π Day 34 β Networking Mental Model Reset (DNS, TCP/UDP, HTTPS/TLS, QUIC)
π― Goal
Rebuild a clear mental model of what actually happens when I type a website address in a browser, without mixing layers or relying on vague explanations.
Key areas explored:
- network fundamentals (IP vs MAC vs ports vs protocols)
- TCP vs UDP tradeoffs
- DNS resolution in practice
- HTTPS basics and the TLS handshake
- modern web behavior (QUIC / HTTP/3)
- interpreting command-line network tools
π οΈ What I Did
I started by writing plain-language definitions for key networking concepts:
- network β systems connected for communication
- IP address β routable address used to identify a host
- port β logical service endpoint on a host
- protocol β rules governing communication between systems
- TCP vs UDP β reliable vs lightweight transport mechanisms
Then I reconstructed the actual sequence of events when opening a website.
π Website Request Flow
Typing a URL such as:
https://example.com
triggers several steps.
1. URL parsing
The browser identifies:
- protocol β
https - domain β
example.com - default port β
443
2. DNS resolution
The browser asks a DNS resolver:
What is the IP address of example.com?
Tools used to observe this process:
nslookup google.com
dig google.com
DNS returns an IP address.
3. Local routing decision
The system determines whether the destination is:
- on the local network
- or reachable through the default gateway (router).
If the destination is remote, the packet must be sent to the router.
4. ARP resolution
To deliver a frame on the local network, the system must know the MAC address of the next hop.
If the destination is remote:
- destination IP = remote server
- destination MAC = router
This clarified an important concept:
MAC addresses are only relevant on the local network segment, while IP addresses route traffic across networks.
5. Transport connection
The browser initiates a TCP connection to the server.
Classic web traffic:
TCP port 443
The TCP handshake establishes a reliable connection.
6. TLS handshake
Before any HTTP data is exchanged, the client and server negotiate encryption using TLS (Transport Layer Security).
This includes:
- certificate validation
- key exchange
- session encryption setup
The purpose is to guarantee:
- confidentiality
- integrity
- server identity verification
7. HTTP request and response
Once the encrypted session is established, the browser sends an HTTP request:
GET /
The server replies with a response containing:
- status code
- headers
- page content
Observed using:
curl -I https://google.com
Example behavior:
HTTP/1.1 301 Moved Permanently
which indicates a redirect.
8. Additional resource requests
The browser then downloads additional resources such as:
- CSS
- JavaScript
- images
- fonts
Each resource may trigger additional network requests.
π Modern Web Note β QUIC / HTTP3
Modern web traffic increasingly uses HTTP/3, which runs on QUIC.
Important differences:
| Protocol | Transport |
|---|---|
| HTTP/1.1 | TCP |
| HTTP/2 | TCP |
| HTTP/3 | QUIC over UDP |
QUIC combines:
- encryption
- reliability
- congestion control
while running over UDP, reducing connection setup latency.
Servers advertising HTTP/3 support may include headers such as:
alt-svc: h3=":443"
π§ Commands Used
To observe real network behavior I used:
ping google.com
Basic reachability and latency.
nslookup google.com
DNS resolution.
dig google.com
Detailed DNS responses and TTL values.
curl -I https://google.com
HTTP response headers.
π Key Cybersecurity Connections
Understanding network behavior is essential for security investigations.
Important concepts reinforced today:
DNS as an attack surface
DNS can be abused through:
- DNS poisoning
- malicious resolvers
- domain-based command and control
Ports and service identification
Security investigations often begin by asking:
Which service is this traffic trying to reach?
Example:
443 β HTTPS
TLS and identity verification
TLS certificates prevent trivial man-in-the-middle attacks by verifying the serverβs identity.
Analysts often examine certificate metadata during investigations.
QUIC visibility challenges
Because QUIC uses UDP with encrypted payloads, traffic analysis may differ from traditional HTTPS traffic.
Modern monitoring tools must account for this shift.
β οΈ Challenges
Initially I mixed several networking layers together, producing explanations that sounded technical but were structurally wrong.
Key areas of confusion included:
- MAC vs IP responsibilities
- router vs destination host roles
- TTL interpretation in ping output
- understanding protocol overhead
- what QUIC actually does
Clarifying the separation of layers resolved most of these issues.
π§ What I Learned
Key networking insights from this session:
- MAC addresses are local link identifiers
- IP addresses are end-to-end routing identifiers
- TCP provides reliability through state and acknowledgments
- UDP provides lightweight transport without delivery guarantees
- TLS establishes encrypted communication before application data flows
Understanding these roles makes network behavior easier to analyze.
βοΈ Next Steps
- draw a simplified diagram of the website request process
- compare DNS results across several domains
- explore additional network diagnostic tools such as:
traceroute
netstat
ss
These tools will help reveal how packets move across networks.
π Reflection
Explaining the network flow step by step exposed gaps in my understanding.
Once the responsibilities of each layer were separated, the process became much clearer.
A simple rule that helped:
Build a correct step-by-step model first.
Only attach OSI terminology afterward.
π§© Lessons Learned
What worked
- writing explanations in plain language
- validating ideas with real commands (
dig,curl,ping)
What broke
- trying to sound technical without a clear mental model
Why it broke
- confusion between network layers
Fix / takeaway
Focus first on understanding the flow of communication, then map it to protocol layers.
π Skill Progression Context
Networking knowledge directly supports security analysis.
Understanding DNS resolution, HTTP requests, TLS negotiation, and packet routing allows analysts to interpret network telemetry and identify abnormal behavior.
This knowledge forms the foundation for future work in:
- network traffic analysis
- intrusion detection
- threat hunting
- incident response.
