CS 161, Lesson 42, in 54 slides, opening the network-security unit. It covers LANs, routers, and WANs through the postal model, in section 25.1, then layers of abstraction and the OSI model in section 25.2, protocols, headers, and encapsulation in section 25.3, and MAC, IP, and port addressing in section 25.4. It ends with packets against connections and the taxonomy of off-path, on-path, and in-path adversaries, in sections 25.5 and 25.6. It is anchored to textbook sections 25.1 to 25.6.
Subject: Computer Security · 80 slides · applied lesson
Open the interactive version of this deck · Homework for this lesson
Title
CS 161 · Lesson 42 of 45
LANs, routers & WANs · layers of abstraction & OSI · headers & encapsulation · MAC/IP/port addressing · the network adversary taxonomy — the foundation of every network attack
Objectives
Warm-up
Discussion prompt
Before we open L42 · Introduction to Networking: Layers, Addressing & Adversaries: without looking back, what was the main idea of L41 · Clickjacking, UI Attacks, Phishing & CAPTCHAs, and what could you do by the end of it that you could not do before?
Hint: One sentence for the idea, one for the skill. If the second one is blank, that is the part to revisit.
Answer:
CS 161, Lesson 41, in 54 slides. It covers the UI attacks that "steal a click" - fake download buttons, mismatched form values, and fake cursors and browser chrome - in section 23.1, with the defenses in section 23.2. It then covers phishing with valid certificates, homograph URLs, and browser-in-browser attacks, in section 23.3. It ends with CAPTCHAs in sections 24.1 and 24.2: what they ask, why they lose the arms race, and the roughly ten-cents-per-solve farm economics that defeat them. It is anchored to textbook sections 23.1 to 24.2.
Concept
Every network attack in this unit — ARP spoofing, IP/BGP attacks, TCP hijacking, DNS poisoning, and the case for TLS — is an attack on how machines find and talk to each other. Before we can break the network, we have to model it precisely.
Matching
Match the pairs
From Why a whole lesson on networking basics — match each one to what it actually does. The descriptions have been shuffled.
Why: How is it wired?, How does a message travel?, Who can attack it? are easy to tell apart while they are sitting next to their descriptions and much harder afterwards, which is what this checks.
Section
Part 1 · §25.1 building the Internet
Concept
Concrete scenario: you send a message from your laptop in Berkeley to a server in Tokyo. The whole point of the Internet is to move that data from one place to another.
The building block — Something that moves bits across space — a wire, a fiber, a radio link. Every network is ultimately built out of these bit-movers; the rest of networking is how we organize many of them into a worldwide system.
Counterexample
Discussion prompt
Concrete scenario: you send a message from your laptop in Berkeley to a server in Tokyo. The whole point of the Internet is to move that data from one place to another.
That is stated as though it always holds. Do one of two things: produce a case where it fails, or say precisely what rules such a case out. "It just does" is not on the menu.
Hint: Hunt at the extremes first — zero, one, negative, empty, equal. If every extreme survives, the reason they survive is the proof.
Concept
Start small. A Local Area Network (LAN) connects a group of nearby machines so that any machine can send a message to any other machine on it. Think of every dorm room or office on one floor wired together.
Local Area Network (LAN) — A group of local machines all interconnected so any one can message any other directly. A LAN is the unit of 'everyone here can talk to everyone here.'
Definition probe
Sort into buckets
Every line below is part of the definition of The building block or of Local Area Network (LAN) — one or the other, never both. Put each where it belongs.
Concept
Connecting every machine in the world directly to every other is infeasible — far too many wires. So instead we connect LANs together with routers.
Router — A device connected to two or more LANs that forwards messages between them. Enough routers and LANs linked together form a Wide Area Network (WAN) — and the global WAN is the Internet.
LAN A ---\ /--- LAN C
[ROUTER]---[ROUTER]
LAN B ---/ \--- LAN D
many LANs + routers = a WAN = the InternetAnalogy
Discussion prompt
Explain §25.1 Routers stitch LANs into a WAN by analogy to something with no Computer Security in it at all — a queue, a recipe, a map, a bank balance, whatever fits. Then say where your analogy breaks.
Hint: An analogy that never breaks is not an analogy, it is the same idea wearing a hat. Find the seam — that is the part that is actually new.
Answer:
Connecting every machine in the world directly to every other is infeasible — far too many wires. So instead we connect LANs together with routers.
Intuition
Picture the mail. A LAN is like an apartment complex: everyone inside can pass notes to everyone else directly.
A router is like the post office: it doesn't live in any one complex — it sits between them and forwards mail from one complex toward another. Chain enough post offices together and a letter can reach any building on Earth.
Ask yourself: does your laptop have a direct wire to the Tokyo server? (No — it hands the message to its LAN, which hands it to a router, which forwards it post-office-to-post-office until it arrives. This postal picture runs through the whole unit.)
Explain it
Discussion prompt
Explain §25.1 The Internet is a postal system to a student a year behind you. No notation, no jargon they have not met — and it still has to be true.
Hint: If your explanation needs a symbol they have never seen, you are describing the notation rather than the idea.
Answer:
Picture the mail. A LAN is like an apartment complex: everyone inside can pass notes to everyone else directly.
Pattern
Predict first
The table runs: 1 | Alice → her LAN A | the LAN delivers locally · 2 | LAN A → Router 1 | Router 1 sits on LAN A and others · 3 | Router 1 → Router 2 | each router forwards one step closer
In §25.1 Trace a message across the Internet, given the rows so far: what is the next one — the row where hop is 4?
Correct: 4 | Router 2 → LAN D → server | final LAN delivers locally
| hop | where the message is | who forwards it |
|---|---|---|
| 1 | Alice → her LAN A | the LAN delivers locally |
| 2 | LAN A → Router 1 | Router 1 sits on LAN A and others |
| 3 | Router 1 → Router 2 | each router forwards one step closer |
| 4 | Router 2 → LAN D → server | final LAN delivers locally |
Why: The relationship between the columns, not the individual numbers, is what generates the next row. There is no direct wire between them; the message must be forwarded across LANs.
Worked example
Alice's laptop on LAN A wants to reach a server on LAN D
Why: There is no direct wire between them; the message must be forwarded across LANs.
| hop | where the message is | who forwards it |
|---|---|---|
| 1 | Alice → her LAN A | the LAN delivers locally |
| 2 | LAN A → Router 1 | Router 1 sits on LAN A and others |
| 3 | Router 1 → Router 2 | each router forwards one step closer |
| 4 | Router 2 → LAN D → server | final LAN delivers locally |
Verify: no single machine is wired to all the others
Why: §25.1: the Internet is LANs joined by routers, not a giant mesh of direct connections. Each router only needs to know which neighbor to forward toward — exactly like a post office handing mail to the next post office.
Comparison
Comparison matrix
From §25.1 Trace a message across the Internet: refill the where the message is column from what you know. The rest of the table is as it appeared.
| hop | where the message is | who forwards it |
|---|---|---|
| 1 | Alice → her LAN A | the LAN delivers locally |
| 2 | LAN A → Router 1 | Router 1 sits on LAN A and others |
| 3 | Router 1 → Router 2 | each router forwards one step closer |
| 4 | Router 2 → LAN D → server | final LAN delivers locally |
Anomaly
Predict first
A student writes this, and it looks reasonable:
A student: 'The Internet connects all computers, so my laptop has a direct connection to every server in the world.'
It is wrong. Say what breaks — and say it before you turn the page.
Correct: Directly wiring every machine to every other is infeasible — the number of links explodes.
A student: how are machines actually connected?
Why: Directly wiring every machine to every other is infeasible — the number of links explodes. No machine is connected to all the others.
Trap
A student: 'The Internet connects all computers, so my laptop has a direct connection to every server in the world.'
Assume a single global mesh of direct links
Why: Wrong. Directly wiring every machine to every other is infeasible — the number of links explodes. No machine is connected to all the others.
A student: how are machines actually connected?
LANs of local machines, joined by routers into a WAN
Why: §25.1: machines sit on LANs; routers (each on 2+ LANs) forward messages between LANs. Enough LANs + routers = a WAN = the Internet. Like apartment complexes connected by post offices, not everyone wired to everyone.
Section
Part 2 · §25.2 the layered design
Concept
The Internet's design is layers of abstraction. Each layer solves one piece of the problem and hides its details from the layers above. The lowest three:
| layer | name | job |
|---|---|---|
| 1 | Physical | moves raw bits across space (wire, radio) |
| 2 | Link | connects local machines into a LAN |
| 3 | (Inter)Network | connects many LANs together |
Trade off
Comparison matrix
From §25.2 The Internet is built in layers: every row here is a choice with a cost. Fill the name column, then say which row you would actually pick and what you give up for it.
| layer | name | job |
|---|---|---|
| 1 | Physical | moves raw bits across space (wire, radio) |
| 2 | Link | connects local machines into a LAN |
| 3 | (Inter)Network | connects many LANs together |
Concept
The contract between layers is simple: each layer uses the services of the layer below it, and provides services to the layer above it. Higher layers carry richer information; lower layers carry it across space.
Layer 3 (Network) doesn't move bits itself — it asks Layer 2 to move them on a LAN, which asks Layer 1 to push them down a wire. Each layer trusts the one below to do its job.
Intuition
Here's the payoff. Layer 1 (Physical) can be a copper wire or a WiFi radio — and the layers above don't care. As long as Layer 1 promises 'I move bits across space,' Layer 2 and up work identically over either.
It's like shipping a package: you write the address once, and whether the truck is gas or electric is the shipper's problem, not yours. The interface stays fixed; the implementation underneath can change freely.
Ask yourself: if you swap from a wired LAN to wireless, do you have to rewrite the web browser? (No — Layer 1 changed; the higher layers are insulated from it. That insulation is the entire point of layering.)
Concept
The classic reference is the OSI model. Read it top (richest, closest to the app) to bottom (closest to the wire). Two layers are obsolete; we add a 'secure transport' half-layer for TLS.
| # | OSI layer | in this course |
|---|---|---|
| 7 | Application | HTTP, DNS, your app's data |
| 6.5 | Secure Transport | TLS (added; L44) |
| 6 | Presentation | obsolete |
| 5 | Session | obsolete |
| 4 | Transport | TCP / UDP, ports, connections |
| 3 | (Inter)Network | IP, routing between LANs |
| 2 | Link | the LAN, MAC addresses |
| 1 | Physical | bits across space |
Socratic
Discussion prompt
The classic reference is the OSI model. Read it top (richest, closest to the app) to bottom (closest to the wire). Two layers are obsolete; we add a 'secure transport' half-layer for TLS.
Suppose that were not true. What is the first thing in L42 · Introduction to Networking: Layers, Addressing & Adversaries that would stop working?
Hint: Follow it one step downstream. The answer is whatever was quietly relying on it.
Worked example
Given four jobs, assign each to its OSI layer
Why: Layer is decided by WHAT the job operates on — bits, the LAN, between-LAN routing, or the application.
| job | layer | why |
|---|---|---|
| push voltage down a copper wire | 1 Physical | moving raw bits across space |
| deliver a frame to a machine on my LAN | 2 Link | local delivery within one LAN |
| route a packet across many LANs | 3 (Inter)Network | joining LANs together |
| encrypt the byte stream end-to-end | 6.5 Secure Transport | TLS rides above transport |
Verify: switching Layer 1 from copper to WiFi changes none of the rows above it
Why: §25.2: each layer only uses the service below and provides to the one above. Layer 1 is independent — the Link, Network, and Transport rows are unchanged when the physical medium changes.
Comparison
Comparison matrix
From §25.2 Place a service in the right layer: refill the why column from what you know. The rest of the table is as it appeared.
| job | layer | why |
|---|---|---|
| push voltage down a copper wire | 1 Physical | moving raw bits across space |
| deliver a frame to a machine on my LAN | 2 Link | local delivery within one LAN |
| route a packet across many LANs | 3 (Inter)Network | joining LANs together |
| encrypt the byte stream end-to-end | 6.5 Secure Transport | TLS rides above transport |
Trap
A student: 'WiFi is totally different from Ethernet, so going wireless means rewriting IP, TCP, and the browser to match.'
Assume a Layer 1 change ripples up through every layer
Why: Wrong. That would defeat the purpose of layering. The higher layers only see the SERVICE 'move bits across space,' not how it's done.
A student: what does changing the physical medium actually affect?
Only Layer 1 changes; everything above is insulated
Why: §25.2: layers of abstraction mean Layer 1 (wired vs wireless) is independent of the layers above. Swap copper for radio and Link/Network/Transport/Application all work unchanged — that insulation IS the point of layering.
Section
Part 3 · §25.3 how a message is packaged
Concept
For two machines to communicate, they must agree on the rules ahead of time: the message format, the expected behavior, how errors are handled. That agreement is a protocol.
Protocol — An agreed-upon set of rules for how to communicate — the message format, the behavior each side follows, and how errors are handled. Both endpoints must speak the same protocol or they can't understand each other.
Concept
Every message carries headers — metadata describing the message: who sent it, who should receive it, how long it is, identifying numbers. The headers are separate from the actual content (the payload).
Header — Metadata attached to a message: sender/recipient identity, length, IDs, and more. The header is like the ENVELOPE of a letter — addressing and handling info on the outside, the actual letter (payload) inside.
Concept
A message starts as human-readable text at the top layer and is passed DOWN the stack. Each layer adds its OWN header on top of whatever the layer above handed it.
Encapsulation — As a message descends the layers, each layer wraps what it received in its own header. At the bottom the packet is a stack of nested headers — the lowest layer's header outermost — with the original message buried inside, like envelopes inside envelopes.
Sorting
Sort into buckets
These are the pieces of L42 · Introduction to Networking: Layers, Addressing & Adversaries, out of order. Put each one back under the part of the lesson it belongs to.
Intuition
Imagine writing a letter, then sealing it inside an envelope, then putting THAT envelope inside a bigger envelope, then a shipping box. Each layer of packaging adds its own label without touching the contents inside.
On the way out, you keep wrapping (encapsulation, going down). On the way in, the recipient unwraps one layer at a time — strips the box label, opens the outer envelope, opens the inner envelope, and finally reads the letter. Each layer removes only ITS header and hands the rest up.
Ask yourself: does the mail truck need to read your actual letter? (No — it only reads the outermost shipping label. Each layer reads only its own header, which is why layering keeps the layers independent.)
Worked example
Start with the application message: the text 'GET /index.html'
Why: This is the human-readable payload at the top of the stack, before any headers are added.
going DOWN the stack, each layer prepends ITS header:
[Link | IP | Transport | "GET /index.html" ]
^ ^ ^ ^
outermost ... payload (innermost)| layer (top→bottom) | header it adds | what's inside now |
|---|---|---|
| Application | (none — the data) | GET /index.html |
| Transport | + Transport header | [T | data] |
| (Inter)Network | + IP header | [IP | T | data] |
| Link | + Link header | [Link | IP | T | data] |
Verify: at the destination it goes UP the stack, stripping one header per layer
Why: §25.3: the receiving Link layer removes the Link header and hands [IP | T | data] up; IP strips its header; Transport strips its; the top layer finally sees the original 'GET /index.html'. Every layer touches only its own header.
Error analysis
Annotate
Walk the callouts on §25.3 Build a packet by encapsulation. Each one is a place this is easy to get subtly wrong.
Anomaly
Predict first
A student writes this, and it looks reasonable:
A student: 'A packet has a header and a body — one header that says where it's going.'
It is wrong. Say what breaks — and say it before you turn the page.
Correct: Encapsulation means EACH layer added its own header.
A student: how many headers does a packet actually carry?
Why: Encapsulation means EACH layer added its own header. A finished packet carries a STACK of headers, nested, with the original data buried innermost.
Trap
A student: 'A packet has a header and a body — one header that says where it's going.'
Assume a single flat header on the whole packet
Why: Wrong. Encapsulation means EACH layer added its own header. A finished packet carries a STACK of headers, nested, with the original data buried innermost.
A student: how many headers does a packet actually carry?
One header PER layer, nested by encapsulation
Why: §25.3: as the message went down the stack, Link, IP, and Transport each prepended a header. The packet is [Link | IP | Transport | data] — envelopes inside envelopes, lowest-layer header outermost.
Section
Part 4 · §25.4 who is who, at each layer
Concept
Scenario: to deliver a message you need to name the destination — but 'the destination' means something different at each layer. So each layer has its OWN kind of address, stored in that layer's header.
Three addresses matter: a MAC address (Layer 2), an IP address (Layer 3), and a port number (higher layers). Each answers a different 'which?'.
Concept
A MAC address is 48 bits (6 bytes) and uniquely identifies a machine on its LAN. It's written as 6 hex pairs separated by colons.
MAC: ca:fe:f0:0d:be:ef (48 bits = 6 hex pairs)
broadcast: ff:ff:ff:ff:ff:ff ("send to everyone on this LAN")The special broadcast address ff:ff:ff:ff:ff:ff means 'deliver to every machine on the local network.' Analogy: a MAC is an apartment NUMBER — unique within the complex, useless for routing across the city.
Concept
Heads up on a name collision. The link-layer MAC here (Media Access Control address) is not the cryptographic MAC (Message Authentication Code) from L23 — they share three letters and nothing else.
To avoid the clash, the cryptographic kind is sometimes called a MIC (Message Integrity Code) in networking. When you read 'MAC' in this unit, it means the 48-bit hardware address.
Socratic
Discussion prompt
To avoid the clash, the cryptographic kind is sometimes called a MIC (Message Integrity Code) in networking. When you read 'MAC' in this unit, it means the 48-bit hardware address.
Suppose that were not true. What is the first thing in L42 · Introduction to Networking: Layers, Addressing & Adversaries that would stop working?
Hint: Follow it one step downstream. The answer is whatever was quietly relying on it.
Concept
An IPv4 address is 32 bits (4 bytes) and uniquely identifies a machine globally across the whole Internet. It's written as 4 integers, each 0–255, separated by dots.
IPv4: 128.32.131.10 (32 bits = 4 integers, each 0-255)
IPv6: 2607:f140:... (128 bits, 8 hex groups — not used in this class)(IPv6 is 128 bits in 8 hex groups, but this course uses IPv4.) Analogy: an IP is the building's street address — it routes to the right building anywhere in the world, the way a MAC never could.
Explain it
Discussion prompt
Explain §25.4 Layer 3: the IP address (global) to a student a year behind you. No notation, no jargon they have not met — and it still has to be true.
Hint: If your explanation needs a symbol they have never seen, you are describing the notation rather than the idea.
Answer:
An IPv4 address is 32 bits (4 bytes) and uniquely identifies a machine globally across the whole Internet. It's written as 4 integers, each 0–255, separated by dots.
Concept
One machine (one IP) runs many programs at once — browser tabs, email, a game. A port number is 16 bits and identifies WHICH process on the machine a message is for.
Analogy: a port is the room number inside the building. The IP gets you to the building; the port gets you to the right room (process) inside it.
Analogy
Discussion prompt
Explain §25.4 Higher layers: the port (per-process) by analogy to something with no Computer Security in it at all — a queue, a recipe, a map, a bank balance, whatever fits. Then say where your analogy breaks.
Hint: An analogy that never breaks is not an analogy, it is the same idea wearing a hat. Find the seam — that is the part that is actually new.
Answer:
One machine (one IP) runs many programs at once — browser tabs, email, a game. A port number is 16 bits and identifies WHICH process on the machine a message is for.
Worked example
Lay the three addresses side by side
Why: Each lives in a different layer's header, has a different size, and a different scope — that's the whole table to memorize.
| layer | address | size | scope / analogy |
|---|---|---|---|
| 2 Link | MAC ca:fe:f0:0d:be:ef | 48 bits | LAN-local / apartment number |
| 3 Network | IP 128.32.131.10 | 32 bits | global / building street address |
| higher | port 443 | 16 bits | one process / room number |
Verify: source & destination addresses live in the headers — MACs in the Link header, IPs in the IP header, ports in the transport header
Why: §25.4: the layer that owns an address is the layer whose header carries it. So a packet [Link(MACs) | IP(IPs) | Transport(ports) | data] names the destination three different ways, one per layer.
Trade off
Comparison matrix
From §25.4 Match each address to its layer & header: every row here is a choice with a cost. Fill the address column, then say which row you would actually pick and what you give up for it.
| layer | address | size | scope / analogy |
|---|---|---|---|
| 2 Link | MAC ca:fe:f0:0d:be:ef | 48 bits | LAN-local / apartment number |
| 3 Network | IP 128.32.131.10 | 32 bits | global / building street address |
| higher | port 443 | 16 bits | one process / room number |
Anomaly
Predict first
A student writes this, and it looks reasonable:
A student: 'Every network card has a unique MAC, so I can use the MAC to reach any machine anywhere on the Internet.'
It is wrong. Say what breaks — and say it before you turn the page.
Correct: A MAC is LAN-LOCAL — it only identifies a machine on its own local network.
A student: which address is the global identifier?
Why: A MAC is LAN-LOCAL — it only identifies a machine on its own local network. Routers don't forward across LANs by MAC; a MAC is like an apartment number, meaningless outside the complex.
Trap
A student: 'Every network card has a unique MAC, so I can use the MAC to reach any machine anywhere on the Internet.'
Treat the MAC as the global identifier
Why: Wrong. A MAC is LAN-LOCAL — it only identifies a machine on its own local network. Routers don't forward across LANs by MAC; a MAC is like an apartment number, meaningless outside the complex.
A student: which address is the global identifier?
The IP address identifies a machine globally; the MAC is LAN-local
Why: §25.4: the 32-bit IP (building street address) is the global identifier used to route across the Internet. The 48-bit MAC (apartment number) only matters within one LAN. Different layers, different scopes.
Trap
A student: 'We learned MACs in the crypto unit — so the MAC address must be the authentication tag protecting the packet.'
Conflate the 48-bit hardware address with a crypto authentication tag
Why: Wrong. The link-layer MAC (Media Access Control address) is just a 48-bit hardware identifier with NO cryptographic protection. It's unrelated to the Message Authentication Code from L23.
A student: which 'MAC' is which?
Link-layer MAC = hardware address; crypto MAC (MIC) = authentication tag
Why: §25.4: a networking MAC address is a 48-bit LAN identifier providing no integrity or authenticity. The cryptographic MAC from L23 — sometimes called a MIC here to avoid confusion — is a keyed authentication tag. Same three letters, different worlds.
Section
Part 5 · §25.5–25.6 best-effort & the threat model
Concept
The physical/link/internetwork layers don't track conversations. A router just forwards each individual packet toward its destination and forgets it — it has no idea your packet is part of a longer exchange.
Packet — A single message of fixed maximum length that the lower layers forward independently. A router treats each packet on its own, like a post office that sorts one letter at a time and never tracks your whole pen-pal correspondence.
Concept
What about long messages, or the idea of a 'connection' that stays open? Those are built by higher layers, which split a long message into packets, hand them to the lower layers one at a time, and reassemble them at the other end.
So 'connection' is an illusion maintained at the top — underneath, it's just a stream of independent packets being forwarded. The post office never knew you were having a conversation; the two of you did.
Concept
IP (Layer 3) promises only best-effort delivery: it will TRY to deliver each packet, but packets can be corrupted, dropped, reordered, or duplicated — and IP does nothing about it. No error handling. No security.
Best-effort delivery — IP forwards each packet as well as it can but guarantees nothing — packets may be lost or corrupted with no recovery, and there is no built-in security. Correctness and security must be added by HIGHER layers (TCP for reliability; TLS for security, L44).
Intuition
Think again of the post office. It tries to deliver every letter, but letters DO get lost, rained on, or shuffled out of order — and the post office offers no guarantee and reads nothing to protect you.
If you need reliability (resend lost letters) or secrecy (seal them so no one reads them), YOU add that on top — numbered pages and a locked box. On the Internet that's TCP (reliability) and TLS (security, L44).
Ask yourself: why were so many old protocols insecure? (They trusted the network to be honest and reliable — but IP guarantees neither. This is the §1.1 'old code assumed a friendly world' problem all over again.)
Concept
Now the threat model. Network adversaries come in three strengths, weakest to strongest, defined by what they can do to packets on the path between sender and receiver.
Concept
The crucial twist: every adversary — even the weakest off-path one — can SEND its own packets and SPOOF the source field of a header to impersonate someone else.
Spoofing is trivial because the source address is just a field the sender fills in — nothing checks that you 'are' the address you wrote. You can mail a letter with anyone's name in the return-address corner.
Source spoofing — Putting a false source address in a packet header to impersonate another machine. It works for ALL network adversaries (even off-path) because the source field is unverified — this is the network instance of STRIDE 'Spoofing.'
Counterexample
Discussion prompt
The crucial twist: every adversary — even the weakest off-path one — can SEND its own packets and SPOOF the source field of a header to impersonate someone else.
That is stated as though it always holds. Do one of two things: produce a case where it fails, or say precisely what rules such a case out. "It just does" is not on the menu.
Hint: Hunt at the extremes first — zero, one, negative, empty, equal. If every extreme survives, the reason they survive is the proof.
Pattern
Predict first
The table runs: off-path (weakest) | NO | NO | NO | YES · on-path | YES | NO | NO | YES
In §25.6 What each adversary can do, given the rows so far: what is the next one — the row where adversary is in-path / MITM (strongest)?
Correct: in-path / MITM (strongest) | YES | YES | YES | YES
| adversary | read? | modify? | block? | send spoofed? |
|---|---|---|---|---|
| off-path (weakest) | NO | NO | NO | YES |
| on-path | YES | NO | NO | YES |
| in-path / MITM (strongest) | YES | YES | YES | YES |
Why: The relationship between the columns, not the individual numbers, is what generates the next row. The columns are the four powers that matter: read, modify, block, and send-spoofed.
Worked example
Rank off-path, on-path, in-path by their capabilities
Why: The columns are the four powers that matter: read, modify, block, and send-spoofed.
| adversary | read? | modify? | block? | send spoofed? |
|---|---|---|---|---|
| off-path (weakest) | NO | NO | NO | YES |
| on-path | YES | NO | NO | YES |
| in-path / MITM (strongest) | YES | YES | YES | YES |
Verify: the 'send spoofed' column is YES for ALL THREE
Why: §25.6: reading/modifying/blocking gets stronger as you go down — but spoofing your own packets needs none of those. Even an off-path attacker who can't see your traffic can still forge packets with a faked source. Never assume off-path = harmless.
Comparison
Comparison matrix
From §25.6 What each adversary can do: refill the block? column from what you know. The rest of the table is as it appeared.
| adversary | read? | modify? | block? | send spoofed? |
|---|---|---|---|---|
| off-path (weakest) | NO | NO | NO | YES |
| on-path | YES | NO | NO | YES |
| in-path / MITM (strongest) | YES | YES | YES | YES |
Anomaly
Predict first
A student writes this, and it looks reasonable:
A student: 'The off-path attacker can't read or change my packets, so it's basically harmless — I don't need to worry about it.'
It is wrong. Say what breaks — and say it before you turn the page.
Correct: Off-path means it can't read or modify YOUR packets — but it can still SEND its own packets and SPOOF the source address to impersonate someone you trust.
A student: what's the weakest attacker still capable of?
Why: Off-path means it can't read or modify YOUR packets — but it can still SEND its own packets and SPOOF the source address to impersonate someone you trust. Spoofing the source is trivial.
Trap
A student: 'The off-path attacker can't read or change my packets, so it's basically harmless — I don't need to worry about it.'
Treat 'can't read or modify' as 'can't attack'
Why: Wrong. Off-path means it can't read or modify YOUR packets — but it can still SEND its own packets and SPOOF the source address to impersonate someone you trust. Spoofing the source is trivial.
A student: what's the weakest attacker still capable of?
Even off-path attackers can inject spoofed packets
Why: §25.6: ALL network adversaries — off-path included — can send packets with a forged source field, because nothing verifies it. That's why protocols can't trust the source address, and why we need TLS (L44) for real authentication.
Anomaly
Predict first
A student writes this, and it looks reasonable:
A student: 'I sent it over IP, so the bytes are delivered correctly and in order — IP handles that.'
It is wrong. Say what breaks — and say it before you turn the page.
Correct: IP is BEST-EFFORT only: packets can be dropped, corrupted, reordered, or duplicated, and IP does nothing to fix it — and offers no security at all.
A student: what does IP actually promise?
Why: IP is BEST-EFFORT only: packets can be dropped, corrupted, reordered, or duplicated, and IP does nothing to fix it — and offers no security at all.
Trap
A student: 'I sent it over IP, so the bytes are delivered correctly and in order — IP handles that.'
Assume IP provides reliability (and security)
Why: Wrong. IP is BEST-EFFORT only: packets can be dropped, corrupted, reordered, or duplicated, and IP does nothing to fix it — and offers no security at all.
A student: what does IP actually promise?
IP tries its best; reliability & security come from higher layers
Why: §25.6: IP makes no delivery or security guarantees. Reliability is added by TCP at Layer 4; confidentiality and authenticity by TLS (L44). If you assume IP is reliable or safe, you've assumed something the protocol never promised.
Two truths and a lie
Sort into buckets
Some of these hold up and some are the exact mistakes this lesson is built to prevent. Sort them.
Section
Part 6 · the bridge to L43–L44
Constraint
Discussion prompt
Run The networking playbook with this step confiscated:
Address it three ways: MAC (48-bit, LAN-local, apartment #) in the Link header · IP (32-bit, global, street address) in the IP header · port (16-bit, per-process, room #) in the transport header.
Is it still possible? If it is, say what takes its place and what it costs you. If it is not, say exactly what that step was providing that nothing else does.
Hint: A step you can drop for free was never load-bearing. If you cannot drop it, name the thing that goes wrong the moment it is gone.
Answer:
Pattern
[Link | IP | Transport | data].Edge cases
Discussion prompt
The networking playbook works on the cases you have just seen. Push it to the edge: what is the most degenerate input it still handles — empty, zero, one item, everything equal — and what is the first case where it stops being true? Name the case, not just "it breaks".
Hint: Try the smallest legal input, then the largest, then the one where two things collide. Methods are specified at their edges; the middle takes care of itself.
Answer:
Elimination
Eliminate the wrong options
Which statement about this packet's journey is TRUE?
3 of these 4 are wrong. Strike them one at a time, and say what rules each one out before you strike the next. The survivor is the answer.
Survives elimination: D
Why: §25.3–25.6: encapsulation adds ONE header per layer as the message descends the stack, so a finished packet is [Link | IP | Transport | data] — multiple nested headers, lowest-layer header outermost. The other claims fail: a 48-bit MAC is LAN-LOCAL (the 32-bit IP is the global identifier); IP is BEST-EFFORT and guarantees neither delivery nor integrity (TCP/TLS add those at higher layers); and even an off-path attacker that cannot read or modify your packets can still SEND its own with a SPOOFED source address.
Check
A laptop on a LAN sends a packet across several routers to a distant server. Think through MAC vs IP scope, encapsulation, IP's guarantees, and the adversary taxonomy before choosing.
Check your understanding
Which statement about this packet's journey is TRUE?
Answer: D
Why: §25.3–25.6: encapsulation adds ONE header per layer as the message descends the stack, so a finished packet is [Link | IP | Transport | data] — multiple nested headers, lowest-layer header outermost. The other claims fail: a 48-bit MAC is LAN-LOCAL (the 32-bit IP is the global identifier); IP is BEST-EFFORT and guarantees neither delivery nor integrity (TCP/TLS add those at higher layers); and even an off-path attacker that cannot read or modify your packets can still SEND its own with a SPOOFED source address.
Concept
Concept
Concept
Connect it up
Draw it
One page, no notation unless you need it: draw how these connect — LANs, Routers & WANs · Layers of Abstraction & the OSI Model · Protocols, Headers & Encapsulation · Addressing: MAC, IP & Ports · Packets, Connections & Adversaries · Why This Model Powers the Attacks. Put an arrow wherever one of them is what makes another possible, and label the arrow with why.
Recap
You can now explain how LANs, routers, and WANs compose the Internet (postal model), read the layered/OSI design and why Layer 1 is independent, define protocols/headers/encapsulation and build a multi-header packet, tell MAC from IP from port and which header carries each, and contrast packets vs connections with IP's best-effort delivery — then rank off/on/in-path adversaries knowing all of them can spoof the source.
| Idea | § | The one-line version |
|---|---|---|
| LAN / router / WAN | 25.1 | machines on LANs; routers forward between them; together = the Internet |
| Layers & OSI | 25.2 | 1 Physical · 2 Link · 3 Network · 4 Transport · 7 App; uses below, provides above |
| Encapsulation | 25.3 | one header per layer going down; strip one per layer going up |
| Addressing | 25.4 | MAC 48-bit LAN-local · IP 32-bit global · port 16-bit per-process |
| Packets vs connections | 25.5 | lower layers forward independent packets; higher layers build connections |
| Best-effort IP | 25.6 | no reliability, no security — added by TCP/TLS above |
| Adversaries | 25.6 | off-path < on-path < in-path; ALL can send spoofed-source packets |
| Bridge | — | encapsulation→where each attack lives; taxonomy→threat model; no-security IP→TLS (L44) |
Want this taught 1-on-1? Alexander tutors Computer Security — $55/session, free consultation.