Module 3
Networking and the Internet
1
Networking and the Internet
2
Networking and the Internet
4.1 Network Fundamentals
Network Classifications:
1. Personal Area Network (PAN)
2. Local Area Network (LAN)
3. Metropolitan Area Network (MAN)
4. Wide Area Network (WAN)
3
Networking and the Internet
Network Classifications:
Classification Based on Network Design
1. Open Network
2. Closed / Proprietary Network
4
Networking and the Internet
Network Classifications:
Classification Based on Network Topology
Network Topology:
Refers to the pattern in which computers are connected.
5
Network Protocols:
Network Protocols:
6
Network Protocols:
Network Protocols:
CSMA/CD Protocol in Bus Networks:
7
Networking and the Internet
Limitations of CSMA/CD Protocol:
CSMA/CD is not compatible with wireless star networks in which all machines communicate through a central AP.
8
Networking and the Internet
Network Protocols:
CSMA/CA Protocol in Wireless Networks
Collision Avoidance Strategy in Wireless Networks:
Benefit:
9
Network Protocols:
Handling the Hidden Terminal Problem in WiFi
10
Networking and the Internet
Combining Networks
Repeater
11
Networking and the Internet
Combining Networks
Bridge
12
Networking and the Internet
Combining Networks
Switch
13
Networking and the Internet
Combining Networks
internet:
14
Networking and the Internet
Combining Networks
Routers
Example: Routers connecting two WiFi networks and an Ethernet network
15
Networking and the Internet
Combining Networks
Why Routers are so named?
16
Networking and the Internet
Combining Networks
Gateways
17
Networking and the Internet
Methods of Process Communication
Client/Server Model
Example of Client/Server Model
18
Networking and the Internet
Methods of Process Communication
Client/Server Model – File Server Example
19
Networking and the Internet
Methods of Process Communication
Peer-to-Peer (P2P) Model
- Instant messaging for online text conversations
- Interactive or competitive online games
20
Networking and the Internet
Methods of Process Communication
Peer-to-Peer (P2P) Model
21
Networking and the Internet
Methods of Process Communication
Peer-to-Peer (P2P) Model
22
Networking and the Internet
Client/Server model
Peer to Peer (P2P) model
23
Networking and the Internet
Distributed Systems
Types of distributed computing systems:
1. Cluster computing:
24
Networking and the Internet
Distributed Systems
Types of distributed computing systems:
2. Grid computing
25
Networking and the Internet
Distributed Systems
Types of distributed computing systems:
2. Cloud computing
26
The Internet
27
The Internet
Internet Architecture
The Internet is a collection of connected networks.
28
The Internet
Internet Architecture
29
The Internet
30
The Internet
Internet Addressing
31
The Internet
Internet Addressing
32
The Internet
Internet Addressing
33
The Internet
Internet Addressing
34
Internet Applications
35
Internet Applications
36
Internet Applications
Electronic Mail :
37
Internet Applications
Electronic Mail :
38
Internet Applications
VoIP:
39
Internet Applications
VoIP:
40
Internet Applications
Internet Multimedia Streaming :
41
The World Wide Web
42
The World Wide Web
Browsers
Webservers
Communication
43
The World Wide Web
44
The World Wide Web
A URL has four segments. These segments help the browser find the correct document on the Web.
Four segments of a URL:
A typical URL is presented in Figure 4.8.
45
Internet Protocols
46
Internet Protocols
The Layered Approach to Internet Software
47
Internet Protocols
The Layered Approach to Internet Software
48
Internet Protocols
The Layered Approach to Internet Software
49
Internet Protocols
The Layered Approach to Internet Software
50
Internet Protocols
The Layered Approach to Internet Software
We will trace how a message moves through the Internet.
51
Internet Protocols
The Layered Approach to Internet Software
52
Internet Protocols
The Layered Approach to Internet Software
53
Internet Protocols
The Layered Approach to Internet Software
54
Internet Protocols
The Layered Approach to Internet Software
55
Internet Protocols
At the Intermediate nodes:
The Layered Approach to Internet Software
56
Internet Protocols
At the destination:
The Layered Approach to Internet Software
57
Internet Protocols
The TCP/IP Protocol Suit
58
Internet Protocols
The TCP/IP Protocol Suit
59
Internet Protocols
The TCP/IP Protocol Suit
TCP
60
UDP
Internet Protocols
The TCP/IP Protocol Suit
TCP
61
UDP
Internet Protocols
62
The TCP/IP Protocol Suit
Internet Protocol (IP)
A router stops working, so packets should not be sent through it.
A part of the network becomes congested, so traffic should be sent through a different path.
Internet Protocols
63
The TCP/IP Protocol Suit
Internet Protocol (IP): IPv4 and IPv6
Cybersecurity
Prevention of damage to, protection of, and restoration of computers, electronic communications systems, electronic communications services, wire communication, and electronic communication, including information contained therein, to ensure its availability, integrity, authentication, confidentiality, and nonrepudiation
protecting information and information systems from:
in order to provide—integrity…, confidentiality…, and availability…
64
Cybersecurity
Overview—What is Cybersecurity?
65
Cybersecurity
Overview—What is Cybersecurity?
Confidentiality
Confidentiality…means preserving authorized restrictions on access and disclosure, including means for
protecting personal privacy and proprietary information.
66
Cybersecurity
Overview—What is Cybersecurity?
Integrity:
Integrity…means guarding against improper information modification or destruction, and includes ensuring information non-repudiation and authenticity.
67
Cybersecurity
Overview—What is Cybersecurity?
Availability:
Availability…means ensuring timely and reliable access to and use of information.
68
Cybersecurity
The Basic Information Security Model
Fig. shows a simple framework to understand information security. This model has four main parts:
i)assets, ii) vulnerabilities, iii) threats, and iv) controls.
These four parts are very important because they help us understand any cybersecurity event where information is attacked or at risk.
69
Cybersecurity
The Basic Information Security Model
Assets:
a resource or information that is to be protected.
70
Cybersecurity
71
Cybersecurity
72
Cybersecurity
73
The Basic Information Security Model
Assets
For example, a conventional lock cannot stop someone from stealing data over the network.
Cybersecurity
74
The Basic Information Security Model
Threats
A threat is defined as
the capabilities, intentions, and attack methods of adversaries to exploit or cause harm to assets.
Example: In the Excel example, a worker may want to exploit the lack of password protection on the file and modify their hourly rate. These threats are shown in the Fig. as arrows.
MITRE is a non-profit organization funded by the government for research and development.
The MITRE ATT&CK framework is based on real-world observations.
It provides a global knowledge base of the tactics and techniques used by cybercriminals.
It shows how attackers exploit vulnerabilities in IT systems.
The MITRE ATT&CK knowledge inventory is a tremendous source for what is called threat intelligence.
NIST (National Institute of Standards and Technology) defines threat intelligence as:
Threat information that has been aggregated, transformed, analyzed, interpreted, or enriched to provide the necessary context for decision-making processes.
Cybersecurity
75
The Basic Information Security Model
Threats
Public sources – Free and open to everyone
Private sources – Paid or available only to specific organizations
Current global cyber threats
Hackers who are trying to attack systems
Vulnerability in IT assets that attackers may exploit
Axiom
GOLD SOUTHFIELD
Hikit
Axiom is believed to be a Chinese cyber espionage group.
GOLD SOUTHFIELD is motivated for financial gain.
Both groups are global cybersecurity threats.
Hikit, is classified as malware that can be used to remotely connect to an IT system for the purpose of creating a persistent threat
Persistent threats are used to cause damage to an IT system at any time a malicious actor chooses.
Cybersecurity
76
The Basic Information Security Model
Threats
viruses,
worms,
phishing, and
malware.
VIruses and Worms:
are computer programs that adversely affect computers and propagate through the network without the user’s consent.
a virus uses other programs (e.g., the user’s email client) to spread, whereas
the worm can propagate all by itself.
Malware (malicious software):
is a general term used to describe software or code specifically designed to exploit a computer, or the data it contains, without the user’s consent.
Cybersecurity
77
Threats
Phishing:
is an attempt to compromise a user by masquerading as a trustworthy entity in electronic communication.
Cybersecurity
78
The Basic Information Security Model
Vulnerabilities
A vulnerability is a weakness in an information system that gives a threat the opportunity to compromise an asset.
In this Excel-based IT system, vulnerabilities include:
Unauthorized access, which can cause loss of confidentiality or integrity.
Hard drive failures, which can cause loss of availability.
For example, Microsoft Windows has millions of lines of code. It is difficult to predict and eliminate every possible vulnerability in such big software systems.
Common Vulnerabilities and Exposures (CVE) list:
Cybersecurity
79
The Basic Information Security Model
Vulnerabilities
A software vulnerability is an error in the specification, development, or configuration of software such that its execution can violate the security policy.
If the developer does not write code to validate the user’s input, a hacker can type SQL commands into the textbox and submit the form. This type of attack is called SQL Injection.
Cybersecurity
80
The Basic Information Security Model
Controls
Security controls are safeguards used to minimize the impact of threats.
Within the framework illustrated in Fig. these controls are shown as the ring around the IT system.
Cybersecurity
81
The Basic Information Security Model
Controls
Most operating systems now include a firewall with some default settings.
They also encourage users to create a strong password to protect the administrative user account.
Even the smallest businesses backup their important files on external storage appliances or other Internet services.
They also keep their computers locked to stop unauthorized access.
Cybersecurity
82
The Basic Information Security Model
Controls
Users often prefer memorable passwords over secure passwords.
They also do not back up their data regularly, even if they have spent a lot of money to purchase backup systems.
Cybersecurity
83
The Basic Information Security Model
Controls
i) physical, ii) procedural, and iii) technical.
Examples of such controls include:
locks, fire extinguishers, background checks, and doors.
Examples of procedural controls include:
Procedures for obtaining computer accounts
Procedures for escalating privileges
Procedures for modifying programs
Procedures for hiring
Requirements that users change their passwords periodically
Cybersecurity
84
The Basic Information Security Model
Controls
i) physical, ii) procedural, and iii) technical.
Examples include
passwords, firewalls, intrusion detection systems, system updates, and antivirus software.
Cybersecurity
85
Cyber Hygiene
Definition
Why Important?
Cybersecurity
86
Key Cyber Hygiene Practices
b. End-point Protection (Antivirus Software)
Use unique passwords (not same across accounts).
Change passwords regularly.
f. Secure Network Practices
Cybersecurity
87
Key Cyber Hygiene Practices
g. Device Security
Weakest Link: Humans
Most cyber-attacks target people, not technology.
Example: Social Engineering → hackers trick people into sharing passwords, OTPs, or private data.
Poor cyber hygiene can lead to:
Identity theft
Bank fraud
Privacy violations
Cybersecurity
88
Teams in Cybersecurity
Cybersecurity is not a one-person job — it’s more like a team sport where multiple groups work together to protect systems and respond to attacks. These teams study the TTPs (Tactics, Techniques, and Procedures) used by hackers.
What are TTPs?
Types of Teams
Example: A Red Team might run a phishing campaign inside a company to see how many employees fall for it.
Cybersecurity
89
2. Blue Teams (Defense)
Example: If malware infects a server, the Blue Team checks how it happened, removes the malware, and adds stronger controls to prevent repeat attacks.
Ethical Issues in Information
90
Site owners (companies, admins).
Content posters and monitors.
Copyright
91
Open-Source Software (OSS)
92
Ex:Popular in industry (e.g., Linux OS powers much of the internet
Public Domain
93
Fair Use
94
Permitted for:
Commentary
Criticism
Teaching
Research
Parody
👉 Example:
Quoting a few lines from a book in your research paper = Fair Use.
Uploading the entire book for free distribution = Copyright violation.
Plagiarism
95
It disrespects intellectual creativity.
Piracy
96
Plagiarism = Passing off someone’s work as your own.
Piracy = Sharing/distributing without claiming it as your own.
Examples: movies, software sharing
Online Privacy
97
sector-specific laws:
HIPAA (healthcare)
FERPA (education).
Collect personal data only for the intended purpose.
Protect against misuse, fraud, and identity theft.
Teachers must safeguard student academic records.
Social Media Addiction
98
Online Tracking
99
AI Biases
100