Skip to content

CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice

Network Basics and Security: formula sheet

Full chapter guide

Key formulas

Classification by size
PAN (personal, few metres) < LAN (building or campus) < MAN (city) < WAN (country or world)
Use this order to answer any comparison question. Range, cost and speed differences follow from it.
Mesh links needed (full mesh)
Links = n(n − 1) ÷ 2
n is the number of nodes. Each node needs n − 1 ports. Use it to show why full mesh is costly.
Device and OSI layer
Hub: Layer 1 | Switch and bridge: Layer 2 | Router: Layer 3 | Gateway: up to Layer 7
A basic switch works on MAC addresses. A router works on IP addresses.
Topology failure point
Bus: main cable | Star: central device | Ring: any node or link (single ring) | Mesh: none single
Almost every topology question asks about the effect of one failure.
OSI layers, top to bottom
Application → Presentation → Session → Transport → Network → Data Link → Physical
Memory aid: All People Seem To Need Data Processing. Layers are numbered 7 down to 1.
TCP/IP layers, top to bottom
Application → Transport → Internet → Link (Network Access)
Some texts show five layers by splitting Link into Data Link and Physical. State which version you use.
Layer mapping
OSI 5-6-7 = TCP/IP Application; OSI 4 = Transport; OSI 3 = Internet; OSI 1-2 = Link
Use this to compare the two models in one line.
Data unit at each layer
Application/Presentation/Session: data; Transport: segment (TCP) or datagram (UDP); Network: packet; Data Link: frame; Physical: bits
Questions often ask for the name of the data unit.
Addressing at each layer
Transport: port number; Network: IP address; Data Link: MAC address
Port identifies the application, IP identifies the host, MAC identifies the device on the local network.
IPv4 address size
32 bits = 4 octets × 8 bits; each octet 0 to 255; total addresses = 2^32
2^32 is about 4.3 billion. Written in dotted decimal.
IPv6 address size
128 bits = 8 groups × 16 bits; total addresses = 2^128
Written in hexadecimal separated by colons. :: may replace one run of zero groups, only once per address.
Common default ports (1)
HTTP 80 | HTTPS 443 | FTP 21 (control) and 20 (data) | SSH 22 | SFTP 22
SFTP runs over SSH, so it shares port 22.
Common default ports (2)
SMTP 25 | DNS 53 | DHCP 67/68 | POP3 110 | IMAP 143
These are default ports. Services can be configured on other ports.
HTTPS composition
HTTPS = HTTP + TLS/SSL encryption
Gives confidentiality, server authentication and integrity.
CIA triad
Confidentiality + Integrity + Availability
Map each attack to the goal it breaks. DoS/DDoS: availability. MITM: confidentiality and integrity. Ransomware: mainly availability.
DoS vs DDoS
DoS = one source; DDoS = many sources (botnet)
Same aim: make a service unavailable. The difference is the number of attacking sources.
Virus vs worm vs trojan
Virus = needs host file; Worm = self-spreads; Trojan = disguised, no self-replication
This is the usual three-way comparison asked in exams.
Phishing vs spoofing
Phishing = tricking a person; Spoofing = faking an identity
Phishing commonly uses spoofing, but not all spoofing is phishing.
Firewall vs IDS vs IPS
Firewall = filter by rules; IDS = detect + alert; IPS = detect + block
IDS is passive and out of the traffic path. IPS is active and inline.
Types of firewall
Packet filter → Stateful inspection → Proxy/application → NGFW
Inspection gets deeper at each stage, with more processing cost.
Detection methods
Signature-based (known attacks) | Anomaly-based (unusual behaviour)
Signature misses new attacks. Anomaly gives more false positives.
Access control (AAA)
Authentication → Authorisation → Accounting
Who are you, what can you do, what did you do.
Least privilege
Access granted = minimum needed for the role
Reduces damage from errors, misuse and compromised accounts.
VPN purpose
Public network + encryption tunnel = private communication
Gives confidentiality and integrity of data in transit. It does not remove malware.
Symmetric encryption
Ciphertext = Encrypt(Plaintext, K); Plaintext = Decrypt(Ciphertext, K)
Same key K at both ends. Fast. Key sharing is the problem.
Asymmetric encryption for confidentiality
Sender encrypts with receiver's public key; receiver decrypts with receiver's private key
Only the receiver can read the message.
Digital signature creation
Signature = Encrypt(Hash(Message), Sender's private key)
Gives authenticity, integrity and non-repudiation. It does not hide the message.
Digital signature verification
Decrypt(Signature, Sender's public key) = Hash(Message received) ⇒ valid
Any mismatch means the message or signature was altered or the signer is different.
Hashing vs encryption
Hash: one-way, no key to reverse, fixed length. Encryption: two-way, key needed, output size varies with input
Use this as your comparison line.
Digital certificate contents
Certificate = Holder's name + Public key + Validity period + CA's digital signature
The CA's signature lets others trust the binding.
CIA triad
Confidentiality + Integrity + Availability
Core security goals. Name each, define it, and give one control for each.
Risk
Risk = Threat × Vulnerability × Impact (or Likelihood × Impact)
A conceptual relationship, not a precise calculation. Use it to explain prioritising risks.
Residual risk
Residual risk = Inherent risk − Risk reduced by controls
Conceptual. Management decides whether residual risk is acceptable.
NIST CSF core functions
Identify → Protect → Detect → Respond → Recover (Govern added in version 2.0)
State the version if you list six functions.
ISO 27001 cycle
Plan → Do → Check → Act
Continual improvement of the ISMS. Certification is by an independent body.
Incident response phases
Prepare → Detect and analyse → Contain → Eradicate → Recover → Post-incident review
Common NIST-style sequence. Other models merge or rename phases.

Quick revision

  • A network is a set of connected devices that share data and resources.
  • Know the main network types by size and reach, and the common topologies.
  • The OSI model has seven layers and the TCP/IP model has fewer; be able to map one to the other.
  • An IP address identifies a device on a network, and you must know the difference between IPv4 and IPv6.
  • Protocols are agreed rules for communication; link each common protocol to its purpose.
  • Malware, phishing, denial of service and interception are different attacks, so define each separately.
  • Firewalls filter traffic, while intrusion detection systems alert and intrusion prevention systems block.
  • Encryption protects confidentiality; digital signatures support authenticity, integrity and non-repudiation.
  • Symmetric encryption uses one shared key; asymmetric encryption uses a public and private key pair.
  • Frameworks and standards give an organisation a structured way to manage security risk.
  • In a case answer, name the threat, name the control, then give the compliance recommendation.

Common mistakes

  • Calling the internet a LAN or treating every office network as a WAN. Fix: Decide by coverage and ownership. One site under one owner is a LAN. Linked sites across cities form a WAN.
  • Saying a hub and a switch work the same way. Fix: A hub sends data to all ports. A switch learns addresses and sends data only to the target port, which cuts collisions and snooping.
  • Writing the OSI layers in the wrong order or numbering from the top. Fix: Use the memory aid and write the numbers 7 to 1 beside the names before you start.
  • Saying TCP/IP has five or seven layers without explanation. Fix: State that the standard version has four layers, and mention the five-layer variant only as a note.
  • Saying IPv4 has 64 bits or IPv6 has 64 bits. Fix: Remember 32 for IPv4 (4 × 8) and 128 for IPv6 (8 × 16).
  • Claiming DNS gives the website's content. Fix: DNS only returns the IP address. The web server then supplies the page over HTTP or HTTPS.
  • Saying a DDoS attack is just a bigger DoS attack. Fix: State that DoS comes from one source and DDoS from many distributed devices, usually a botnet.
  • Calling every malware a virus. Fix: Use virus only for code that needs a host file. Use worm, trojan, ransomware and spyware for the others.
  • Saying an IDS blocks attacks. Fix: Remember D is for detect and alert only. P is for prevent, which means block.
  • Treating a firewall as protection against everything. Fix: State its limits: it cannot stop threats from inside, malware that arrives through allowed traffic, or social engineering.

Exam tips

  • Prepare a one-page comparison of PAN, LAN, MAN and WAN. This is the most likely differentiate question.
  • For topologies, always give advantages, disadvantages and the effect of a single failure. Examiners look for all three.
  • In case-based questions, recommend a topology or network type for the facts given, such as budget, number of sites or need for uptime, and justify it.
  • Name the address each device uses: MAC for switches and bridges, IP for routers. It shows depth in few words.
  • Link the answer to security where possible, for example a WAN needs a VPN, a shared bus is easy to tap.
  • Always give layer number, name, function and one example. Marks follow these four items.
  • For comparison questions, use a point-by-point format with the same heads for both models.
  • Link the model to security where you can: for example, firewalls and routers filter at the Network and Transport layers, and encryption such as TLS is associated with the upper layers.