🎯 Goal

Rebuild a clear mental model of what actually happens when I type a website address in a browser, without mixing layers or relying on vague explanations.

Key areas explored:

  • network fundamentals (IP vs MAC vs ports vs protocols)
  • TCP vs UDP tradeoffs
  • DNS resolution in practice
  • HTTPS basics and the TLS handshake
  • modern web behavior (QUIC / HTTP/3)
  • interpreting command-line network tools

πŸ› οΈ What I Did

I started by writing plain-language definitions for key networking concepts:

  • network – systems connected for communication
  • IP address – routable address used to identify a host
  • port – logical service endpoint on a host
  • protocol – rules governing communication between systems
  • TCP vs UDP – reliable vs lightweight transport mechanisms

Then I reconstructed the actual sequence of events when opening a website.


🌐 Website Request Flow

Typing a URL such as:

https://example.com

triggers several steps.

1. URL parsing

The browser identifies:

  • protocol β†’ https
  • domain β†’ example.com
  • default port β†’ 443

2. DNS resolution

The browser asks a DNS resolver:

What is the IP address of example.com?

Tools used to observe this process:

nslookup google.com
dig google.com

DNS returns an IP address.


3. Local routing decision

The system determines whether the destination is:

  • on the local network
  • or reachable through the default gateway (router).

If the destination is remote, the packet must be sent to the router.


4. ARP resolution

To deliver a frame on the local network, the system must know the MAC address of the next hop.

If the destination is remote:

  • destination IP = remote server
  • destination MAC = router

This clarified an important concept:

MAC addresses are only relevant on the local network segment, while IP addresses route traffic across networks.


5. Transport connection

The browser initiates a TCP connection to the server.

Classic web traffic:

TCP port 443

The TCP handshake establishes a reliable connection.


6. TLS handshake

Before any HTTP data is exchanged, the client and server negotiate encryption using TLS (Transport Layer Security).

This includes:

  • certificate validation
  • key exchange
  • session encryption setup

The purpose is to guarantee:

  • confidentiality
  • integrity
  • server identity verification

7. HTTP request and response

Once the encrypted session is established, the browser sends an HTTP request:

GET /

The server replies with a response containing:

  • status code
  • headers
  • page content

Observed using:

curl -I https://google.com

Example behavior:

HTTP/1.1 301 Moved Permanently

which indicates a redirect.


8. Additional resource requests

The browser then downloads additional resources such as:

  • CSS
  • JavaScript
  • images
  • fonts

Each resource may trigger additional network requests.


🌐 Modern Web Note – QUIC / HTTP3

Modern web traffic increasingly uses HTTP/3, which runs on QUIC.

Important differences:

Protocol Transport
HTTP/1.1 TCP
HTTP/2 TCP
HTTP/3 QUIC over UDP

QUIC combines:

  • encryption
  • reliability
  • congestion control

while running over UDP, reducing connection setup latency.

Servers advertising HTTP/3 support may include headers such as:

alt-svc: h3=":443"

πŸ”§ Commands Used

To observe real network behavior I used:

ping google.com

Basic reachability and latency.

nslookup google.com

DNS resolution.

dig google.com

Detailed DNS responses and TTL values.

curl -I https://google.com

HTTP response headers.


πŸ” Key Cybersecurity Connections

Understanding network behavior is essential for security investigations.

Important concepts reinforced today:

DNS as an attack surface

DNS can be abused through:

  • DNS poisoning
  • malicious resolvers
  • domain-based command and control

Ports and service identification

Security investigations often begin by asking:

Which service is this traffic trying to reach?

Example:

443 β†’ HTTPS

TLS and identity verification

TLS certificates prevent trivial man-in-the-middle attacks by verifying the server’s identity.

Analysts often examine certificate metadata during investigations.


QUIC visibility challenges

Because QUIC uses UDP with encrypted payloads, traffic analysis may differ from traditional HTTPS traffic.

Modern monitoring tools must account for this shift.


⚠️ Challenges

Initially I mixed several networking layers together, producing explanations that sounded technical but were structurally wrong.

Key areas of confusion included:

  • MAC vs IP responsibilities
  • router vs destination host roles
  • TTL interpretation in ping output
  • understanding protocol overhead
  • what QUIC actually does

Clarifying the separation of layers resolved most of these issues.


🧠 What I Learned

Key networking insights from this session:

  • MAC addresses are local link identifiers
  • IP addresses are end-to-end routing identifiers
  • TCP provides reliability through state and acknowledgments
  • UDP provides lightweight transport without delivery guarantees
  • TLS establishes encrypted communication before application data flows

Understanding these roles makes network behavior easier to analyze.


⏭️ Next Steps

  • draw a simplified diagram of the website request process
  • compare DNS results across several domains
  • explore additional network diagnostic tools such as:
traceroute
netstat
ss

These tools will help reveal how packets move across networks.


πŸ’­ Reflection

Explaining the network flow step by step exposed gaps in my understanding.

Once the responsibilities of each layer were separated, the process became much clearer.

A simple rule that helped:

Build a correct step-by-step model first.
Only attach OSI terminology afterward.


🧩 Lessons Learned

What worked

  • writing explanations in plain language
  • validating ideas with real commands (dig, curl, ping)

What broke

  • trying to sound technical without a clear mental model

Why it broke

  • confusion between network layers

Fix / takeaway

Focus first on understanding the flow of communication, then map it to protocol layers.


πŸ“ˆ Skill Progression Context

Networking knowledge directly supports security analysis.

Understanding DNS resolution, HTTP requests, TLS negotiation, and packet routing allows analysts to interpret network telemetry and identify abnormal behavior.

This knowledge forms the foundation for future work in:

  • network traffic analysis
  • intrusion detection
  • threat hunting
  • incident response.