Unit 3: Internet protocols and network security
Computer Networks notes · PTU syllabus (PGCA1910)
On this page
- Unit summary
- Principles of internetworking
- Connectionless internetworking
- The Internet Protocol (IPv4)
- IPv6
- Security requirements and attacks
- Encryption
- Conventional and public key encryption
- The RSA algorithm
- Digital signatures
- Distributed applications: SNMP
- Distributed applications: SMTP
- Distributed applications: HTTP
- Key terms
- Quick revision
- Important questions
Unit summary
The internet joins thousands of networks, must be secured, and supports everyday applications. This unit covers the principles of internetworking, connectionless internetworking, the Internet Protocol and IPv6, security requirements and attacks, encryption, public key encryption and digital signatures, and distributed applications — SNMP, SMTP and HTTP.
After this unit you can
- Explain the principles of internetworking
- Describe IPv4 and IPv6
- Explain security requirements, attacks and cryptographic protection
- Explain SNMP, SMTP and HTTP
PTU syllabus topics
- Principles of internetworking
- connectionless internetworking
- Internet protocols and IPv6
- security requirements and attacks
- encryption
- public key encryption and digital signatures
- distributed applications — SNMP
- SMTP
- HTTP
Confidentiality
Threat: eavesdropping
Integrity
Threat: modification
Authentication
Threat: spoofing
Availability
Threat: denial of service
Non-repudiation
Digital signatures
Topic 1
Principles of internetworking
- Internetworking: connecting different networks (LANs, WANs with different protocols) so they work as one — the internet is a network of networks.
- Repeater or hub
- Physical layer; extends a segment
- Bridge or switch
- Data link layer; connects LAN segments
- Router
- Network layer; connects different networks, chooses routes
- Gateway
- Up to the application layer; translates between different protocols
- Issues: different addressing, packet sizes (fragmentation), quality of service and security; solved by IP as a common protocol, tunnelling and fragmentation.
- Link between networks
- Physical and link-layer connection
- Routing and delivery
- Across multiple networks
- Accounting and status
- Track use and keep status information
- Hide differences
- Addressing, maximum packet size, access mechanisms, timeouts, error recovery, status reporting, routing, connection or connectionless service
Topic 2
Connectionless internetworking
- The internet is a datagram (connectionless) internetwork: each IP packet carries full source and destination addresses and is routed independently; routers keep no per-connection state.
- Advantages: flexible, robust when routers fail, simple routers. Disadvantages: no delivery guarantee, packets may arrive out of order — reliability is added by TCP at the hosts.
- Fragmentation: a router splits a datagram that exceeds the next network's MTU; the destination reassembles fragments using identification, flags and fragment offset fields.
Topic 3
The Internet Protocol (IPv4)
- Version and header length
- 4 and 20–60 bytes
- Type of service (DSCP)
- Priority and quality of service
- Total length
- Up to 65,535 bytes
- Identification, flags, fragment offset
- Fragmentation and reassembly
- Time to live (TTL)
- Hop limit to stop looping packets
- Protocol
- Upper layer — 6 TCP, 17 UDP
- Header checksum
- Error check of the header
- Source and destination addresses
- 32 bits each
- Addressing: classes A, B, C (now replaced by CIDR, e.g., 192.168.10.0/24 has 256 addresses), private ranges with NAT, and supporting protocols ICMP (ping, errors), ARP (IP to MAC) and DHCP (automatic configuration).
Topic 4
IPv6
Address size
32 bits (about 4.3 billion)
128 bits (about 3.4 × 10³⁸)
Notation
Dotted decimal — 172.16.4.1
Hexadecimal groups — 2001:db8:0:1::25
Header
Variable, 20–60 bytes, with checksum
Fixed 40 bytes with extension headers; no checksum
Fragmentation
By routers and hosts
Only by the source host
Configuration
Manual or DHCP
Stateless autoconfiguration (SLAAC) or DHCPv6
Security
IPsec optional
IPsec designed in
Broadcast
Yes
No — multicast and anycast instead
- Transition mechanisms: dual stack, tunnelling (IPv6 inside IPv4) and translation (NAT64).
Topic 5
Security requirements and attacks
Confidentiality
Only authorised parties read data
Integrity
Data not altered without detection
Availability
Services usable when needed
Authenticity and non-repudiation
Verify identities; senders cannot deny messages
Nature
Eavesdropping without changing data
Modify, fabricate or block data
Types
Release of message contents, traffic analysis
Masquerade, replay, modification of messages, denial of service
Detection
Hard — prevent with encryption
Easier to detect; aim to recover
Topic 6
Encryption
- 1Plaintext
Readable message
- 2Encryption algorithm with key
- 3Ciphertext
Unreadable message sent
- 4Decryption algorithm with key
- 5Plaintext recovered
- Cryptography
- Science of secret writing
- Cryptanalysis
- Breaking ciphers without the key
- Cryptology
- Cryptography and cryptanalysis together
- Key
- Secret value controlling encryption
- Brute-force attack
- Trying every possible key
Topic 7
Conventional and public key encryption
Keys
One shared secret key
Pair — public key and private key
Speed
Fast
Slower
Key distribution
Difficult — key must be shared securely
Easy — public key can be published
Examples
AES, DES, 3DES
RSA, ECC
Use
Bulk data encryption
Key exchange, digital signatures
- Hybrid approach (SSL/TLS): asymmetric encryption to exchange a session key, then symmetric encryption for data.
- Public/private key pair: what one key encrypts only the other can decrypt — encrypt with the receiver's public key for confidentiality; sign with the sender's private key for authentication.
- Hash functions (SHA-256) produce fixed-length digests for integrity checks; AES is the common symmetric standard; RSA and elliptic-curve cryptography are common asymmetric methods.
Topic 8
The RSA algorithm
- 1
Choose two large primes p and q
- 2
Compute n = p × q and φ(n) = (p − 1)(q − 1)
- 3
Choose e with 1 < e < φ(n) and gcd(e, φ(n)) = 1
- 4
Compute d such that d × e mod φ(n) = 1
- 5
Public key (e, n); private key (d, n)
- 6
Encrypt C = M^e mod n; decrypt M = C^d mod n
Example
p = 3, q = 11 → n = 33, φ(n) = 20. Choose e = 3 (gcd(3, 20) = 1). d = 7, since 3 × 7 = 21 mod 20 = 1. Encrypt M = 4: C = 4³ mod 33 = 64 mod 33 = 31. Decrypt: 31⁷ mod 33 = 4.
- Security: rests on the difficulty of factoring n; keys of 2048 bits or more are recommended.
Topic 9
Digital signatures
- Digital signature: an electronic signature using asymmetric cryptography and a hash function to authenticate the signer and ensure integrity.
- 1Hash the document
- 2Encrypt the hash with the signer's private key
- 3Send document, signature and certificate
- 4Receiver decrypts the signature with the public key
- 5Compare with a fresh hash — match means authentic and unaltered
- Digital Signature Certificate (DSC): classes based on verification level (Class 3 and document signer certificates now in use); used for MCA filings, income-tax returns, GST, e-tenders.
- Aadhaar e-Sign: online electronic signature using Aadhaar OTP or biometric authentication.
- Properties: authentication of the signer, integrity of the message, non-repudiation. Standards: RSA signatures, DSA (Digital Signature Standard), ECDSA; legally valid in India under the IT Act, 2000.
Topic 10
Distributed applications: SNMP
- Simple Network Management Protocol monitors and manages devices (routers, switches, servers, printers) over UDP (ports 161 and 162).
- Manager (NMS)
- Station that polls and controls devices
- Agent
- Software on each managed device
- MIB
- Management information base — variables such as interface counters, identified by object IDs
- Operations
- Get, GetNext, GetBulk, Set, Trap (unsolicited alert), Inform
- Versions
- v1 and v2c use community strings; v3 adds authentication and encryption
Topic 11
Distributed applications: SMTP
- 1User agent (Outlook, Gmail) composes mail
- 2Submission to the sender's mail server (port 587)
- 3SMTP transfer between mail servers (port 25) after a DNS MX lookup
- 4Stored in the recipient's mailbox
- 5Recipient retrieves it with POP3 or IMAP
- SMTP commands: HELO or EHLO, MAIL FROM, RCPT TO, DATA, QUIT; MIME extends email to attachments and non-ASCII text.
Topic 12
Distributed applications: HTTP
- HyperText Transfer Protocol: the request–response protocol of the web, over TCP port 80 (HTTPS on 443 with TLS); stateless — cookies and sessions add state.
- Methods
- GET (read), POST (submit), PUT (replace), DELETE (remove), HEAD, PATCH
- Status codes
- 200 OK, 301 moved, 304 not modified, 404 not found, 500 server error
- Headers
- Host, Content-Type, Cache-Control, Set-Cookie
- Versions
- HTTP/1.1 persistent connections; HTTP/2 multiplexing; HTTP/3 over QUIC (UDP)
Key terms
- Internetworking
- Connecting different networks into one
- Datagram
- Independently routed packet carrying full addresses
- IPv6
- 128-bit version of the Internet Protocol
- Active attack
- Attack that modifies or disrupts data
- SNMP
- Protocol for managing network devices
Quick revision
- Internetworking requirements; routers and gateways; connectionless datagrams; fragmentation.
- IPv4 header; CIDR; ICMP, ARP, DHCP.
- IPv6 features; comparison; transition methods.
- CIA; passive vs active attacks; symmetric and public key encryption; RSA; digital signatures.
- SNMP manager, agent, MIB; SMTP with POP3 and IMAP; HTTP methods, status codes, versions.
Important exam questions
Practice questions written to the PTU exam pattern for this unit's syllabus: short answers (Section A style) and long answers (Sections B and C style).
Short-answer questions
- Q1.What is connectionless internetworking?
- Q2.What is the purpose of the TTL field?
- Q3.State three advantages of IPv6 over IPv4.
- Q4.Distinguish passive and active attacks.
- Q5.What is a MIB?
- Q6.Distinguish GET and POST.
Long-answer questions
- Q1.Explain the principles of internetworking and connectionless internetworking.
- Q2.Compare IPv4 and IPv6.
- Q3.Explain security requirements, attacks, encryption and digital signatures.
- Q4.Explain the distributed applications SNMP, SMTP and HTTP.
Stuck on this unit?
Message SBS on WhatsApp for help with Computer Networks, or to ask about studying M.Sc IT at Synetic.
