📅 Day 108 — Network Protocols, Ports, DNS, HTTP, and Remote Access
🔄 Topic
Studying common protocols and ports as practical SOC vocabulary.
🎯 Goal
Memorize key protocols by connecting each one to what defenders see in logs and traffic.
🛠 What I Did
Today I worked through network operations material from Course 3 and focused on common protocols.
Protocols are not just exam facts. They are field values in logs.
Important examples:
- DNS uses port 53 and resolves names to IP addresses
- HTTP commonly uses port 80
- HTTPS commonly uses port 443
- SSH commonly uses port 22
- Telnet commonly uses port 23 and is insecure
- SMTP is used for email sending
- IMAP and POP3 are used for email retrieval
- DHCP assigns network configuration
- ARP resolves IP addresses to MAC addresses on local networks
🔗 Key Cybersecurity Connections
Every protocol creates different investigation questions.
DNS asks:
What domain did this host try to resolve?
HTTP/HTTPS asks:
What web resource did the host contact?
SSH asks:
Was remote access attempted or successful?
SMTP asks:
Was email sent, relayed, or abused?
ARP asks:
Is local network address mapping normal or suspicious?
This helps turn memorization into detection thinking.
🔍 Investigation Questions
- Which protocol is involved?
- What port is used?
- Is the port expected for the protocol?
- Is the source host expected to use this protocol?
- Is the destination internal or external?
- Is the protocol encrypted or cleartext?
- Does the event show connection attempt, success, failure, or data transfer?
- Which logs would confirm the activity?
🚨 Detection Opportunities
Detection ideas:
- Telnet traffic in a modern environment
- SSH brute force attempts
- DNS queries to newly seen domains
- HTTP traffic to suspicious paths
- SMTP sending from unauthorized host
- unusual outbound connection on non-standard port
Example:
protocol=SSH
dst_port=22
failed_logins=45
src_ip=203.0.113.90
target=linux-server-01
detection=possible_ssh_bruteforce
🧭 MITRE ATT&CK Techniques
Possible mappings:
- T1110 — Brute Force
- T1021.004 — SSH
- T1071.001 — Web Protocols
- T1048 — Exfiltration Over Alternative Protocol
- T1046 — Network Service Discovery
🗺 Visual Investigation Diagram
Protocol
↓
Port
↓
Expected behavior
↓
Log source
↓
Suspicious deviation
↓
Investigation
⚠ Challenges
The challenge is memorizing ports without context. Port numbers stick better when connected to real attacker behavior and defender telemetry.
For example, SSH port 22 is not just a number. It means remote access, authentication logs, brute force risk, and possible server compromise.
📚 What I Learned
I learned that protocol knowledge is SOC vocabulary. If I cannot quickly recognize DNS, HTTP, SSH, SMTP, DHCP, and ARP traffic, I will struggle to triage basic network events.
➡ Next Steps
- Create protocol flashcards with port, purpose, logs, and attack examples
- Build fake logs for DNS, SSH, HTTP, and SMTP events
- Practice identifying protocols from port numbers
- Separate normal protocol use from suspicious patterns
🧠 Reflection
This was practical because protocols appear constantly in SOC alerts. Memorization alone is weak; evidence-based protocol recognition is the real skill.
🧩 Lessons Learned
What worked
Linking each protocol to logs and attacks.
What broke
Port memorization feels random when isolated.
Why it broke
Numbers are hard to retain without scenarios.
Fix / takeaway
Study protocols as purpose + port + evidence + attacker abuse.
📈 Skill Progression Context
This supports my SOC analyst and detection engineering progression because it turns course material into investigation habits: identifying assets, reading evidence, asking better questions, and explaining security risk clearly.
Instead of treating the certificate as passive study, I am using each topic to build practical analyst thinking that can later become lab notes, detections, diagrams, or portfolio writeups.
😄 TL;DR
Ports are not trivia. They are clues.
