L42 · Introduction to Networking: Layers, Addressing & Adversaries

CS 161, Lesson 42, in 54 slides, opening the network-security unit. It covers LANs, routers, and WANs through the postal model, in section 25.1, then layers of abstraction and the OSI model in section 25.2, protocols, headers, and encapsulation in section 25.3, and MAC, IP, and port addressing in section 25.4. It ends with packets against connections and the taxonomy of off-path, on-path, and in-path adversaries, in sections 25.5 and 25.6. It is anchored to textbook sections 25.1 to 25.6.

Subject: Computer Security · 80 slides · applied lesson

Open the interactive version of this deck · Homework for this lesson

What this lesson covers

The lesson, slide by slide

1. How the Internet Moves Data

Title

CS 161 · Lesson 42 of 45

LANs, routers & WANs · layers of abstraction & OSI · headers & encapsulation · MAC/IP/port addressing · the network adversary taxonomy — the foundation of every network attack

2. By the end of this lesson you can…

Objectives

  1. Explain how LANs, routers, and WANs compose the Internet, and use the postal-system analogy to describe message forwarding.
  2. Describe the layers of abstraction (Physical / Link / (Inter)Network …) and read the OSI 7-layer table, saying which layer uses/provides services to which.
  3. Define a protocol, headers, and encapsulation, and build a packet by adding one header per layer as it goes down the stack.
  4. Distinguish the three addresses — 48-bit MAC (LAN-local), 32-bit IPv4 (global), 16-bit port (per-process) — and which header carries each.
  5. Contrast packets vs connections, explain why IP is best-effort, and rank network adversaries off-path / on-path / in-path — knowing all of them can spoof the source field.

3. What survived from L41 · Clickjacking, UI Attacks, Phishing & CAPTCHAs?

Warm-up

Discussion prompt

Before we open L42 · Introduction to Networking: Layers, Addressing & Adversaries: without looking back, what was the main idea of L41 · Clickjacking, UI Attacks, Phishing & CAPTCHAs, and what could you do by the end of it that you could not do before?

Hint: One sentence for the idea, one for the skill. If the second one is blank, that is the part to revisit.

Answer:

CS 161, Lesson 41, in 54 slides. It covers the UI attacks that "steal a click" - fake download buttons, mismatched form values, and fake cursors and browser chrome - in section 23.1, with the defenses in section 23.2. It then covers phishing with valid certificates, homograph URLs, and browser-in-browser attacks, in section 23.3. It ends with CAPTCHAs in sections 24.1 and 24.2: what they ask, why they lose the arms race, and the roughly ten-cents-per-solve farm economics that defeat them. It is anchored to textbook sections 23.1 to 24.2.

4. Why a whole lesson on networking basics

Concept

Every network attack in this unit — ARP spoofing, IP/BGP attacks, TCP hijacking, DNS poisoning, and the case for TLS — is an attack on how machines find and talk to each other. Before we can break the network, we have to model it precisely.

How is it wired?
§25.1–25.2 LANs, routers, layers
How does a message travel?
§25.3 protocols & encapsulation
Who can attack it?
§25.4–25.6 addressing & adversaries

5. Which is which: Why a whole lesson on networking basics

Matching

Match the pairs

From Why a whole lesson on networking basics — match each one to what it actually does. The descriptions have been shuffled.

  • c1. How is it wired?
  • c2. How does a message travel?
  • c3. Who can attack it?
  • b1. §25.1–25.2 LANs, routers, layers
  • b2. §25.3 protocols & encapsulation
  • b3. §25.4–25.6 addressing & adversaries

Why: How is it wired?, How does a message travel?, Who can attack it? are easy to tell apart while they are sitting next to their descriptions and much harder afterwards, which is what this checks.

6. LANs, Routers & WANs

Section

Part 1 · §25.1 building the Internet

7. §25.1 The Internet's goal: move data across space

Concept

Concrete scenario: you send a message from your laptop in Berkeley to a server in Tokyo. The whole point of the Internet is to move that data from one place to another.

The building block — Something that moves bits across space — a wire, a fiber, a radio link. Every network is ultimately built out of these bit-movers; the rest of networking is how we organize many of them into a worldwide system.

8. Break it if you can: §25.1 The Internet's goal: move data across space

Counterexample

Discussion prompt

Concrete scenario: you send a message from your laptop in Berkeley to a server in Tokyo. The whole point of the Internet is to move that data from one place to another.

That is stated as though it always holds. Do one of two things: produce a case where it fails, or say precisely what rules such a case out. "It just does" is not on the menu.

Hint: Hunt at the extremes first — zero, one, negative, empty, equal. If every extreme survives, the reason they survive is the proof.

9. §25.1 A LAN connects local machines

Concept

Start small. A Local Area Network (LAN) connects a group of nearby machines so that any machine can send a message to any other machine on it. Think of every dorm room or office on one floor wired together.

Local Area Network (LAN) — A group of local machines all interconnected so any one can message any other directly. A LAN is the unit of 'everyone here can talk to everyone here.'

10. Take the definitions apart: The building block vs Local Area Network (LAN)

Definition probe

Sort into buckets

Every line below is part of the definition of The building block or of Local Area Network (LAN) — one or the other, never both. Put each where it belongs.

The building block
Something that moves bits across space; a wire, a fiber, a radio link.; Every network is ultimately built out of these bit-movers
Local Area Network (LAN)
A group of local machines all interconnected so any one can message any other directly.; A LAN is the unit of 'everyone here can talk to everyone here.'
b1
Something that moves bits across space — a wire, a fiber, a radio link. Every network is ultimately built out of these bit-movers; the rest of networking is how we organize many of them into a worldwide system.
b2
A group of local machines all interconnected so any one can message any other directly. A LAN is the unit of 'everyone here can talk to everyone here.'

11. §25.1 Routers stitch LANs into a WAN

Concept

Connecting every machine in the world directly to every other is infeasible — far too many wires. So instead we connect LANs together with routers.

Router — A device connected to two or more LANs that forwards messages between them. Enough routers and LANs linked together form a Wide Area Network (WAN) — and the global WAN is the Internet.

  LAN A ---\                /--- LAN C
           [ROUTER]---[ROUTER]
  LAN B ---/                \--- LAN D

  many LANs + routers  =  a WAN  =  the Internet

12. By analogy: §25.1 Routers stitch LANs into a WAN

Analogy

Discussion prompt

Explain §25.1 Routers stitch LANs into a WAN by analogy to something with no Computer Security in it at all — a queue, a recipe, a map, a bank balance, whatever fits. Then say where your analogy breaks.

Hint: An analogy that never breaks is not an analogy, it is the same idea wearing a hat. Find the seam — that is the part that is actually new.

Answer:

Connecting every machine in the world directly to every other is infeasible — far too many wires. So instead we connect LANs together with routers.

13. §25.1 The Internet is a postal system

Intuition

Picture the mail. A LAN is like an apartment complex: everyone inside can pass notes to everyone else directly.

A router is like the post office: it doesn't live in any one complex — it sits between them and forwards mail from one complex toward another. Chain enough post offices together and a letter can reach any building on Earth.

Ask yourself: does your laptop have a direct wire to the Tokyo server? (No — it hands the message to its LAN, which hands it to a router, which forwards it post-office-to-post-office until it arrives. This postal picture runs through the whole unit.)

14. Teach it back: §25.1 The Internet is a postal system

Explain it

Discussion prompt

Explain §25.1 The Internet is a postal system to a student a year behind you. No notation, no jargon they have not met — and it still has to be true.

Hint: If your explanation needs a symbol they have never seen, you are describing the notation rather than the idea.

Answer:

Picture the mail. A LAN is like an apartment complex: everyone inside can pass notes to everyone else directly.

15. Predict the next row: §25.1 Trace a message across the Internet

Pattern

Predict first

The table runs: 1 | Alice → her LAN A | the LAN delivers locally · 2 | LAN A → Router 1 | Router 1 sits on LAN A and others · 3 | Router 1 → Router 2 | each router forwards one step closer

In §25.1 Trace a message across the Internet, given the rows so far: what is the next one — the row where hop is 4?

Correct: 4 | Router 2 → LAN D → server | final LAN delivers locally

hopwhere the message iswho forwards it
1Alice → her LAN Athe LAN delivers locally
2LAN A → Router 1Router 1 sits on LAN A and others
3Router 1 → Router 2each router forwards one step closer
4Router 2 → LAN D → serverfinal LAN delivers locally

Why: The relationship between the columns, not the individual numbers, is what generates the next row. There is no direct wire between them; the message must be forwarded across LANs.

16. §25.1 Trace a message across the Internet

Worked example

Alice's laptop on LAN A wants to reach a server on LAN D

Why: There is no direct wire between them; the message must be forwarded across LANs.

hopwhere the message iswho forwards it
1Alice → her LAN Athe LAN delivers locally
2LAN A → Router 1Router 1 sits on LAN A and others
3Router 1 → Router 2each router forwards one step closer
4Router 2 → LAN D → serverfinal LAN delivers locally

Verify: no single machine is wired to all the others

Why: §25.1: the Internet is LANs joined by routers, not a giant mesh of direct connections. Each router only needs to know which neighbor to forward toward — exactly like a post office handing mail to the next post office.

17. Fill in: where the message is for §25.1 Trace a message across the Internet

Comparison

Comparison matrix

From §25.1 Trace a message across the Internet: refill the where the message is column from what you know. The rest of the table is as it appeared.

hopwhere the message iswho forwards it
1Alice → her LAN Athe LAN delivers locally
2LAN A → Router 1Router 1 sits on LAN A and others
3Router 1 → Router 2each router forwards one step closer
4Router 2 → LAN D → serverfinal LAN delivers locally

18. Something is wrong here: 'every machine on the Internet is directly connected…

Anomaly

Predict first

A student writes this, and it looks reasonable:

A student: 'The Internet connects all computers, so my laptop has a direct connection to every server in the world.'

It is wrong. Say what breaks — and say it before you turn the page.

Correct: Directly wiring every machine to every other is infeasible — the number of links explodes.

A student: how are machines actually connected?

Why: Directly wiring every machine to every other is infeasible — the number of links explodes. No machine is connected to all the others.

19. Trap: 'every machine on the Internet is directly connected to every other'

Trap

The trap

A student: 'The Internet connects all computers, so my laptop has a direct connection to every server in the world.'

Assume a single global mesh of direct links

Why: Wrong. Directly wiring every machine to every other is infeasible — the number of links explodes. No machine is connected to all the others.

The fix

A student: how are machines actually connected?

LANs of local machines, joined by routers into a WAN

Why: §25.1: machines sit on LANs; routers (each on 2+ LANs) forward messages between LANs. Enough LANs + routers = a WAN = the Internet. Like apartment complexes connected by post offices, not everyone wired to everyone.

20. Layers of Abstraction & the OSI Model

Section

Part 2 · §25.2 the layered design

21. §25.2 The Internet is built in layers

Concept

The Internet's design is layers of abstraction. Each layer solves one piece of the problem and hides its details from the layers above. The lowest three:

layernamejob
1Physicalmoves raw bits across space (wire, radio)
2Linkconnects local machines into a LAN
3(Inter)Networkconnects many LANs together

22. What each one costs: §25.2 The Internet is built in layers

Trade off

Comparison matrix

From §25.2 The Internet is built in layers: every row here is a choice with a cost. Fill the name column, then say which row you would actually pick and what you give up for it.

layernamejob
1Physicalmoves raw bits across space (wire, radio)
2Linkconnects local machines into a LAN
3(Inter)Networkconnects many LANs together

23. §25.2 Each layer uses below, provides above

Concept

The contract between layers is simple: each layer uses the services of the layer below it, and provides services to the layer above it. Higher layers carry richer information; lower layers carry it across space.

Layer 3 (Network) doesn't move bits itself — it asks Layer 2 to move them on a LAN, which asks Layer 1 to push them down a wire. Each layer trusts the one below to do its job.

24. §25.2 Why layering is a clean abstraction

Intuition

Here's the payoff. Layer 1 (Physical) can be a copper wire or a WiFi radio — and the layers above don't care. As long as Layer 1 promises 'I move bits across space,' Layer 2 and up work identically over either.

It's like shipping a package: you write the address once, and whether the truck is gas or electric is the shipper's problem, not yours. The interface stays fixed; the implementation underneath can change freely.

Ask yourself: if you swap from a wired LAN to wireless, do you have to rewrite the web browser? (No — Layer 1 changed; the higher layers are insulated from it. That insulation is the entire point of layering.)

25. §25.2 The OSI 7-layer model

Concept

The classic reference is the OSI model. Read it top (richest, closest to the app) to bottom (closest to the wire). Two layers are obsolete; we add a 'secure transport' half-layer for TLS.

#OSI layerin this course
7ApplicationHTTP, DNS, your app's data
6.5Secure TransportTLS (added; L44)
6Presentationobsolete
5Sessionobsolete
4TransportTCP / UDP, ports, connections
3(Inter)NetworkIP, routing between LANs
2Linkthe LAN, MAC addresses
1Physicalbits across space

26. What rests on this: §25.2 The OSI 7-layer model

Socratic

Discussion prompt

The classic reference is the OSI model. Read it top (richest, closest to the app) to bottom (closest to the wire). Two layers are obsolete; we add a 'secure transport' half-layer for TLS.

Suppose that were not true. What is the first thing in L42 · Introduction to Networking: Layers, Addressing & Adversaries that would stop working?

Hint: Follow it one step downstream. The answer is whatever was quietly relying on it.

27. §25.2 Place a service in the right layer

Worked example

Given four jobs, assign each to its OSI layer

Why: Layer is decided by WHAT the job operates on — bits, the LAN, between-LAN routing, or the application.

joblayerwhy
push voltage down a copper wire1 Physicalmoving raw bits across space
deliver a frame to a machine on my LAN2 Linklocal delivery within one LAN
route a packet across many LANs3 (Inter)Networkjoining LANs together
encrypt the byte stream end-to-end6.5 Secure TransportTLS rides above transport

Verify: switching Layer 1 from copper to WiFi changes none of the rows above it

Why: §25.2: each layer only uses the service below and provides to the one above. Layer 1 is independent — the Link, Network, and Transport rows are unchanged when the physical medium changes.

28. Fill in: why for §25.2 Place a service in the right layer

Comparison

Comparison matrix

From §25.2 Place a service in the right layer: refill the why column from what you know. The rest of the table is as it appeared.

joblayerwhy
push voltage down a copper wire1 Physicalmoving raw bits across space
deliver a frame to a machine on my LAN2 Linklocal delivery within one LAN
route a packet across many LANs3 (Inter)Networkjoining LANs together
encrypt the byte stream end-to-end6.5 Secure TransportTLS rides above transport

29. Trap: 'switch from wired to wireless and you must reimplement the higher layers'

Trap

The trap

A student: 'WiFi is totally different from Ethernet, so going wireless means rewriting IP, TCP, and the browser to match.'

Assume a Layer 1 change ripples up through every layer

Why: Wrong. That would defeat the purpose of layering. The higher layers only see the SERVICE 'move bits across space,' not how it's done.

The fix

A student: what does changing the physical medium actually affect?

Only Layer 1 changes; everything above is insulated

Why: §25.2: layers of abstraction mean Layer 1 (wired vs wireless) is independent of the layers above. Swap copper for radio and Link/Network/Transport/Application all work unchanged — that insulation IS the point of layering.

30. Protocols, Headers & Encapsulation

Section

Part 3 · §25.3 how a message is packaged

31. §25.3 A protocol is an agreement

Concept

For two machines to communicate, they must agree on the rules ahead of time: the message format, the expected behavior, how errors are handled. That agreement is a protocol.

Protocol — An agreed-upon set of rules for how to communicate — the message format, the behavior each side follows, and how errors are handled. Both endpoints must speak the same protocol or they can't understand each other.

32. §25.3 Headers carry the metadata

Concept

Every message carries headers — metadata describing the message: who sent it, who should receive it, how long it is, identifying numbers. The headers are separate from the actual content (the payload).

Header — Metadata attached to a message: sender/recipient identity, length, IDs, and more. The header is like the ENVELOPE of a letter — addressing and handling info on the outside, the actual letter (payload) inside.

33. §25.3 Encapsulation: down the stack, one header per layer

Concept

A message starts as human-readable text at the top layer and is passed DOWN the stack. Each layer adds its OWN header on top of whatever the layer above handed it.

Encapsulation — As a message descends the layers, each layer wraps what it received in its own header. At the bottom the packet is a stack of nested headers — the lowest layer's header outermost — with the original message buried inside, like envelopes inside envelopes.

34. Where does each piece belong: L42 · Introduction to Networking: Layers…

Sorting

Sort into buckets

These are the pieces of L42 · Introduction to Networking: Layers, Addressing & Adversaries, out of order. Put each one back under the part of the lesson it belongs to.

LANs, Routers & WANs
§25.1 The Internet's goal: move data across space; §25.1 A LAN connects local machines; §25.1 Routers stitch LANs into a WAN
Layers of Abstraction & the OSI Model
§25.2 The Internet is built in layers; §25.2 Each layer uses below, provides above; §25.2 Why layering is a clean abstraction
Protocols, Headers & Encapsulation
§25.3 A protocol is an agreement; §25.3 Headers carry the metadata; §25.3 Encapsulation: down the stack, one header per layer
s1
LANs, Routers & WANs is where L42 · Introduction to Networking: Layers, Addressing & Adversaries puts §25.1 The Internet's goal: move data across space, §25.1 A LAN connects local machines, §25.1 Routers stitch LANs into a WAN. Knowing which part of the lesson a problem belongs to is most of knowing which method to reach for.
s2
Layers of Abstraction & the OSI Model is where L42 · Introduction to Networking: Layers, Addressing & Adversaries puts §25.2 The Internet is built in layers, §25.2 Each layer uses below, provides above, §25.2 Why layering is a clean abstraction. Knowing which part of the lesson a problem belongs to is most of knowing which method to reach for.
s3
Protocols, Headers & Encapsulation is where L42 · Introduction to Networking: Layers, Addressing & Adversaries puts §25.3 A protocol is an agreement, §25.3 Headers carry the metadata, §25.3 Encapsulation: down the stack, one header per layer. Knowing which part of the lesson a problem belongs to is most of knowing which method to reach for.

35. §25.3 Envelopes inside envelopes

Intuition

Imagine writing a letter, then sealing it inside an envelope, then putting THAT envelope inside a bigger envelope, then a shipping box. Each layer of packaging adds its own label without touching the contents inside.

On the way out, you keep wrapping (encapsulation, going down). On the way in, the recipient unwraps one layer at a time — strips the box label, opens the outer envelope, opens the inner envelope, and finally reads the letter. Each layer removes only ITS header and hands the rest up.

Ask yourself: does the mail truck need to read your actual letter? (No — it only reads the outermost shipping label. Each layer reads only its own header, which is why layering keeps the layers independent.)

36. §25.3 Build a packet by encapsulation

Worked example

Start with the application message: the text 'GET /index.html'

Why: This is the human-readable payload at the top of the stack, before any headers are added.

going DOWN the stack, each layer prepends ITS header:

[Link | IP | Transport | "GET /index.html" ]
  ^      ^      ^             ^
 outermost          ...      payload (innermost)
layer (top→bottom)header it addswhat's inside now
Application(none — the data)GET /index.html
Transport+ Transport header[T | data]
(Inter)Network+ IP header[IP | T | data]
Link+ Link header[Link | IP | T | data]

Verify: at the destination it goes UP the stack, stripping one header per layer

Why: §25.3: the receiving Link layer removes the Link header and hands [IP | T | data] up; IP strips its header; Transport strips its; the top layer finally sees the original 'GET /index.html'. Every layer touches only its own header.

37. Inspect it line by line: §25.3 Build a packet by encapsulation

Error analysis

Annotate

Walk the callouts on §25.3 Build a packet by encapsulation. Each one is a place this is easy to get subtly wrong.

  • This is the human-readable payload at the top of the stack, before any headers are added.
  • §25.3: the receiving Link layer removes the Link header and hands [IP | T | data] up; IP strips its header; Transport strips its; the top layer finally sees the original 'GET /index.html'. Every layer touches only its own header.

38. Something is wrong here: 'each packet has exactly one header'

Anomaly

Predict first

A student writes this, and it looks reasonable:

A student: 'A packet has a header and a body — one header that says where it's going.'

It is wrong. Say what breaks — and say it before you turn the page.

Correct: Encapsulation means EACH layer added its own header.

A student: how many headers does a packet actually carry?

Why: Encapsulation means EACH layer added its own header. A finished packet carries a STACK of headers, nested, with the original data buried innermost.

39. Trap: 'each packet has exactly one header'

Trap

The trap

A student: 'A packet has a header and a body — one header that says where it's going.'

Assume a single flat header on the whole packet

Why: Wrong. Encapsulation means EACH layer added its own header. A finished packet carries a STACK of headers, nested, with the original data buried innermost.

The fix

A student: how many headers does a packet actually carry?

One header PER layer, nested by encapsulation

Why: §25.3: as the message went down the stack, Link, IP, and Transport each prepended a header. The packet is [Link | IP | Transport | data] — envelopes inside envelopes, lowest-layer header outermost.

40. Addressing: MAC, IP & Ports

Section

Part 4 · §25.4 who is who, at each layer

41. §25.4 Different layers, different addresses

Concept

Scenario: to deliver a message you need to name the destination — but 'the destination' means something different at each layer. So each layer has its OWN kind of address, stored in that layer's header.

Three addresses matter: a MAC address (Layer 2), an IP address (Layer 3), and a port number (higher layers). Each answers a different 'which?'.

42. §25.4 Layer 2: the MAC address (LAN-local)

Concept

A MAC address is 48 bits (6 bytes) and uniquely identifies a machine on its LAN. It's written as 6 hex pairs separated by colons.

MAC:        ca:fe:f0:0d:be:ef    (48 bits = 6 hex pairs)
broadcast:  ff:ff:ff:ff:ff:ff    ("send to everyone on this LAN")

The special broadcast address ff:ff:ff:ff:ff:ff means 'deliver to every machine on the local network.' Analogy: a MAC is an apartment NUMBER — unique within the complex, useless for routing across the city.

43. §25.4 A link-layer MAC ≠ a crypto MAC

Concept

Heads up on a name collision. The link-layer MAC here (Media Access Control address) is not the cryptographic MAC (Message Authentication Code) from L23 — they share three letters and nothing else.

To avoid the clash, the cryptographic kind is sometimes called a MIC (Message Integrity Code) in networking. When you read 'MAC' in this unit, it means the 48-bit hardware address.

44. What rests on this: §25.4 A link-layer MAC ≠ a crypto MAC

Socratic

Discussion prompt

To avoid the clash, the cryptographic kind is sometimes called a MIC (Message Integrity Code) in networking. When you read 'MAC' in this unit, it means the 48-bit hardware address.

Suppose that were not true. What is the first thing in L42 · Introduction to Networking: Layers, Addressing & Adversaries that would stop working?

Hint: Follow it one step downstream. The answer is whatever was quietly relying on it.

45. §25.4 Layer 3: the IP address (global)

Concept

An IPv4 address is 32 bits (4 bytes) and uniquely identifies a machine globally across the whole Internet. It's written as 4 integers, each 0–255, separated by dots.

IPv4:  128.32.131.10     (32 bits = 4 integers, each 0-255)
IPv6:  2607:f140:...      (128 bits, 8 hex groups — not used in this class)

(IPv6 is 128 bits in 8 hex groups, but this course uses IPv4.) Analogy: an IP is the building's street address — it routes to the right building anywhere in the world, the way a MAC never could.

46. Teach it back: §25.4 Layer 3: the IP address (global)

Explain it

Discussion prompt

Explain §25.4 Layer 3: the IP address (global) to a student a year behind you. No notation, no jargon they have not met — and it still has to be true.

Hint: If your explanation needs a symbol they have never seen, you are describing the notation rather than the idea.

Answer:

An IPv4 address is 32 bits (4 bytes) and uniquely identifies a machine globally across the whole Internet. It's written as 4 integers, each 0–255, separated by dots.

47. §25.4 Higher layers: the port (per-process)

Concept

One machine (one IP) runs many programs at once — browser tabs, email, a game. A port number is 16 bits and identifies WHICH process on the machine a message is for.

Analogy: a port is the room number inside the building. The IP gets you to the building; the port gets you to the right room (process) inside it.

48. By analogy: §25.4 Higher layers: the port (per-process)

Analogy

Discussion prompt

Explain §25.4 Higher layers: the port (per-process) by analogy to something with no Computer Security in it at all — a queue, a recipe, a map, a bank balance, whatever fits. Then say where your analogy breaks.

Hint: An analogy that never breaks is not an analogy, it is the same idea wearing a hat. Find the seam — that is the part that is actually new.

Answer:

One machine (one IP) runs many programs at once — browser tabs, email, a game. A port number is 16 bits and identifies WHICH process on the machine a message is for.

49. §25.4 Match each address to its layer & header

Worked example

Lay the three addresses side by side

Why: Each lives in a different layer's header, has a different size, and a different scope — that's the whole table to memorize.

layeraddresssizescope / analogy
2 LinkMAC ca:fe:f0:0d:be:ef48 bitsLAN-local / apartment number
3 NetworkIP 128.32.131.1032 bitsglobal / building street address
higherport 44316 bitsone process / room number

Verify: source & destination addresses live in the headers — MACs in the Link header, IPs in the IP header, ports in the transport header

Why: §25.4: the layer that owns an address is the layer whose header carries it. So a packet [Link(MACs) | IP(IPs) | Transport(ports) | data] names the destination three different ways, one per layer.

50. What each one costs: §25.4 Match each address to its layer & header

Trade off

Comparison matrix

From §25.4 Match each address to its layer & header: every row here is a choice with a cost. Fill the address column, then say which row you would actually pick and what you give up for it.

layeraddresssizescope / analogy
2 LinkMAC ca:fe:f0:0d:be:ef48 bitsLAN-local / apartment number
3 NetworkIP 128.32.131.1032 bitsglobal / building street address
higherport 44316 bitsone process / room number

51. Something is wrong here: 'a MAC address uniquely identifies a machine on the…

Anomaly

Predict first

A student writes this, and it looks reasonable:

A student: 'Every network card has a unique MAC, so I can use the MAC to reach any machine anywhere on the Internet.'

It is wrong. Say what breaks — and say it before you turn the page.

Correct: A MAC is LAN-LOCAL — it only identifies a machine on its own local network.

A student: which address is the global identifier?

Why: A MAC is LAN-LOCAL — it only identifies a machine on its own local network. Routers don't forward across LANs by MAC; a MAC is like an apartment number, meaningless outside the complex.

52. Trap: 'a MAC address uniquely identifies a machine on the global Internet'

Trap

The trap

A student: 'Every network card has a unique MAC, so I can use the MAC to reach any machine anywhere on the Internet.'

Treat the MAC as the global identifier

Why: Wrong. A MAC is LAN-LOCAL — it only identifies a machine on its own local network. Routers don't forward across LANs by MAC; a MAC is like an apartment number, meaningless outside the complex.

The fix

A student: which address is the global identifier?

The IP address identifies a machine globally; the MAC is LAN-local

Why: §25.4: the 32-bit IP (building street address) is the global identifier used to route across the Internet. The 48-bit MAC (apartment number) only matters within one LAN. Different layers, different scopes.

53. Trap: 'the link-layer MAC is the cryptographic MAC from L23'

Trap

The trap

A student: 'We learned MACs in the crypto unit — so the MAC address must be the authentication tag protecting the packet.'

Conflate the 48-bit hardware address with a crypto authentication tag

Why: Wrong. The link-layer MAC (Media Access Control address) is just a 48-bit hardware identifier with NO cryptographic protection. It's unrelated to the Message Authentication Code from L23.

The fix

A student: which 'MAC' is which?

Link-layer MAC = hardware address; crypto MAC (MIC) = authentication tag

Why: §25.4: a networking MAC address is a 48-bit LAN identifier providing no integrity or authenticity. The cryptographic MAC from L23 — sometimes called a MIC here to avoid confusion — is a keyed authentication tag. Same three letters, different worlds.

54. Packets, Connections & Adversaries

Section

Part 5 · §25.5–25.6 best-effort & the threat model

55. §25.5 Lower layers have no concept of a connection

Concept

The physical/link/internetwork layers don't track conversations. A router just forwards each individual packet toward its destination and forgets it — it has no idea your packet is part of a longer exchange.

Packet — A single message of fixed maximum length that the lower layers forward independently. A router treats each packet on its own, like a post office that sorts one letter at a time and never tracks your whole pen-pal correspondence.

56. §25.5 Connections are built by higher layers

Concept

What about long messages, or the idea of a 'connection' that stays open? Those are built by higher layers, which split a long message into packets, hand them to the lower layers one at a time, and reassemble them at the other end.

So 'connection' is an illusion maintained at the top — underneath, it's just a stream of independent packets being forwarded. The post office never knew you were having a conversation; the two of you did.

57. §25.6 IP gives only best-effort delivery

Concept

IP (Layer 3) promises only best-effort delivery: it will TRY to deliver each packet, but packets can be corrupted, dropped, reordered, or duplicated — and IP does nothing about it. No error handling. No security.

Best-effort delivery — IP forwards each packet as well as it can but guarantees nothing — packets may be lost or corrupted with no recovery, and there is no built-in security. Correctness and security must be added by HIGHER layers (TCP for reliability; TLS for security, L44).

58. §25.6 IP is the postal service, not the conversation

Intuition

Think again of the post office. It tries to deliver every letter, but letters DO get lost, rained on, or shuffled out of order — and the post office offers no guarantee and reads nothing to protect you.

If you need reliability (resend lost letters) or secrecy (seal them so no one reads them), YOU add that on top — numbered pages and a locked box. On the Internet that's TCP (reliability) and TLS (security, L44).

Ask yourself: why were so many old protocols insecure? (They trusted the network to be honest and reliable — but IP guarantees neither. This is the §1.1 'old code assumed a friendly world' problem all over again.)

59. §25.6 The network adversary taxonomy

Concept

Now the threat model. Network adversaries come in three strengths, weakest to strongest, defined by what they can do to packets on the path between sender and receiver.

  1. Off-path — weakest. CANNOT read or modify your packets (it's not on the path between you).
  2. On-path — can READ your packets but cannot modify or block them (it sees them go by).
  3. In-path / man-in-the-middle — strongest. Can read, MODIFY, and BLOCK your packets entirely.

60. §25.6 ALL adversaries can spoof the source

Concept

The crucial twist: every adversary — even the weakest off-path one — can SEND its own packets and SPOOF the source field of a header to impersonate someone else.

Spoofing is trivial because the source address is just a field the sender fills in — nothing checks that you 'are' the address you wrote. You can mail a letter with anyone's name in the return-address corner.

Source spoofing — Putting a false source address in a packet header to impersonate another machine. It works for ALL network adversaries (even off-path) because the source field is unverified — this is the network instance of STRIDE 'Spoofing.'

61. Break it if you can: §25.6 ALL adversaries can spoof the source

Counterexample

Discussion prompt

The crucial twist: every adversary — even the weakest off-path one — can SEND its own packets and SPOOF the source field of a header to impersonate someone else.

That is stated as though it always holds. Do one of two things: produce a case where it fails, or say precisely what rules such a case out. "It just does" is not on the menu.

Hint: Hunt at the extremes first — zero, one, negative, empty, equal. If every extreme survives, the reason they survive is the proof.

62. Predict the next row: §25.6 What each adversary can do

Pattern

Predict first

The table runs: off-path (weakest) | NO | NO | NO | YES · on-path | YES | NO | NO | YES

In §25.6 What each adversary can do, given the rows so far: what is the next one — the row where adversary is in-path / MITM (strongest)?

Correct: in-path / MITM (strongest) | YES | YES | YES | YES

adversaryread?modify?block?send spoofed?
off-path (weakest)NONONOYES
on-pathYESNONOYES
in-path / MITM (strongest)YESYESYESYES

Why: The relationship between the columns, not the individual numbers, is what generates the next row. The columns are the four powers that matter: read, modify, block, and send-spoofed.

63. §25.6 What each adversary can do

Worked example

Rank off-path, on-path, in-path by their capabilities

Why: The columns are the four powers that matter: read, modify, block, and send-spoofed.

adversaryread?modify?block?send spoofed?
off-path (weakest)NONONOYES
on-pathYESNONOYES
in-path / MITM (strongest)YESYESYESYES

Verify: the 'send spoofed' column is YES for ALL THREE

Why: §25.6: reading/modifying/blocking gets stronger as you go down — but spoofing your own packets needs none of those. Even an off-path attacker who can't see your traffic can still forge packets with a faked source. Never assume off-path = harmless.

64. Fill in: block? for §25.6 What each adversary can do

Comparison

Comparison matrix

From §25.6 What each adversary can do: refill the block? column from what you know. The rest of the table is as it appeared.

adversaryread?modify?block?send spoofed?
off-path (weakest)NONONOYES
on-pathYESNONOYES
in-path / MITM (strongest)YESYESYESYES

65. Something is wrong here: 'an off-path attacker can't do anything'

Anomaly

Predict first

A student writes this, and it looks reasonable:

A student: 'The off-path attacker can't read or change my packets, so it's basically harmless — I don't need to worry about it.'

It is wrong. Say what breaks — and say it before you turn the page.

Correct: Off-path means it can't read or modify YOUR packets — but it can still SEND its own packets and SPOOF the source address to impersonate someone you trust.

A student: what's the weakest attacker still capable of?

Why: Off-path means it can't read or modify YOUR packets — but it can still SEND its own packets and SPOOF the source address to impersonate someone you trust. Spoofing the source is trivial.

66. Trap: 'an off-path attacker can't do anything'

Trap

The trap

A student: 'The off-path attacker can't read or change my packets, so it's basically harmless — I don't need to worry about it.'

Treat 'can't read or modify' as 'can't attack'

Why: Wrong. Off-path means it can't read or modify YOUR packets — but it can still SEND its own packets and SPOOF the source address to impersonate someone you trust. Spoofing the source is trivial.

The fix

A student: what's the weakest attacker still capable of?

Even off-path attackers can inject spoofed packets

Why: §25.6: ALL network adversaries — off-path included — can send packets with a forged source field, because nothing verifies it. That's why protocols can't trust the source address, and why we need TLS (L44) for real authentication.

67. Something is wrong here: 'IP guarantees my data arrives intact'

Anomaly

Predict first

A student writes this, and it looks reasonable:

A student: 'I sent it over IP, so the bytes are delivered correctly and in order — IP handles that.'

It is wrong. Say what breaks — and say it before you turn the page.

Correct: IP is BEST-EFFORT only: packets can be dropped, corrupted, reordered, or duplicated, and IP does nothing to fix it — and offers no security at all.

A student: what does IP actually promise?

Why: IP is BEST-EFFORT only: packets can be dropped, corrupted, reordered, or duplicated, and IP does nothing to fix it — and offers no security at all.

68. Trap: 'IP guarantees my data arrives intact'

Trap

The trap

A student: 'I sent it over IP, so the bytes are delivered correctly and in order — IP handles that.'

Assume IP provides reliability (and security)

Why: Wrong. IP is BEST-EFFORT only: packets can be dropped, corrupted, reordered, or duplicated, and IP does nothing to fix it — and offers no security at all.

The fix

A student: what does IP actually promise?

IP tries its best; reliability & security come from higher layers

Why: §25.6: IP makes no delivery or security guarantees. Reliability is added by TCP at Layer 4; confidentiality and authenticity by TLS (L44). If you assume IP is reliable or safe, you've assumed something the protocol never promised.

69. Which of these survive contact with L42 · Introduction to Networking: Layers…?

Two truths and a lie

Sort into buckets

Some of these hold up and some are the exact mistakes this lesson is built to prevent. Sort them.

Holds up
Concrete scenario: you send a message from your laptop in Berkeley to a server in Tokyo. The whole point of the Internet is to move that data from one place to another.; Connecting every machine in the world directly to every other is infeasible — far too many wires. So instead we connect LANs together with routers.; Picture the mail. A LAN is like an apartment complex: everyone inside can pass notes to everyone else directly.
Breaks
A student: 'The Internet connects all computers, so my laptop has a direct connection to every server in the world.'; A student: 'WiFi is totally different from Ethernet, so going wireless means rewriting IP, TCP, and the browser to match.'
sound
These are stated as this lesson states them — each one survives the edge cases L42 · Introduction to Networking: Layers, Addressing & Adversaries puts it through.
flawed
Each of these is lifted from a trap in this deck: reasonable-sounding, and wrong in a way that only shows up once you rely on it.

70. Why This Model Powers the Attacks

Section

Part 6 · the bridge to L43–L44

71. Without one step: The networking playbook

Constraint

Discussion prompt

Run The networking playbook with this step confiscated:

Address it three ways: MAC (48-bit, LAN-local, apartment #) in the Link header · IP (32-bit, global, street address) in the IP header · port (16-bit, per-process, room #) in the transport header.

Is it still possible? If it is, say what takes its place and what it costs you. If it is not, say exactly what that step was providing that nothing else does.

Hint: A step you can drop for free was never load-bearing. If you cannot drop it, name the thing that goes wrong the moment it is gone.

Answer:

  1. Compose the Internet: machines sit on LANs; routers (on 2+ LANs) forward between them; many LANs + routers = a WAN = the Internet. (LAN = apartment…
  2. Read the layers: 1 Physical (bits) · 2 Link (LAN) · 3 (Inter)Network (between LANs) · 4 Transport · 6.5 Secure Transport (TLS) · 7 Application. Each uses…
  3. Package the message: a protocol is the agreement; headers are the metadata envelope; encapsulation adds ONE header per layer going down, stripped one per…
  4. Address it three ways: MAC (48-bit, LAN-local, apartment #) in the Link header · IP (32-bit, global, street address) in the IP header · port (16-bit…
  5. Know the limits: lower layers forward independent packets with NO connection; connections/long messages are split into packets by higher layers; IP is…
  6. Apply the threat model: off-path (can't read/modify) < on-path (read only) < in-path (read/modify/block) — but ALL can send SPOOFED-source packets. Map to…

72. The networking playbook

Pattern

  1. Compose the Internet: machines sit on LANs; routers (on 2+ LANs) forward between them; many LANs + routers = a WAN = the Internet. (LAN = apartment complex, router = post office.)
  2. Read the layers: 1 Physical (bits) · 2 Link (LAN) · 3 (Inter)Network (between LANs) · 4 Transport · 6.5 Secure Transport (TLS) · 7 Application. Each uses below, provides above; Layer 1 is independent.
  3. Package the message: a protocol is the agreement; headers are the metadata envelope; encapsulation adds ONE header per layer going down, stripped one per layer going up. A packet = [Link | IP | Transport | data].
  4. Address it three ways: MAC (48-bit, LAN-local, apartment #) in the Link header · IP (32-bit, global, street address) in the IP header · port (16-bit, per-process, room #) in the transport header.
  5. Know the limits: lower layers forward independent packets with NO connection; connections/long messages are split into packets by higher layers; IP is BEST-EFFORT — no reliability, no security.
  6. Apply the threat model: off-path (can't read/modify) < on-path (read only) < in-path (read/modify/block) — but ALL can send SPOOFED-source packets. Map to attacks: ARP (L2) · IP/BGP (L3) · TCP/TLS/DNS (L4+) in L43–L44.

73. Where does it stop working: The networking playbook

Edge cases

Discussion prompt

The networking playbook works on the cases you have just seen. Push it to the edge: what is the most degenerate input it still handles — empty, zero, one item, everything equal — and what is the first case where it stops being true? Name the case, not just "it breaks".

Hint: Try the smallest legal input, then the largest, then the one where two things collide. Methods are specified at their edges; the middle takes care of itself.

Answer:

  1. Compose the Internet: machines sit on LANs; routers (on 2+ LANs) forward between them; many LANs + routers = a WAN = the Internet. (LAN = apartment…
  2. Read the layers: 1 Physical (bits) · 2 Link (LAN) · 3 (Inter)Network (between LANs) · 4 Transport · 6.5 Secure Transport (TLS) · 7 Application. Each uses…
  3. Package the message: a protocol is the agreement; headers are the metadata envelope; encapsulation adds ONE header per layer going down, stripped one per…
  4. Address it three ways: MAC (48-bit, LAN-local, apartment #) in the Link header · IP (32-bit, global, street address) in the IP header · port (16-bit…
  5. Know the limits: lower layers forward independent packets with NO connection; connections/long messages are split into packets by higher layers; IP is…
  6. Apply the threat model: off-path (can't read/modify) < on-path (read only) < in-path (read/modify/block) — but ALL can send SPOOFED-source packets. Map to…

74. Rule out three: Checkpoint — which statement is TRUE?

Elimination

Eliminate the wrong options

Which statement about this packet's journey is TRUE?

3 of these 4 are wrong. Strike them one at a time, and say what rules each one out before you strike the next. The survivor is the answer.

  • A. The laptop's 48-bit MAC address is what uniquely identifies it to the distant server across the global Internet.
  • B. Because IP delivered the packet, the data is guaranteed to arrive uncorrupted and in order.
  • C. An off-path attacker who can't read the packets is harmless — it can't affect the exchange at all.
  • D. As the message went down the stack, each layer added its own header (Link, IP, transport), so the packet carries several nested headers, not one.

Survives elimination: D

Why: §25.3–25.6: encapsulation adds ONE header per layer as the message descends the stack, so a finished packet is [Link | IP | Transport | data] — multiple nested headers, lowest-layer header outermost. The other claims fail: a 48-bit MAC is LAN-LOCAL (the 32-bit IP is the global identifier); IP is BEST-EFFORT and guarantees neither delivery nor integrity (TCP/TLS add those at higher layers); and even an off-path attacker that cannot read or modify your packets can still SEND its own with a SPOOFED source address.

75. Checkpoint — which statement is TRUE?

Check

A laptop on a LAN sends a packet across several routers to a distant server. Think through MAC vs IP scope, encapsulation, IP's guarantees, and the adversary taxonomy before choosing.

Check your understanding

Which statement about this packet's journey is TRUE?

  • A. The laptop's 48-bit MAC address is what uniquely identifies it to the distant server across the global Internet.
  • B. Because IP delivered the packet, the data is guaranteed to arrive uncorrupted and in order.
  • C. An off-path attacker who can't read the packets is harmless — it can't affect the exchange at all.
  • D. As the message went down the stack, each layer added its own header (Link, IP, transport), so the packet carries several nested headers, not one. (correct)

Answer: D

Why: §25.3–25.6: encapsulation adds ONE header per layer as the message descends the stack, so a finished packet is [Link | IP | Transport | data] — multiple nested headers, lowest-layer header outermost. The other claims fail: a 48-bit MAC is LAN-LOCAL (the 32-bit IP is the global identifier); IP is BEST-EFFORT and guarantees neither delivery nor integrity (TCP/TLS add those at higher layers); and even an off-path attacker that cannot read or modify your packets can still SEND its own with a SPOOFED source address.

Why A tempts people
A MAC address is LAN-local — it only identifies a machine on its own local network (like an apartment number). The 32-bit IP address is the global identifier used to route across the Internet. Routers never forward across LANs by MAC.
Why B tempts people
IP provides only best-effort delivery: packets may be dropped, corrupted, reordered, or duplicated, and IP does nothing to fix it. Reliability is added by TCP and security by TLS at higher layers — IP itself guarantees nothing.
Why C tempts people
Off-path means it can't read or modify your packets — but it can still send its OWN packets and spoof the source address to impersonate someone, because the source field is unverified. Off-path is not harmless.

76. Misconceptions to retire

Concept

77. Synthesis — the foundation of the whole network unit

Concept

78. Primary sources & where to read more

Concept

79. Connect it up: L42 · Introduction to Networking: Layers, Addressing & Adversaries

Connect it up

Draw it

One page, no notation unless you need it: draw how these connect — LANs, Routers & WANs · Layers of Abstraction & the OSI Model · Protocols, Headers & Encapsulation · Addressing: MAC, IP & Ports · Packets, Connections & Adversaries · Why This Model Powers the Attacks. Put an arrow wherever one of them is what makes another possible, and label the arrow with why.

80. Recap — Lesson 42

Recap

You can now explain how LANs, routers, and WANs compose the Internet (postal model), read the layered/OSI design and why Layer 1 is independent, define protocols/headers/encapsulation and build a multi-header packet, tell MAC from IP from port and which header carries each, and contrast packets vs connections with IP's best-effort delivery — then rank off/on/in-path adversaries knowing all of them can spoof the source.

Idea§The one-line version
LAN / router / WAN25.1machines on LANs; routers forward between them; together = the Internet
Layers & OSI25.21 Physical · 2 Link · 3 Network · 4 Transport · 7 App; uses below, provides above
Encapsulation25.3one header per layer going down; strip one per layer going up
Addressing25.4MAC 48-bit LAN-local · IP 32-bit global · port 16-bit per-process
Packets vs connections25.5lower layers forward independent packets; higher layers build connections
Best-effort IP25.6no reliability, no security — added by TCP/TLS above
Adversaries25.6off-path < on-path < in-path; ALL can send spoofed-source packets
Bridge—encapsulation→where each attack lives; taxonomy→threat model; no-security IP→TLS (L44)

Sources

  1. CS 161 Computer Security Textbook §25.1–25.6 — Wagner, Weaver, Kao, Shakir, Law & Ngai, UC Berkeley — LANs, routers and WANs (§25.1), layers of abstraction and the OSI model (§25.2), protocols, headers and encapsulation (§25.3), MAC/IP/port addressing (§25.4), packets vs connections and IP's best-effort delivery (§25.5), and the off-path/on-path/in-path network adversary taxonomy (§25.6)
  2. Kurose & Ross — Computer Networking: A Top-Down Approach — J. Kurose & K. Ross, Pearson — layered architecture, the link/network/transport layers, MAC vs IP addressing, and ports as process identifiers
  3. ISO/IEC 7498-1 — The OSI Reference Model — ISO/IEC 7498-1:1994 — the seven-layer Open Systems Interconnection reference model (Physical, Link, Network, Transport, Session, Presentation, Application)
  4. RFC 791 — Internet Protocol (IPv4) — J. Postel (ed.), IETF, September 1981 — defines the 32-bit IPv4 address, the packet/datagram format, and IP's best-effort (no reliability, no security) delivery model

Want this taught 1-on-1? Alexander tutors Computer Security — $55/session, free consultation.

Book on Wyzant · Text (657) 465-8108