends data only to the target port, which cuts collisions and snooping.
- Writing the OSI layers in the wrong order or numbering from the top. Fix: Use the memory aid and write the numbers 7 to 1 beside the names before you start.
- Saying TCP/IP has five or seven layers without explanation. Fix: State that the standard version has four layers, and mention the five-layer variant only as a note.
- Saying IPv4 has 64 bits or IPv6 has 64 bits. Fix: Remember 32 for IPv4 (4 × 8) and 128 for IPv6 (8 × 16).
- Claiming DNS gives the website's content. Fix: DNS only returns the IP address. The web server then supplies the page over HTTP or HTTPS.
- Saying a DDoS attack is just a bigger DoS attack. Fix: State that DoS comes from one source and DDoS from many distributed devices, usually a botnet.
- Calling every malware a virus. Fix: Use virus only for code that needs a host file. Use worm, trojan, ransomware and spyware for the others.
- Saying an IDS blocks attacks. Fix: Remember D is for detect and alert only. P is for prevent, which means block.
- Treating a firewall as protection against everything. Fix: State its limits: it cannot stop threats from inside, malware that arrives through allowed traffic, or social engineering.
Exam tips
- Prepare a one-page comparison of PAN, LAN, MAN and WAN. This is the most likely differentiate question.
- For topologies, always give advantages, disadvantages and the effect of a single failure. Examiners look for all three.
- In case-based questions, recommend a topology or network type for the facts given, such as budget, number of sites or need for uptime, and justify it.
- Name the address each device uses: MAC for switches and bridges, IP for routers. It shows depth in few words.
- Link the answer to security where possible, for example a WAN needs a VPN, a shared bus is easy to tap.
- Always give layer number, name, function and one example. Marks follow these four items.
- For comparison questions, use a point-by-point format with the same heads for both models.
- Link the model to security where you can: for example, firewalls and routers filter at the Network and Transport layers, and encryption such as TLS is associated with the upper layers.