1. OSI & TCP/IP Models, Networking Devices
The seven OSI layers, bottom to top: Physical (raw bits, cables, signals) → Data Link (framing, MAC addresses, switches) → Network (logical addressing, routing, IP, routers) → Transport (end-to-end delivery, TCP/UDP, ports) → Session (managing dialogue/sessions between applications) → Presentation (encryption, compression, data format translation) → Application (the actual user-facing protocol — HTTP, FTP, DNS). The practical TCP/IP model collapses this to four layers: Network Interface (combines Physical+Data Link), Internet (Network), Transport, and Application (combines Session+Presentation+Application).
Networking devices map cleanly to layers: a hub operates at the Physical layer (broadcasts to all ports, no intelligence); a switch operates at the Data Link layer (uses MAC address tables to forward only to the correct port); a router operates at the Network layer (uses IP addresses and routing tables to forward between different networks); a gateway can operate at any layer, translating between different protocol stacks entirely.
7. Application - HTTP, FTP, DNS, SMTP
6. Presentation - encryption, compression, data format (e.g. SSL/TLS often placed here)
5. Session - session establishment/management (e.g. NetBIOS)
4. Transport - TCP, UDP | Router = Layer 3
3. Network - IP, ICMP, routers | Switch = Layer 2
2. Data Link - Ethernet, MAC addresses, switches | Hub = Layer 1
1. Physical - cables, voltages, radio signals
Mnemonic (top to bottom): "All People Seem To Need Data Processing"
"At which OSI layer does device X / protocol Y operate?" appears in nearly every cycle — build the device-to-layer table above into pure recall, since it resolves this question type instantly regardless of which specific device or protocol is named.
2. Routing, Congestion Control & Application-Layer Protocols
Distance-vector routing (e.g. RIP) has each router share its entire routing table (distance to each destination) with directly connected neighbours periodically, converging slowly and vulnerable to the count-to-infinity problem. Link-state routing (e.g. OSPF) has each router broadcast information about its direct links to the entire network, and every router independently computes shortest paths (typically via Dijkstra's algorithm) from this complete topology view — converging faster with more overhead per update.
TCP's congestion control reacts to network conditions rather than just the receiver's buffer (that's flow control): slow start begins with a small congestion window and doubles it each round-trip until a threshold, then switches to congestion avoidance (linear growth); on detecting packet loss, TCP drastically cuts the window (multiplicative decrease) — this is the classic "AIMD" (Additive Increase, Multiplicative Decrease) pattern that keeps TCP throughput sawtooth-shaped but stable and fair across competing connections. Key application-layer protocols: DNS (translates domain names to IP addresses, UDP-based for speed), DHCP (automatically assigns IP configuration to a new device), SMTP (sending email), FTP (file transfer, uses two separate connections for control and data).
3. Network Security: Cryptography, Firewalls & Attacks
Symmetric-key cryptography (e.g. AES) uses the same key for encryption and decryption — fast, but requires securely sharing the key beforehand. Asymmetric-key cryptography (e.g. RSA) uses a public key (shared openly, used to encrypt or verify) and a private key (kept secret, used to decrypt or sign) — solves the key-distribution problem but is computationally slower, which is why real systems (like TLS/HTTPS) typically use asymmetric crypto only to securely exchange a symmetric session key, then switch to fast symmetric encryption for the actual data.
A hash function (e.g. SHA-256) produces a fixed-size digest from any input, used for integrity checking — a good hash is one-way (can't recover the input from the digest) and collision-resistant (hard to find two different inputs with the same digest). A digital signature combines hashing with asymmetric crypto to provide both integrity and authentication (proof of who sent it). A firewall filters traffic by rules (IP, port, protocol); common attacks include DoS/DDoS (overwhelming a system with traffic to deny service to legitimate users), man-in-the-middle (secretly intercepting/altering communication between two parties who believe they're communicating directly), and phishing (social engineering to trick a user into revealing credentials).
Asymmetric crypto solves "how do two strangers agree on a secret key with no prior shared secret," but it's too slow for bulk data. So HTTPS uses asymmetric crypto exactly once, at connection setup, purely to exchange a symmetric session key — then all actual page data is encrypted with fast symmetric crypto using that key.
4. Hands-on Exercise
Map protocols to layers and reason about a routing/security scenario
Networks concepts are best fixed in memory by building your own reference and working one applied scenario.
Part 1 — Layer mapping:
- Build a table mapping these to their OSI layer: HTTP, TCP, IP, Ethernet/MAC, a switch, a router, DNS, TLS.
- For each, state whether it primarily concerns addressing, framing, routing, or application data.
Part 2 — Applied scenario:
- A company's internal network uses RIP. Explain, in your own words, why adding a new subnet takes noticeably longer to be known network-wide than it would under OSPF.
- An attacker intercepts traffic between a user and their bank's website, but the connection is HTTPS. Explain what specifically prevents the attacker from reading or altering the transmitted data, referencing both types of cryptography used.
5. Exam-Style Practice (UGC NET Pattern)
Five NTA-pattern questions on the OSI model, routing and network security.
Q1
At which OSI layer does a switch primarily operate, using MAC addresses to forward frames?
A) Physical layer
B) Data Link layer
C) Network layer
D) Transport layer
At which OSI layer does a switch primarily operate, using MAC addresses to forward frames?
A) Physical layer
B) Data Link layer
C) Network layer
D) Transport layer
Correct answer: B) Data Link layer. A switch operates at the Data Link layer, using MAC address tables to intelligently forward frames only to the correct port, unlike a hub (Physical layer, broadcasts to all ports).
Q2
Which routing approach has every router broadcast its direct link information to the entire network, allowing each router to independently compute shortest paths?
A) Distance-vector routing
B) Link-state routing
C) Static routing
D) Flooding
Which routing approach has every router broadcast its direct link information to the entire network, allowing each router to independently compute shortest paths?
A) Distance-vector routing
B) Link-state routing
C) Static routing
D) Flooding
Correct answer: B) Link-state routing. Link-state routing (e.g. OSPF) has each router share information about its own direct links with the whole network, so every router can build a complete topology map and independently compute shortest paths, typically using Dijkstra's algorithm.
Q3
TCP congestion control's "slow start" phase behaves in which way before reaching its threshold?
A) The congestion window decreases linearly
B) The congestion window doubles every round-trip time
C) The congestion window stays fixed at its initial value
D) The congestion window is set by the receiver's buffer size alone
TCP congestion control's "slow start" phase behaves in which way before reaching its threshold?
A) The congestion window decreases linearly
B) The congestion window doubles every round-trip time
C) The congestion window stays fixed at its initial value
D) The congestion window is set by the receiver's buffer size alone
Correct answer: B) The congestion window doubles every round-trip time. Slow start begins with a small congestion window and doubles it every round-trip time until a threshold is reached, after which TCP switches to the more conservative linear-growth congestion avoidance phase.
Q4
Which type of cryptography uses a public key for encryption and a separate, secret private key for decryption?
A) Symmetric-key cryptography
B) Asymmetric-key cryptography
C) Hash-based cryptography
D) One-time pad cryptography
Which type of cryptography uses a public key for encryption and a separate, secret private key for decryption?
A) Symmetric-key cryptography
B) Asymmetric-key cryptography
C) Hash-based cryptography
D) One-time pad cryptography
Correct answer: B) Asymmetric-key cryptography. Asymmetric-key (public-key) cryptography uses a mathematically related key pair — a public key for encryption/verification and a private key for decryption/signing — solving the key-distribution problem that symmetric cryptography has.
Q5
An attack where an attacker secretly intercepts and possibly alters communication between two parties who believe they are communicating directly with each other is called:
A) Phishing
B) Denial-of-Service (DoS)
C) Man-in-the-middle attack
D) SQL injection
An attack where an attacker secretly intercepts and possibly alters communication between two parties who believe they are communicating directly with each other is called:
A) Phishing
B) Denial-of-Service (DoS)
C) Man-in-the-middle attack
D) SQL injection
Correct answer: C) Man-in-the-middle attack. This describes a man-in-the-middle attack precisely — the defining feature is the attacker secretly positioning themselves between two communicating parties, who remain unaware of the interception.