TCP Ip
TCP Ip
TCP Ip
lill:S:UtJ
1-nhaJ~ -
"
• n1';iU1lJ~-J1~1JlJiJD-Jn'W~htJ1yJ{dDfil~
,,
itO ..
ISiJiJlns
s"aUla
liJl:S:UU TCP/IP
b~l.J'Vl1'V'lii
a,rJ'wm'1J~'Vl~(;11l.J'V'l1:::'il'1JU'l!~&i~'1J~'Vl~ ViI."!. 25371(;1tJ1J~';'Vl 'I11l.J~Dm~1.J'W Vhfllb'Wl oEflN ~~Jl fi:!.J~l'lf\lii 'Jl1'11 : 'VI1mhmDnal1
"
ll1il\l1~Bl\1
13J111ih'W1(;1~1'W'VIit\l'1Jfl\l'VIU\lam~l.Ji1
0\1 biJ'W'1Jfl\l1J~';'Vl,x'W 1
~.
b1fl\llm
luII uUiJiJulau1cin
www.thai.com/provision
amiufi iJllmau
... ~(;1~\l'Vll\lltJ1BrlhJ 1tin~j~(;1!ii\l~nitiMf)'W ... 1'1Jilj:::b~ti~ltJUMjbAj~~ ... lill'ljlAlfibI'lH'Vlm~l.J , 'W1I'il~(;1!ii\l 1(;1tJ'OJ:::~D~11.J1N~n'Wnj:::~'Vlnfl~l\1~ ... 1J11'OJi1uvlmblil :::~(;1 i.'1'\liil'W~h)~I\1VltiVl tl'W 1~l.Jll'l1=il'W f
--
b ~B\l'lJB\lL1.ld bVlr1B~
TCP liP
hntw
b~1:.:~n~\l1tlfi\ln~
'"
BVln tI'lJe-neuu
U dJ'Wb~f)\l~:i1U'VlUl'Vldl~ru';'WlJlf)cil\lb~
VU1
~ruBl~
''"
"
Ien
hl-J&i
lJl\lViil1~b ~£J\lbojh11.Jdldl~~l'11\I11nB'W
"'~El ~\I bBl-ii1m~ 1tl1t1l1V1t1~:.: n "'~BU1\1Vi 1'1 rum~ 1Jiu'Wvi1.ld:':b Vll 'Vlrll-J111rll'Wl'l b ~l-J1.ld:': f)\lfh&'\ln'W ~
"
n~l1ff)\lmd~:.:lJin~Ul-ll
"
"
...
ojj\l b ",l-Jl:':
"
h",iBAnHlli1'l'W,1[liWMd\l
1 bblJUYi 'Wd1.l
"
"
_- - ._ In8]nUIUIU8U
..
IsaiJlns siJilwa
rilb ~~nT~Am~11r1'm'J'n-lA1G'l[fJ{:IJ'VIllJru"{;l ~lnrlru::::1rl1m'J:lJA1G'l[fJ{ Li'mlJ'Wb'Vlrl1'W
1~v
iJ
m::::~mJ bn~lb<ijlrlru'Vl'VI1'J~1(;lm::::1J\I ,
1991 i1~~U'UbU'U~U~'VI1'l'Vl'th~\ll'Ucl11'U1"l11:lJU~eJ{;lJl~
Q.o
U{;ldl~ 1'V1q!'lJD\I
[fJ El{;l"V'W~ ~ l'Wnl'JN n DUl:lJ El~1\1 bU'W'VI1\1 nl'J"V 1 n G'lmlJ'U~1.rfJ bb~::': mn b~fJl ntJrll1:lJU A d::::tJUrlD:IJ~lb\llDdbbt'l::::b'U(IIb m'VILi'lrlru'lJfl\lLi''VI'J~m:IJ'lnl T
Q
4€',o::{
0)
Q..'
v....
eJ1'V1b'1!'W
.."..
• • • • •
ISACA (Information Systems Audit and Control Association) (www.isaca.org) ISS (Internet Security System Corp.) NFR (Network Flight Recorder) Foundstone Corporation
n.o u\l1cl1fu U d::::rn Ail ~lJ\Il 'lftJ 'lEl\l D ~1\1 bU'U
~1'W:::: Certified
til1'V1'hJ'u n1 brl'll
Denial of Service
14
17 17
18 18
m •.•
unit
23
Ugj L~in
(Information) (Control Signal)
23 24
iiflf'iU,YlI'l
25 27 28
28 29 29
3J?'i~YlU!iPU'ilOl..:J IDS
30
30 30 31
uon'
.. ~
...
..J:
~ ,.. ~.•......•••.•
33
34
35 36 37 39 40 40
IP Header IP Routing
42 .45
45
46 49 51 52
IP Address
1Un"5W'WbAl:t
Ethernet
54 56
ARP Cache ARP Packet ARP Reply : ARP i\'lJfl ..n:IJlltilEl~i1v'JJEI\'l : IP Format.
56 58 58
61 62 63
n'1"5t-ii,,'lu'JJ£)\'l
ICMP
66 67 68
tCP :
,..•.,.,., ..,69
69 71 74 76 78
TCP Half-Close
80
82
'f
b~~RUWbllla"5
..
85 86
l111'l1P1fl£l1il TCP/IP
89
90 91
-ii'i1Un'l'll":iE..:l'ilE..:lTCP/IP '111~niillnfiTwI'l11:wtJiilEll>1ilV n1".iIilElufU L1J'Wa-JV11N1:1J1".i(l1'l1~'VI:w1 ulfi fl1".i~ElUrurhm.Jl>11 "Jl:J.iI'l,Elul'l~:w'Vlnb~EI'W 1'll n1':ltI1~rua)JiJgj'ila..:l W1".id'VLi:JTVIl-J1U m,riElfld'Wfl1".i'Yl1-J1'W'llehldJ1'V1:W1V Stimulus & Response 'lID..:lLbllia::ttJ':ill11f1flQ Stimulus & Response ltJl1i\l1'W
94 94 95 96 97 97 98 99 99 101 102
106 106 109 109 110 110 111 Horse) 111 111 113 114
i111'l'l".i~'W (Trojan
rrrs
.rt
lVV 'Il''lIi1~1il'''1:1il'l'\lfl':lI1lL'I'\IflL'''1::':i::::1J1J
..;
Transmission
Unit)
Inspection
Fragment
.,~
.'
.'
.,>,~"
~ .
"
-----
.. , ---
!Ir~ ~~ ~ -------"
------~
--
una 15 i\1S1iUUlftllllUiut1Ul
n1':iS1';r1VtUAL!j1n
OteCOlrlnaIISslInce)m .•.•••••
Li31n
131
138 138
............•..•...•.............•...................................................................................•
<jlu·m1m'lWi.;;jii€l~tULil~
.................................................................................................. 138 (ifl€l~h..JnTj""lbml:::Vi.......................... n1':iSI':iJ'~ . 138 140 . . . . .. . 141 141 142 142
l~R91
nl'l"«bbn'lJ'I'l€l1(P1 m ";i«bbnuoii ell;:!~d:::l.i u m v.I R LI'I-TIU fll;:!~"'j :::UUtJ:!.l u&\ m 'l" TCP Sequence to
rn "'j,Hb nuoii
nT'JiilrnJCll:!.J
143
143 143
Broadcast
Mask Request
llund I
,.,•.•.,.~•.,••.,•..•.••• ~••~
~.~.~.~~ •••~
~.,
,.161
161 162 164 165
fl'l'13.JS'1f1Q,!1leJ..:In1':iRbbnU'I'IeJ,!jA
bbfJv.lv.lR ,1'l'1i''U-vi~iiI"n'Wa'W
1"1
1fi 1fi
!jij !jfi
FIN SCAN SYN/FIN Scan Xmas Scan Null Scan (Concealment Technique)
b'VIf'luf'lmio''I'I':i'1..:1n1':iRbbnU
Basic
UDP Scanning
176 178
unn
Scan)
" " .." "
~."
"
,.n
119
unn
,.,
"" ,, " "" .."."." " " "
,..,
".""
,
"" .."" "
, 189
190 "" ..191
"
"".""
"
"
"
193 196
trmetru:::m, h:w&i
Teardrop Attack " " " " "."" .."" " " " " " " " " " "
196
198 199
Smurf Attack
anl--lru:::"lJlh'lm,1'l:IJei
Ping Of Death Attack Tribe Flood Network " Diagnostic Port Attack " .." "." " " " "" .." " " " " " " " " " " " " " " " "
200
202 204 207
m,l-7iu:::im'
trnl--lru:::nl,1'l:w&i
UDP Bomb ICMP Source Quench Attack Winfreeze Fragmented IGMP Attack Attack " " " " " " " " " " " "" " " " " " " " " " "" " " "" "" " " " " " " " "
207 208
211 ".213 214 ".216 217 "" ..".219
unn~21
IP Address Sp,oQ.fing;
IP Duplicating Active " " " IP spoofing "
"""
" "
~
"."." " " " " "
'.'.,
" " " "."" " " "
Prediction
spoofing
u •••••••••
, ••••••
, ••
, ••
,229
-iul1lflun."l~Jbt~I"l
Gathering Interception
"
"
"".""
"
__
"""""."" ..""
__
"
,,
__
Information
__
·~~-.
~~ ~": '.~
-
''''' ....... ~:
-
-,
-:~ ..
-
'
------
., ..
~.,~.231
238
11
:
"
"."
,
"
"
Confidentiality ff~l".!nm:lJ
1 ~.v filULL1)'V1'V1flbl'l'lJ''U
bil!ili ifn
(filtering) packet..
u.:::~u
Firewall
244 247
Denial of Service :::lfluEI\lnu Ping Flood :::lflnl.U1)-:lrlU ifluEl-:ln'U iflu1);Jn'U iflu,h'lnu ifluEl-:lnu SYN Flood
" "
Smurf Attack. Tribe Flood Network Diagnostic Fragmented Port Attack IGMP attack attack "
ICMP Timestamp
252 252
rrrs
DoS bb1J1Ja'U1 Land Attack. Teardrop Teardrop Attack Land Attack Attack. Ping Of Death Attack, " "." UDP Bomb, Winfreeze "
nl"aihNnu
nl,UEl-:lrl'U lfil~L.1
nl"JUEI\ln'Ulfilulyjfl1)fl~ Unauthorized IP Spoofing Access & Session Hijacking . Network. Host, Application Scanning
Reconaisance
256
nlRWllD
260
••.•','" '.''.'•...•.•.,.,.••.••... , .
o "'
, ••
262 2,66
21"9,
--
,••••
,.,
•••
III ••••
II
••
III ...
"
"'.
III~.
'"
..
~~.
~"'.~.~
......
III '"
"'.
III III,"
"'
..
III ..
III III ••
, ••••••
"'
••
"'
••
III III, ••
TCPIIP Securi~
1 ujJru:;«r~n rll&,..] ~'UlJi'Unu rrn til W1~'U 1'I'1JJ'lI b1U1'll'V1fl'1 EJ\I v1uv11tJ l.Jii'Tw ~'UlJi'UnlJlJ~n1'
'U1'U1'll'11V1~NWI~U:l.!11 Vi1'.1i..]1UlJUElU lMD11UI'! ~Ul!I!JG'l1~1'bI[i)1'j"..]ilil'!tJv1~V1 , ,OJ
N~W§W'llD
'iJ \J
1JJi1-V[iJ4ln[iJ'lJD..j'~U~'Vll"]D nmE) J h
~\I'Ir1 ~ b1~I'l1D..jlliI'l11!ls:lDU
b~Ub11~U
V1 ,n~
\lVlna VI"]~11bUUhJ ,
bU(;Ibi{n~fi'n'Vlm~tJ~ hHlb1~1
'iJ
lu..]l'lu,7(..]Ian b1h~lun'U
luIsn bbYi..]ilW(;IE)'hU(i]
hmb'l1"] iil'll a..]
ClJ
1JJj:j,~u~'Vl1"]
'Vlna~I\1§l"1~11b1(;1alJG'l'UEl-.l1~1uvl'UYi ,
CI
D'Ubl'lEl1bU(;I~UtJ~(;I~ElVI bliil1 bUVIW1tJU1U NI'l'U1'!\ dh 1li1~V1m 1 iill -nEl~iil~ln~11.J~""1i'i1 ~'UHU'll'l&i G'l1~lJbI~U""11~lJ'WDtlbi91El11UI'l bWl.J..],r"]iil..]1ultl,juiil~Hib1iil1b~U\l , 1 1'lfVl l.JlIH6ttib1iill'1uilllii91niiElT'Ib~U'Vll"]
'l "lJ
1 u1Yit;im1u1'lfVl
1lil~Yfl1uhmb'l·i-JhbuD{G'lbli'lf
~ Ii
bbt;iV11V1ii~UH6~Tl\lfl ~~,j'urJtJ~:i"l~..] b~111 1.1 bbN..]ilV~l mG'l~a ~ U 1:1 6 blJ 'U,7(..]o:u N 11,,] u ~ ~ N Nvh~IU
<J
1u bliillb~
Ien bb 'I1\11'-l11mlJ'U"il1\1'1UUln.yj'l~bbEJnil'Ubi91a{bUi9IaDn'Jln
til::: 30 'il-UU'I:::~(ijn11ili!i1flrJl"]
"
b~
Ubl~l dl",,1uN$ia-.l1Uiib:J.J~lU
'iJ
1''I1'Um~
1)iil nfiLJJ:i"l l
",
Yahoo! l'-l\lblJ'Ul~
builmii'1'u'VI\l,J'lI1N ilu b(ija{ bi'll'l~..] iI..] j:jb1U1"IlVi dl'111U Kt 'I1qJ~I'la UN~hultJ r-h'W:J.J1 b 1 uu b11:::
ltJ
bd u~'ll'~
iil
lvwJ1EJ j:jblu hViv\blJ(i11Yiu~n1.1lJ'V>I't.TuM~a(i1 24 ill:IJ..J ~'UHti u ~:::Isn rii1UlJ I'l fl n""~1 n""~1 mnAu8'U blflil~ bU(i]dJ'Wv\
bb~\lb1Un1EJYlI'lU mNI'-l'WYfl1li u(1j'l'1ln'J::: ih usu bUvrrlJ bN~arllY11UM1~Ubl'lmb~::: " ", 'lJEl..JJJ'U .....
"
,f-'
" . .
.'
• :
.""~,, .
__ '
'JJl1rl'l11'11fl\lll~n 1\1rrnuau 1hi~'I1~UrlUb lnflfb~~ dJ'W~~'\.Hrl!J'IlEl-JrlUY\'l hJmn~'U , ~l\l'lln~
, , _'~'~
___
,'__
:c'
1J~ U~l
"lIm-W!J\lbb~biJ(»1J'l11b'ljEJf£'U~1'VIff\l'llmr'W b'VI~1'Uhn~~\1W'Ul1J-Jl~
bUiI::::flt'ln
lfl'l'l::fll(»~\'I'.hj_h::::
~ au 1lJ'Iil11'l 'l11"lJ El\lusn m Elflll\llJ'U 'VI'Iht'lii\l"lJfl \I'VI \I ~ Elyj~-W'll !Jl'U ~'Ill11h'WY\'ll U dJu~\I~bn(»~Ubbllil bblll::::e)til"i'lfll1~Mil
bb'U11i1~'1::::b~~£'Wb~El!J1'YI1Elbi'liim'l1iBb1ll':uml~~-Jl'V1qj "
b!Jl1'I1'U"lIEl-J mJjrll1~'jjlUlb\!
,"
bl'll'VI
"
'lln~lU"lIEl-JB'Ub(ilElfb
"
TCP/IP e)uJmJbbJu
I'l\l b'l'l'll:;iil~fll(»nl'j(u
11 B'UbtilE:J'1b :;'lJ!'J1!'JiK1l1iY\'11I1ln UM'I 1w'Ihv'l~u (ill fl1'lElElnlblJU"lIEl-JltJ'l ltilI'1ElIll~-Jiilci1:11 fl1d1nHlfl11~ 1illlfl(»Jl!JEl ~l-J bbtiW'VIWl u Ill:;a l-J1Jd ru'l'l El~'1::::dEl\l1lJfl1d~ml'l'l-1im.JlIl1 UV!n amUfl1'lru
"
"
1W
bdEl\lu "i'n
tfufl1'lElEln
uuu l1i'llwirlEllll
usz nl'lfl~'I'l~
"
, 1~nll\1"l111-J£unl1
b(;1;!Jl-JiK1flU LVlflf
dl til nfl'lEllJ
TCP/IP b"jl~-J1t1i~u'Iil1'l1fl\lbb1'JnbnElf
bblll:;lJil l bbu11t'b.Jl1'V::
"
tiwt1
useumn
,,
b-nll1i1J\lbut'l L ~Hn~111i
LiI\'IIIl\l 'YI~mbt.!11il'l-J~'1 ::::1inuEl\l L-Wt'l Llfn-1r-J'YI III1 V 1if"j€lI'lWU'I1nJltJl'1nl'llJ.J'1JEl\lbb~mnElfl~Elrh-J , ~U b ofi\l llJl1'1:; b1JU'YIti1V\ll'W~ b~:I.J 1tJ~1 EJ, a(7lVEl(7le)'1v,1V::::VI-JEl-Jrl nl'l'UI'1il El bVll"Tl VlEJmh-Jll-Jlfl'l'lffl~~Yl1€l1Elih~:J..J 'YI1fll1lJ1H'Vl b€lnrru
~1-J1:1-iEl1'1dfl\'l~U'Ilnli'!J
1Ul~€l'lln~lU"lI Yin1"jlJ1fl1d~l\1<1~fl1 I
""
..
(»Jltll1mn'l'lfl
il' fl ~tfu£'WEl8'IJ nu rll1l.J bVl1V:l.JW1Ell-J :;rl11l-JW VltJll-J 1U n1'l1i11Ji..j"j\l bbrn 'lJ-nElUn'l'l~fl\l-1r\l'YIllllt!"II€l\l bbLii , l ~1'lJEl-J1~atli'tf'U '1 nl'lVEll-J1U Al1l-J1Il':; \'11nsein !Je)ULLlIl'U:l.JVlI'1'1'l'l'U"lI El-JBULt'lElf b U(;1~-J El-JV :l.Jtu ~ a
II.
t~,~~1J1J
tce/»
N~~\lm.J1'W1'111:J..11l-hJ':l:;mV1LYl1tT'W'5,j"~:;~mmflvl1':l.JVI'W1~m.h.Ji.l\llJ
'iJ 'lJ
NVi1:lJLI'1~l'lJ1b~tl\l':l11
'iJ 'il
~1'W1'111:J..1l.l~tl~fi'~:J..I1ri tl'Wn\J bbi11:JJ1t1i~\ltl~1 'Wm1:J.J ll-hh::::lJ1'Vl bb(;]nem bDm 'VI~tl blltl\l"<ll n A11:J..11.J1 ~ ~ 'VI~tl11:lJb 'YilVl'W'lltl\Jl'l'WLD\I a1'V1l'lJ N~1UI'W1t1ibtl1 ~\I~;~'V
b'VI dtl
h1i'1'~"<l:::tJ-:rlJl.l'i\l1 Vi~~'W
::::J..I1'V1fla'WLVlEl1btJVltT'W ~.J~tl\li1~\J~
~El\JYh b fi:J..Ib~:J..I~~ml'W1'llflmh
fl1':l1.l':l1 n:O~'W'lltl\J unn bflEl1~ b~VI'iEl 19l b'ih 11.l!J\J':l:::lJlJA a:J..I'l'l1bl'ltl1v11\Ji bb~:::blluN~\J1U'lla\l5'VQ~~::: El1"<l"<l:::ijG'hul.lnmJu1\1
LL~11"1':lbG'l1~::::J..Ia\li1flun~u11.l!J\Ja1b'VIl'l~'Vnn '
vm
miill'l'i:J..Il9l1 b'I'j'i1:::1"111:J..1l-l\lliu1Ufl1':l~U'VI1-nlllJn'Y'l~ll\l'lJa\l'i:;lJU ~ ,
"
'VI1n1.Ji1~\l1l9llJfl'Y'l1fl.J
b'I'j'il:;th:::~lJ
n1':lru1l'ltlu\J
ba'l! b'Y'l':l1:::':llfl~lU5u1.Jliul'1\1'lla\J':l:::lJu
~luLlIu~\I~ 1Ufl1':llJfl':lfl
lYn"l:::i1mJ1u~h
bb~fHfla1'V::: H'lifl\l'Yll\11'11u
,,
iifllJn'Y'l1fl\ltL~flbnfl1"<l:::i.l1m'imh~1~Li'h'VIJJ1~
1'11'V1t1lilvll.J1U1(1iflci1\11 'i ,
~ 11fhu 1 'I1qj b~:J..I ~U':l:::lJlJ 1l9ltlfl1'l111\11U bb~:::wOOJu11t1 b~fltl'1'Y'l11l:J..InlJ fl1':l 111\11u~ilJlIllu :J..I1n~u b~ a ~ '1 ~1.l':l::: ~'V&Il1'Y'l:J..l1 fl~U b~ fl tI '1 'VI n bllu b~l'll fl \J b1lJ hVi 1 "llfltTuni:lfl1':ll.ll'ul.l':l\l
b1lJb1H'I'hlfl1ll'i'i:J..Il9l1
b.Qfl'VI11'11thau 1"l:J..Ilfl~U
t1~lJl.l'i\ltJa ,
Vi 'l'h 1lJ
b'I'j'V 1~~ltllJnlJN
~b1i1:!J1b~tI:J..I'1J:J..Imn~'W
1
~lJ1fl1'i~uimfl~'W
:i1~u~lba'Wtl'lJ1~
i!fl1'ibn1Jb~'Wflau1iil'l1
bl.l~mml.lt'l\l1~e1V1'i1b
'Vm~Elil~b1i1'1J:J..I:J..I1n~'Wn'Vhfl1':l'lJm~
Vi1'VIqj~u
i:lb1l1'1'Jblfl1mfl
~'W bvi:J..IbblJui9l1Iiltti'lqi~u
"
h bbt'l:::bbt'i1'l11(1i'VI~fl 1l-ltlcil\11
"
1.J11'V::: LlI'WaubVla1bulil
biu b-1i1vJblfl{
'i:::lJlJ b'Y'l'i1:::
'i 1'1\1f)1'V'V:::iju1\1bb(;]1:JJmn
1'111:J..1t1 a lilfi'iJn'W ritlU~"<l::: i.l1mn'W 11.l ill TCP/IP 1:JJ1t?i an tl P.J n bblJlJ:J..I11 Vill t'l a 1ilfi't1U n'VI1D tl1'V'V::: b~~fl111.JtI 1ifllJn'l'\l~il\l'llfl\J TCP/IP bll'W~1n'W~11t11
"
-ntlI"l1'l'i:::l\1'l1tl\lN1l1bbliltlci1.J1l9l
"
Ubb1l9l1\1'lJEl\l bb!:lfHm)1
"
a1"<l'V:::bllub 'I'\I':l1:::dJ1'V1m~'lJtl\ln1TW111.l'i
'VI~fl'Vl111'J:; 1t1'lfii'"11n~~~i1tl
~"
1.JlJ'i1'Vun'WN~H\ll'Wn
~\I
~ "ii~Vln
bntn~'W
tn tl1~i.llm'i
ml1 b'.dutTu1t1i
"
b~tln~U~~n11m
'VIl9l bb'VIU fl1'i b~~'W1~'V :::tlci nlJl1'WtlU1\1l.l sa tnfi'mi 1'1::: bll'Wu 'W1'1l1\1l.l'i:::{lth:::'W a:J..I~ Vib':l1i.l1:J..11':lfl111 1.l'i:::1t1'lJii'Vlm 'Vl1"l1'W h1i1t?i:J..I1n~U
"
"
""I1.JflU11.l':l1V1flflt'lfl1'V'V::: l:JJtlt'lal9lfi't1
"
bb~tf'Wii1t?i'l1:J..11~fll1:!J_'h
1 : TCP/IP Securify •
·c€~,;·
, .\W:"
'~.
-
,
•" --f.,.
"
"
"
"
"
"-lUUb ":il~;f1U\l';h
..
TC P/IP
iHiOUnfol5il\larh,'11'i...?"
Denial of Service
dJu vi (I) 1:::'VI n nu~"hflul'l u
I'lm.JW1 b(l)i1fMl\1'1'l1f1\1bwmnfl1tTu usz nd:::'VllJMili'l11l-.J b~mj'u'IlfI..J«t
'i 't
n 1'l1l-.Jv1imiuu i
'!.I
BU bMfl1 bU(;I'I1nn111Jf11ndh
'I
'I
1U1J..Jd:lJ lJ
ff\l(}JiNVibn1il1'l11l-.Jflu'VI1UfI~l\1mnJi\lMfI"J:::1J1Jvi(l)n l1JUb'VI~f1 1 b
"
11 bbM11U\l1'Un1"'lrlf1'lJmn'llfl\l
'lJ "I "l
bl'lJ1'1l''11
1M E.I ~hu N1 i-v::: biilb'l111'l11l-.J bflm·'I1EJv1 nfil~U'lln unn bmrltTuil bQ'V'Il::: 111v1unn bn€l1 1'VIlli b 1 fflm"'lm~1il1f1filNl'U'l:::lJ'lJ1nHlI'l11J..JU~€lIil.llmiilm1(l1
-"
bLfl:::'Vllnl"Jun1'I1
'lIlJ..JU
'VIl-.J1JI'l11l-.Jll'l:::lJlJ'IlfI-J b'lliJ\lI'l\lU flfll'l.llUfl8 ~ub1JUl"n1J..J dh hv1nnJifl\ll Vl8\lfl'1U'VIi1'.liil'1'VItlJ t ~ " mruvi unn bnB1l:i1'l11l-.Jlh:::iiI \I~'V :::Vll\"l11:IJ b~U'\IIltJ'Vlnf11tJ lu1:::ulJ lbC;\iJ'V'IUUnl"'lm~;-ll'llB-J , blsn bnfl1tTu 1(l1'l181 U'liflU b'llt'llU"I 1 n1'l11J..JJi f1\lnl1v1'1:::lJ mn1:1JlJ 11iltJllJ1(l1t1JflU
ill1(;Itu
blJU
b'l'm::: lu 'l:::U:::'VI ~-Jrrnu ,rnn di11u1 ~ 'l~UlJvll\1 '1tTu l1Ju~\lv1ul'n~unl1 b~ l-.J , mn 'V1m&\J..Jv1fl'lm'lm~Iil'lfllil biil1ul~1:WEJ1mvuun bllJ~l\l'T llilmQ'V'Il::: bllJ 1'1l''I1v1i\"llB-Jl1 b1JU
rnstimrnuilwuru:
dJ1'V1:IJ1U'lIfI-Jusn
tn Bfvll\1litJ11JU1-J1:::U1Jtnb'lfll1:IJU ,
"
"
dJl'14J..J1EJ1lJl'I1fl'l:1J1dn;-ll\11U 1cif fi\lbbiill Ni:'l'i11n1111riiln1utTU€l1'i1"1::: 1lJfl«tlill(l11uu1::: lu'l.i\Jbfluli (l)1l-.Jbil1'VI:lJ1uy)rlnnfln1'Ufll'V'i1:::1:w fl1J..Jl <H11Viu,n1'l11il vlflNb1iuu€imt'lfl1l b~tJlnumdvi bbeJmnBfbfl\lllJiillJ..J1;n
"
"
"
I.
''lI1~::1J1J
Tep/IP
'l:'; vl11~tJ'ln~\lnl
'lJ
l~nUf1::;li1'l'ln'W'lbVliiNm
vifl'fl n btl~tJU bfl'iifl'WI'l'llJiIlD\lI'Il-Jvi'WDn"l'ln"l::; b~D b-firuG'ln~'l b-]'l!.J1 bdhl'l'W~ bbN\ll-l'lnfl'l-;;J-;;J::; btiU bb~nbm]'n\i1~1m'li'Wfl'W ~hl'l ~llf1n ~\I,r'W(I].'llJ b~~U..jI'l\lbYhJ~n1.;;1lJ,r'W~fll-J b~U\ln11QnriDm'W 1...;w'W
"
"
VllbvibllJhl1(;]'l\l'lb'l4G'iTiiWJl'lbl1
1tJ~111iln
DoS '14m U11,.1n 'l'1'11 vid:::lJlJ (l'Ifll-Jvh b(l]fl{bbf1:::1 1 b 1l'lUn'l'lhl-J~,r'W"I::;vl'lb VI1'1 'll-l fl''l !.J11n b 'Wn'l'lbl1 1 b-B\I 11'lu m:::1JdU mJ'lJ [)\I'l euu
VllJ1n1'l 1~fl'll-JtJn~
n'l'l~ D'l~'V11bl11'l11l-l iIl'll-l'l. fl'lJ[)\I.::;UlJ 1il1'l ~11il\l,r'Wfl1 AWllDlJ n'V'l1D\IU1il::;'li[)\ll'l\l~ii bU'l'l4l-l'lutT'WbD\I .::;lJlJ bl'l1viiiD~b Uhn,r'WM'l\lniilt11qtJ'l::;iIl\l#l .:::lJu,x'Wum.J 1aJiitJ'l::; lu'llu bllJb'D-Jv.Jnfl1mU\llJdl1b"lifl{ b-riD lV1lJ1n1.
"
mllJ~n'l'j"Mfln1.-rlJ-G'l'\I"II'l'l1mtJ,xubfl\l
"
-;;J::;
1~n-;;J'lnnl'llJ~n1.~.::;lJlJ,x'Wl1lVlmtTubfl\l
n'l'llJ~m.~
1~-rlJ btl'WN1il-;;J'lnn'l'lvl'l\l'lU'lJfl\l bbD'V'l'V'l ~ bl'l1fuvivll\l'l'WflU ~\lu'W~\I b-B{l'Jb1 fl{ use ltJ. bbml-lvil'lfl tl1U u~m.~~\l11'11il rrrs ~Dfl'wilEl~
'lJ 'iJ
b[)'W#i1'mlllJn'l.rll\1'lUfl~'l\l
"
tln(ilfl\lfl'J..J1Jdru'VlnG'l'l'W cl''l'l4-ru 1'Ul-Jj.Jj.Jfl\l'lJ NbiJEm 1aJ'Vl'l'lU"l1nllvi fl\l b Vimus 1'l\lc.J illJ'WmJ1-;;Jfl b(;] f1::;I'1~ 1 b \lJ'W ~fl\l ~hu m :::1JdUrrrsus 1l1wvi b.lvll n'l'llJ'l11Gfb llJ'lJfl\lbllJ hl1v1~\lEltJb
"
"
U[) bl-J~m~\I'Yil\11tliin.y;n
Is n'l4it\l1'l11n',hviilm.JG'l
"" ,
Nl'WNb VllJ1nl''iBlJbtllfl1b
tlG'll tI'Vll\1 usz bllJ 1 "lil1tJ1il1 U'Vll\1Vlln'l'j" uil tilI'l11:J..i'l4m Ubbil1d\l'lifll-JG'l bllJ bW~tllfllJ-rlJ n ~lJm U\I bl'l~D-Jl'lfll-JW1b(;1fl{v11h'W'lJfl\lb 'l11~,xu-;;J::;(ilfl\l b1iI'l11l-JWUlt11l-J!.J1n b~tI-J1 'l bb(;] bit [)\I"l1 nb'VlI'll U1 til11 1(ii~l'l.J'W1nl1'11iil1tlmn m.tl.:::m 1ilc.J til'lifll-Jf1blJU
'U
"
"
"
bbf1::;
fl'lm'lflb
'1i\l1lJb 'Vll'll'U
l1'l::;~U iIl\lb'l4G'i1d
"
"
bbG'l:::n1il'lU blJ'Wb~~\ltlnWiviNb'1i~fl bel11 T'ldffl\lb Ii'Il1J.j1'l1~ml\111bllJ U-;;J-;;JU'W'I41nbllJ'{j'Vlll'1'1bul'llV1lJ~n1'l H\llti1~J'W 1 , 1\i1n~m:.; btlub~[)-Jbbtltiln~\lnl1 11\1 bbiibVll'll'W lINl1~::;~l'l.J'Wln'l1'11ih fl'1'lbbl'i1 'I4'Wnbb~l bbM bbM~::: 'I4'U b l'liiih~u~ , m.1"';vll\I
iJ-J1U 1~fl~bfl'l-Jfl
"'lJ
1tlflUl-J1 'lnVl'll-J 'V11[)"l::;:ilm.flflnbblJlJ:iJfl\lnUfl~l\1~~ run run tI~~::;'l'h b Vi'l::;lJU1l-J1il'1m'ltlb VllJ1n1'l 1~ bit fl\l~ln
'l'W'V11mh\l'l'WNI'lWtil'lI'l'll fl\lG'l'l'Wtl'l:; nau G'l'1'W bl'ldlU 'l4it\lb 'W.::;UU ~\I,xu 1I'ltl1il'1'W q!un b'l1
I'lfll-JWl b(;1fl1~\lfl''W bbG'l:;a.J\I~'Wvi-;;J::;vl'lbVl'l::;lJlJy'f'l\ll'W fl bilD'I1tJ11'Wl'W~iIll'l bbtil::: 1~~ bVlffl:1J1'j"m~flflD , , 1~niiib~V\l 100% Yi1il'1'l , : TCP/IP Security
.1
~,,<. '#~
--
I ,.
. .
---
"\>.:.~~.~~
."
~'~'~'
,
-
---
~-
-_
--
~,!
'"~
---
.
'
" --
--
VilJ1rnl1$i~Vi~~
1 Vil:-;UlJVI~I'I'VhJ1Ur;N 1 ,
V11~tYUMtlf111
Denial of Service (DoS) blJunl1h:IJCI1~j::J1\11~lh~GiI-JI"1'V1~n~flvi11Vidhllj:IJ181~Gill:IJ11f11Vi U1n11V1~fl1~1V1r:noii1$ifuu1n11"11n'Vlf'V'lmmVi~tl-Jn111~ 'IJ bill b~~'jI\lbl€)~D:'.J~lnVi"l~.fl{j"rilfhu nl:-:vh1~8('11-Jnub~~vJblil1 bbG'l:::~1b~~'V'hI8~b8-J
'IJ
DoS wi€)
1I'lVi'l:-:1~fll~11l-J
1.h:-: bflvrdG'll:IJ11f1m:-;vll
'lJ1n11N
l(l\'llJ 81 n bi!8-J"l1 nllJl1b U1:::UU b{i1 wi1-Jfi:ij~ ~Un'W"i8-J:IJ1n:l-J1 uVib1Ju~~tiilu b1111'liVl,rWr\lfl\l~fJ\lf11d (inn nllfll1l-JtJ bV1
~
1 'I11'1:IJ&f1~1u'Ilru:::b&i81nunT"jiJil-Jnunm:::y'h1~l'ie:J'l..dh\l1'.l1Mm1l1(i1Vi
~
man
tJ~W{i1 fll1mr:::
q
GilDWI,nm1n"l:::UU D U
fl1.JG'l:-;~lUbiil:IJD 1W1UGil'lU ~ bl1ruD1"1'1:::i:J£J\ih ~ h11F111 DoS t!uijb-WtJ'Jn1di"l\lifil:I.Jt'll'iild..nmj1-J'Vh:IJViu'VI~D u Uwi'l1-J'1bb~--Jn11 Dos ij:lJ1nmuGil11~~lfi 1~11
ms
DDS
"I:';blJ1.J'Vl1-Jf11~m'I"J l:::~U1:::1J1JtlBD'~f11d
Database VI~€JbbEl'W'I"J~ bl"1-E'U bb'l1UEl1.J111~11'V11nm:::'1'1lci'1 b~"il1U1:::~U 1I'ln(ll1~ 1i-J "Id~iil1:1J1dblbojj-J1U1C'1 bbliib~D'Wl'lti\ln11 'IJ n~11i;i\lmd DoS 1I'lf.lbbelmnEl1uil'lu'l1UDU11n11
l~U1J~-J'Yl:I.J~n
&rD-JHb'l'lI"1t1l"1bbt'l:::vrnM~'I'll\1~lUIi'18~l'llbM81
bbGil:';blJum1h:IJ~"il1mfl~mhmYhtTu
DoS 1W1tJiE'Vl1-Jn1Wl1V>lbV>ld1:.;1~~Dl1dJ'Ull~~n~l:IJ~bn~"I1nmJnbn81bb~i1rJ1\lb~ , DoS b 1U hrv'l(i]l\1'11I'lmilWl:': bl1J1<1jVlViij'l)Ull'lb 'VII1iLb~:::ilo/lmiiltJ\ltTun dJu bmhtTuwi1-J~-J'VlU:I.J'VI1f!1~ , If!ln1d:-;1J'lJ 1tllbbmm:IJf)1 ij'Vlf'W mm bbiil:-;N'l11U1ill
'1:-;111tJLb~,ml
..
b'W11::: bl1J h~
i'l~-J1iPllnlb~~mhtJ
"
m"l"l:-;ilbbfi1:IJb~:lJliim'lhSUb(llD'hU(ll~lb&\~l
n'lJ1tJdlbndl-J~1ojjrl1
"
Lnf)~rllci'l
"
1~
dJ1V1:1-J1tJ bwmnD~
1V1qj"l~D1AtJ"iitl'lJn'I"J~D-.l buGiI'lutJ1~ntlU'IliI\l1:-:1J1J
'V:-;vllrl1d lvd-J1I11~mQW1:'; b"ll:-;"I-J1tlir\l'V\i10fJ1.J b 'VI~ltTU GiI'-.lVJiiI,b 'r1d:-;1JlJ~\lVI:IJ\i1~\I'Vll:il1!:Jf'l\l~1 ~ltJ , b'Vlfl'l1l"1'VIiiiT~lbtl-J~rl11 Vl1J1-J1"1 bllJ 1 'li~niii~t'l"Gil1tJGiI-J1tJ1~tJNij€)'IlD-J b f-J unn bniJ1"11nm1 hd-JiiitihtJ
••
&~'1~lI:UlJ
Tep/IP
.:!. ~'I
«n'Hru::;~11t1'11ihlnl'j"
DoS ~~nl'j1Jmh~~E1
t1n&i'1lD\!l'iHvJblD{J'W 1lJ~lm'j"C11i1J~n1'j"~M'W~il\l
'I'htl1bil~H1~m'h:IJ (Network
" OJ
-ifil:J.J~vi1lJ dJ'WtI 'j"::; lV'll'uviD r:J1~ 1~ V b1JlV1:J.J1Vb Vl tJ\J1Vi-ifill-J~vi1oii\ll'WM1~t1n fi'll-J1'j"mi \l ~·h'W111u\l~'W'Vl1\J bb~::;tl flltJVll\l 1A~ bEl'W~tllillV'Vll\lvil\JM\lA\I·l'h.n'W
-1t\JNlilff~Yil Vnl'j" 1Viu1nTHblil::; rrn 1oiiU~nl'j"'1I8\J bMvJb lil{ bblildAfl bil'W~n'V::;vll1lJ , ~lb1'V,r'Wbfl\J • Gifiln1~~D~1'iv1a1~ m~lblJ~bil{vJ
"
11
l18fb vimll-ifD~lill-Jl
ill iHN'i:::uu
blUi 1l{vJ b1 D{ VI~8 ~1~1 iu ~ bil{vJ b1 fJ'f-1t\lfll'V'V dl nl11J 8\1 n'Wvi u tiu 'VI'W ihh 1 nl'j" h:J.J ~'1 ~ b-iim.J ~ fl'J::;Vl11\l bMvJ n8f~\ll'ilVi1lJ
"
"
lil'V1n
"
ffll-Jl.rl
&8 ffl'Jn'W
U '1'111Vi
bllJ1MvJnflfllJlil"lmlmi1'W-ifD~lil1ubbm~\JNlil1iJi
"
"
b'li'Wnl"il'j
V1 Vl:J.J ff11\Jn1,b-ii
•
8mi €I
'IJ
1Vil-JlnYiff~ -1i\l'VIlnJ::::lJuvirin
"
n~Yi bih~11'W
1'W'VIfllvnlru'J::;:wn11
b1ilm~1l-J
Iurrn h:J..J~~ltJ
1tl,bbnl:J..J'lJ'W1(i]b~nvig\JbblilnbnM1'Wfll"ihl-J~1t1u\ldh'VIJ..J1v'I'I~i1l-J'1n'W
U'WbM'V'Jb1 €I
'YI~D H~'W~~~rl';1'W1'W:J..Jln
11 'WillI
hi m
"
ffl:IJ1'Jrl'l11l-J11111Vi bA~Nlilb~:nD'W
rm 1tJmh\l~'Wb1l\J
bUV1 ~:Hll b
'VI1m1Jl'Y1J..J1~
tT'WdJ'Wg1'W~:Wml:J..J~1~q)
"
bUl'lb1fn, bbDl'jW~bAi'W) 1~Vll~'1::;vll\11'W1~u':i::;~'VIB.rnl'j(;hnllAdl:l.JdJ'W'i)~\Jbafl\l'i)ln au su i1\Jvi a nl"i DoS 1~ V~l::;UlJ bil\! n13J~1 l-J11rluij isn 1~ «n'Hru:::: n-rs 1 : TCP/IP Security •
(ilillJ fIIUtJ,nhu
h~~Ju
'J111mnnllll
h~Wi«:lJtlYlit'Jt'l
b~l-J~ih:::
'111lV1I:::uudJutl:WVf1I'l'JIIEJtflllll'1hnu •
1.h::::lJlrul"iliJ1~
\l11flUl\lb'liU 100
bllEJ1bobUM YnmilJh'll1~r;;jlmimlJtfl1V1lJ1nlI1~11Jh£.lt'l"lb'Jlllil1tflFi(i]1~
1
•
Vi
"
lfWUtJ:lJ dJu 'VI1EJW:::'1J tJ\I~ln'Ol bt'lEJVi b~ £.11 'Jill mU1 EJlJl'l11 mi':J £.IVII£.I nrrnnn ' 'V1 €ll'Ol'V::: ln~b~f.I\lnu nlJnJru~b'j"l
"
DoS nUl"nl~
1~1Ji
'"
bVhJ\lbbvi'l11bI1b(i]81(i111'J11~m bU~£.Im:Jnmjl\lFi'Ol:::
"
Uvlnllbbn1'1.1dTI'Ifunllnn
"
DoS 1lJ~l£.lb'liU,x'W
(i]
b.Qfl\l'Vlnlll'
mdbU~f.Jmdlb(i]€IflJ.i"hA(i11il1~81'VbbniJClJ'Jlll
blU 1'1JViJu'VIEJ~rvh,'llu"i'lnlU ,
" "
Ulll'J
bbt'l:::tJ\l1J.iilll:IJ1dn'JIIlm\llJ~J\lnU\l11
bil\llJi
l(i]EJ.yfl11lm1hj.J~bbl.lU 1J~nl'JluEiub(i]BibU(i]~bbMnlih\lnu
"
Ltfl~j:Jmj Uvlbd18191"';lbbUn5m!lru:::'1Jil,ml'Jl'Oll-J~B€ln
"
"
1JidJu
3 1h::: bf\Yl~U"ilU(if\ld
•
•
..
m, 1'li-J1UYlfV'l£.lln,~j:J,,)lntfl91uvh
1 Vi'1Jll'lbbl'lillU bb1:'l:::.:i1011llJt'l'lm,nL'li\llUYlfl\lEllm
,:llJi
"
CPU
9lubnurh5\l
bl1:'l::: bl'I~ill\l€l~:::1uui:::j.JJ1:'lt'Jillll\11l'1Ja~u 1~ vllt'llt.J 11'l1,lt'l"11\1'1J8\l1iB~1:'lal,"r;;jub "i'l1"T~'1::: 1i1LUn1'JlJ~nl'l vllt'll t.JYll\lm t.Jm'I'J'JII1€lJltfllll.l1:'l\l€I\1I'lU,::: n €IlJ'1J€l-JUlil biin b LYi1J~m,\'Ill-Jlln~1Ji dJUlilV'll:::iTIll 'mfi\l b1JU~\I~l\IU 1Jimn~a~
1 WYh1iil~€l1ull91:::
nlsluillunSWSlnSiluillulwsilwarianlsusnlS
1'18:IJvh b~1il{bbiil:::Ulil bi{nl'il\1 b bVl~lJu1Jibbri bblJu~i(i]t'1Jil\lbu(i]liin,
nJi€l.Jn1'l'll1V'1 Ulnd~lW1U'Jllct\l
m.htJI'l11l-J~1.
Ylfl\l tnrn
~U~lJU~flln,
CPU 1Unl'l
Time), 11'1'J\lsf'h\l'iiill-Jill,
"
1'll1:lJ1:iIl!-J1,n1 Un11b-1iil:IJ~ElfllJI'1Ell-J-Wlb(l1i'libl'1~~N
TepliP
ilru'YIJlii1 'Wnl'lvll\11'W
q ~
L(Y)[J~11tl Ufll'Vl{l'I ~J1n'l b'YIril'd 'il:::n nes n uuu in111u~m'l,yj blilfClnililn bbUU:J.Jlb>'iEl111~lm'lClU~m'lnl'H~[Jn(ilb iUb l'I'O)
b'li'Wb lUb'Hw
",
tl1:::~'VlBml'lnl'lv11\l1'WL'l(y)~1L'l\l:I.Jln
r:rt1i 500
Vl [J\ll'lf)
dl'Y1{Unl'l
'YIlntl~:l.J1runl'l1'ii\ll'Wa\lfl'hdufl:J.J'il:::vll111
DoS tl'l:::bJl'Vl.cr'il:::flll'1u.:ziW;Jlfl\ilmril.crmbiJ'W
"
H\ll'W'\I~\lb~[J\I
L~mJmJ l~wm'il3,J~
"
Network Connectivity
1'Wm'l~fli.~l'l~l D\lUnl'1fl
Network
bb\l:Jl~rifl [J:fJrl'Wr11il\l
Connectivity
"
&1\ilI'i1lj:::'VI11\1b~fy.,lnf)fbb~:::11'1~bEl'W&i
1 rit1'W"I:'::b~[Jnll
'il:::1oE'V){wmflj"VI'\Jd[J1'I113,J~11 'Wfl1jbn'Ub'{h 1 'lbb~:::1oE,1L'l1 CPU 1'Wfl1jtlj:::m~NfN flU bb~~:::j:::'U'UtliitJMfl1j bbtliii-.:l'il::: Himn'VI~mJmJ1lul{Jl j~'Wnl'l{j\il.hfl\ilvi
"
1 Connection
u '\J'WEl'W1l~ril1~ril'Y1,j-J
Connection IP ~\lt1'W
t1'W1l'l{qjllil1Yifl"lm'lCl~Elffl'lfl'Wl~'VII~mJ11l'W'YIm81
1"V1~1111l'U'Vln<lfl1j1El\l'llil,yj:fJ
'"
tl':::'YI,j\l11'O):::'lIilv11fl1'lb~1l3,Jviillil13,J ltl'lLlilrlilL'l
TCP ~1llilil'U{Ur11'IJil
,1'W
L~ill-JvlilmflUl\lvlf)b.j1l\l1'W~1'Wd'Wmn
fl1'l'llilfl1'lb~ill-Jviil'YIt'lilfl1Vi1~:n1'W('h
'iI
ii\lbbiil1n1j
~~vim'OJl-J&iiil~v11il:::
'iI
1'1
b~1'V'1 bIf)1Li'Jl'Y13,J18 .r'Wbb~(y)\l111L'14'Wl1fi-.:l bb!'lflbnflf'V:.::ii bb1J'W#il(>}gv1~l bti'W ill'il'il::: b~m.Jt;i1ll-Jl bb3J 'illflnlj'YIl-J'W 13,Jb~3,JbbU'U Dial up bb~nil11"l8"1(>}btl'l1:::'Ul\1'l1il-:J'l:::UU , b'li'Wn'W ~\lQ nl'lvi u !'lflbnilfii uen bn1lf b~ flnlflv1 mm:.:: ffl-Jnalm'lblv111
"
1'IN'lb'lI~b'1lilf'llil\l
Vi rrn
1:
TCPliP
Security
.1
.,:~. .
.
, .:
.,>.: ~
--
-.
"~
0("
~.
-
....
-
..
---
---
-.'
,
---
--
---
1u
hhl(i)fl8
~ TCP/IP i:Jn1'l1.J~n-rH~n'1'V1~lVilV1\l~ill·kv:i
81oE(i)'l1'"lNillJJ:::l.JlJ~~~:::
1V1
'iJil:J..JfiI'1·nnYl'ilTlru1lJ~nldb
llJilnTl-rm::flflllmJ~ill'lf(v1(i)'11lJiinw41n(i)~oElJ~m'l
"
'I1lJ~nTl1I'lv
bbfil:::Yi~hR'l!fif)lJ~m'lb'VIG'il,r'W~lJ..J1'lfl WV\lEllA'm'lliPlUi'lnl'l
~il1V>1blil{n~1J..J1'lflflnh:J..Jml~
"
tlllm!1\Jv1d1U \'\I8{(i)v1dJ(i)1'111J~nl'lil~
lv'i'lil'l~f)
rrn hl-Jm~1VlJ~m'l
Echo ~'lbUUlJ~nldill'\JojJf)l-JfilV11al11J:lJl'11n
"
Echo ~l:J..InlJ
1J~n1'l~U'1v1'1:::;iIl'\l'l1m,jfilf)ilnm il ~1\1Hi(i)illJn'Wbil\ltn
Chargen, Time u 1;'1:::; 1V1lJ~n1'lB(;11'WiT~~\I~i1\1 "h rnu 1'Wb1 1;'11 U"Jl (i)b~1v1lJ~n1"Jb 'VIG'i111vl1\11UnUbEl-J B bbVlmn(i)IDai(;1f)lJ 11.l:lJ1'l:::Yll1\l bbfil:::dj8fi-J'1(i)'VIi1\)v1bTI1V>1mrfhJ ,
V 1 'l..lbil{vJb lil{b~Vlnu
'"I'Wl~H:hlfil1bU:~:::'Vl1',t11mml1.l11i-J1Uil~l\1~U
"
n&ivb1fi11~\lYl:lJ(i) hhvj€l.)(i)n1'lnlJ
nT'.il'il:J..J&i1um&df)wvh1YibiPl~fl\lbMV>lb1flidhvlmVYlV(i)n1"J'Il1\l1'WbVliJvbiPl~il\Jb~V1 , Yllnilm'l1.l1mJ1\1b lJ~n1'l echo usz VlV\I bam.'iilv nl'l h:lJ &iall V b'VII'lUfld'l:::~1:lJ1'lfl'll11 chargen EJ~ "J1:lJ~\Ib1j(i)b'HmblJ'WtfilIi'lTI
'!J
bbvi
l-nBUb .Qil\l'"llnm"Jtln
v
h:lJM
"
vh:lJVlull.lJilVbb-Wnb11(i)ffitii(i)EJlJnultJ
,
Yl1\11'WfiI\J bbfil:':uen bnil1 bVlus bbviG'i\l Vln bn(i)'lJEJ\lnl'll '"I:lJm1Ufl'r\l bb ~(i) b'VIilm..m1'l~ li'l'lJU1U bvh,r'W u 'In 'VI~\I'illmrU'l:':lJlJn'"l:':bojJ1i1l''"I(i)'lIil-Jm'lYll1illV(i)UbEl\lJilU'Vl1\'\1mm'1J8\1(i)Ubf)\I
",
mS1UiJ1Ulluuajai
b.Q8\l'"l1 mLlJ'W1'11(i)TI J'W'Vlf'Wrn n"J~ il1i (i)~ln (i)l-J1n~ ~(i) LLfiI d :::-'lIVlt)tllllv'iTITvl ~Ii'l n ~11fiil1 U , , '1Jru:.:~ CPU bvi:IJfl11:IJb11:lJ1nnll \IIEl hJ 10 bvh1'W 3
li YI'l..i1Vf111:lJ~lil'l11'11~mb1il:::1lJ1i1iVl41nIi'lBn
~(i) bdEl bU~VlJ bYiVlJ nlJ1.l~m ru~ ~11u~'Wbt>l81bU(i) bbt'l:::1JJD~1 U~tl1'W'V\'"I::: ~f)~11nU DoS U'l:':b[l'Vldill-Jl~\)bbvi~iTmbln'1
1J
TI~
u~bl1mrU~(i)1il\l
nl'l
1~
bbvi
ci\l f,.JfiI b€iVYI1tJlt1i f}~ bI"l:lJl unn bnf}{ ~1:lJ1"Jfl11i bblJUWll (i)B'1JD\lbU(i) bl1n"r\l'VI:J..I(i)v1il i
"
"
ltJlal
"
11.l~ bU(i)bl{mlh'VIl-JltJ'luojJill-J~~U
"
llJ
bUt>lbl{niTn
'VIi'i1~"lI8\1bUt>l bl1nAmI1UltJI'l11l-J~:':(i)dn
bUt>lblinilnSl1mlilV:lJ1n~'l:,:vl1m'l(>l'l1~~DlJf1dl:J..161niliil\JYI~ilfll1:IJ
"
"
"
'1~
••
&'il~ltllll
Tep/IP
:J~'Vl'il1J ~d v'1h:h-iim.m~Tw
'QJ
fllln'iruvlntl
<:f ,
~1\l1J\l
"
~ bl1~l;!U'vil:lJ bU(i]b~Hn111l1:lJl'l
1-ihVlI'IUI'1'lJfl\l
(Amplification)
nl'ih:lJ~'·nni1~lv~~'W1f):lJ'1nUb~Vn'-h
DoS nUn1'ivll\llU'lJf)\l1tl'lbbn'l:lJl.h:;bilVlih1Vl'i~U
:ilnl'lll-r'IJ1l'l\l1Yii'J
111d bbn'l":lJih 1 V1d~U1tJVIl1!'l~H'1ti!1\l'1Yifl ~1 U iiUb(i]f)1 bU(i] YimnYi ffl'l l1'il1Yi'lJ f)\l1tl'l unru 1'Vl'i~U 1 bi1~l;!U~tl
11 fnYi"J:; h:lJ
'V:;vlln1'l
"
'"
"
~lmrUVl
n bl'1~fl\lih:;'Vhn1;fi\l
V b~:lJ111 ~lV
bbwn di(i]~lU1U:lJln
biJl'l,!:lJ1V'W1fl:lJ'1nU~ubluu!ili~TIbiJl'Vf:lJl
u wmn(i] bi1~Tdbbiil:;i1V~vll\llU ,
Ping Flood tTUbrN
DoS dli1'~'1JbU(i]bi1mb'IJu!ili~TIyj1<Ynnu~1~bbrii~ -u
nlsld~lunSUl81nsdu,
El~l\1.yjl~n ~111
U (i]f)U~U
m nm
v unn bn B1Ell"J"J:;
e-mail ~lU1U:lJ1n111u\lb:lJ~d11Yhlf){bViEl1Vib:lJ~b.i11.V.Jb1B{1-E\llUbdflYiuu
:::.
co:
m-E~lulumn rll ~\l b1J(i]i1ih biu b'W'II'lB~" Cllff:lJ:lJIi'il1 bi'IJ b1J{'i'Jblil1:ilii!i1 " "
bb~'bblJmnfl1vlln1;ff\liPll'lJEl
tl'i::;i1ihil
"
bli1{f'll:lJl'lblll'l::::lJ1SlN~
"
nf'l«\l\llU
1Ylb1J1'i'Jblil1Vhm'lffui11iifl~~'11fl~lu'iiil\lL'l'1lUl~
btJU1 u n1'l'IJ~nl'lVln"lIUI'l~lU
i-J~u dTVlfu
1(i]Yi
fll"i{?)l'l-J 1')~\l1'111~
DoS yj mJ-J:lJ1nur:l('ii~11tlbV;El'V:::f'll:lJ1'l(l-r'IJiJil1[1iil~1\l(ln~D\l ~ ~
Yir)m.~-iil-J tn n ~bti!nbtJU ~1l~1 btJUB ~11l ~\l rn Iildli11U e:JYi~ I'l'l:::1Yi'IJ~n l'l'IJU D1.HWI El1bU WI
"
1 : TCP/IP Security
.11
?ti
_'f. .
I
-
·~ .
.,
•
>
,
~.,-
.-.--1.:
-~-~~-~~------------
~
bbtil::bb'W?iPlllJ,1f\I'l'1lih'l DoS Nfilni:'::YllJbbfil:'::
~ n1tl1'W nli
• &V,t'iifll1J
replIP
S:UUnSlDDUn1SUnSn
.. ..
"
blJ'Un"i:;'U1'Unl"iI?l"id~~lJm"ilJn"inbbiil:;nl"inElnl'U~bi'ilil;ff'UlJ'UbI'11El'.lhmr'Ubfl.J ,,
EJ '1
riA B
~.J~'U Intrusion
nEllJtlil
1u,U~b i1'nl1tiliil.J~V
"
:ilo1ifl:l..liil~~\l~l'U ltl
'IJ
1lJil"i):::blJ'Ubi~~1~V1U Uiil:;n1"i'l'll\ll'U
Bbl-J~ bbiil:::5'U'1lJ~m"ib'VIt'i1t1'Yhl'14:il
-iJfl~1;'ln'UblJ'W<$l'Ul'\.J;j.,l1n b'1l'Wm".i1JjD~1'11iilv1
(broadcast), rrn
dJu 1tl EJ t!l\liil"l,h biill.JEJ iil Blil n iill1~ V~ Nt oii1aJ'VI"illJ Nt 1i~ li1 :;mlUl>J iil'lJD\l nl'l&fl l-J1)\l ~1'W ua WW~ bl'1-5W 'Yh~u b'l1'W'I:::1'h:il
'IJ
""
"
bl-J ~1'11;'l bBwil 'VI~El~ii Dl.Jiil~ blJU HTM L 1~~ iim.J1;'l~:il1lt!mn:I.J~v'U~btilil sr ~ L 'ifn~'U
1'14~~:::~Uil
1~~
V ~l'UbbElWW~bl'1-5'W~
..r~m".ib ~EJ.J~'W '11~tJ bQW1::: bbiil:;bbElW~~bl'li'W~'W '1n~ ::::ij~u bbuu1iEJ\jiil bilWl::: Nl'V1flJ 1'iinlJ ltl".ibbnJ:J.J 'lJD\l Vl'W bfl\l b 'Yh~'W W'Il"in.!l bbfiEl !1\l1~ t
"
ll-Jl bnU'VI1ElUl m
bUlilbi1'nih'Yllvhl1'W
n"i:::'U1'Unl"i&fliill".io/)
b'Yh~u 1aJ:i'hifl.J'VI1.J~'W~~:::&flff\lnulWi
bbiil:::n~m"il-J'VInfl~1\l~~:::bnli1;ffu~'UntliEJ.Jml"YvbuwHi1n ,
"
"
UaC1UlnF1 (Information)
-li~~UbVlRdJu-lim.J~Yhh:;m-J1'11'J.1':J.Jub'6~1:J.JTmflJ~Al1~'Vimtl'Il~\lN~iii\lHi1:IJ1T'V:;~til'\.!
'lJ 'i 'U 'lJ '3J
-lieJA11d-J 'llll1l'l'Hni'HA~
'U
n1'lru~u~~ub'6
~l~Tm
U~ b~Hmi\,Hll'l'l:;
"
""
bbi'l:;b~B~j'flJll~lt1'Vll-J 1(l;
~
flJ-li a d-Jl fi b~ nVi'l ~ilA ~ b'Vi 1,x'\.! bl~l n'V:; '111n 5llJ b-li1 Pin, :;lJ1'W nT'J bbllfl-Jn 5llJIII dJuon eJ~U L f iii VIA1 U
"
'"
iilitJMiliiliil'WbVl
~-.j 1'l1Bti1
'3J
su 1~ 1tiivnn 1:IJ1tiiflm1l1llLltJ
'U
U'lll bllJlJ~fln~fl']
'3J 'lJ
W1\l,xUolJil L au VlI'i~\l'V:; ~ Ehl fi fllJ rn :::lJ1U nTJ' u lliil-JieJd-J~ br;u.J r:J~'Vl1'V!iJ ~ uil iil-Ji D:J.Jiln 5llJ~l d'iu a '1.1 1 i :u
!iJ 'lJ
""
"
iai:ilubVlIi'f,x'Wn~flbbfl~~~bl'1iu
'lJ 'i1 "l.I
b'li'WlJil1b'1:ffl{~'Vl1'V!iJ1~bbll~-J-i1m;j~~flf-J~:J.J~-Jm~
"l.I
bn(;1'l1u 1(;1V H
1(;1V~iUbblJlJnl'lflJci
i'lifr oj{(un1iflJim'l''W
FTP
"
"
\I
"
"
"
nu[ii b'liU
HTTP
11'1~bflutoiY1bUUlJ'l11b'1:ft)'fnlJb-1H'V'J blflf SMTP, POP 1oj{(Wn1i'llJ bb~:;iii\l"V ' (;1'V!:J.J 11.18b~nVl,flill'1~'V1 n ~N \l$1U'Vl1-J iJ-J III m'lD-J"lI,mmtJlJUb1H'V'JL1flflll;'lltJVl1-J \~hflti1-J-i11\1$1UtJn'l1um~El bliuff\lL'IltJbvifl1'J.1'~..rn lll'l l\>ll'lfliil~Hi~lYiflJ~Eliill'lolJfl~~nU
" 'u
"
1'I11:'l'l:J.JTm~fl1:'l'l'ln'Wlt1i,:;w'll\l
fi-J
IIIv\lll
iill 1.1'1'11\1l'jtJ\I bb!iiolJEl bVI rlY1 b au Pi\lbU'WI'lU :;ll'l:; bllVlnu bvh,xu I;'l
~ \I ~1 ~ rvY1"l:;111'11 b ~U
n~a
n'l m,l-J~
1m:;~lJ
Ltl~bl{nJ'Wflrll1:W
n'ln'l:;~lJ
9
"
b'CiU CGI-Attack,
bbfl~~~ bl'l'lfU Pil'W1'IHlj JiEl\lfllAV bVI I'lil 1'l1U'l:;~lJVW(j] Lifn11:J.JJ11~ IDS lt1ihJtJln) b~'ll:::11fliilUb 'Vlrl,xu'V:;~n..rli\nl' blf.l:-;~li\~llbblJlJ 1(;1v(i'h
••
t~I~::llU
TCP/IP
FTP ,Tu 1aJ~3J1J"JrubbVl3Jb'VI~l,T'U1'flaJNl3JTH1'l111t11 oii\llulIlil1ai :vllJ'U ~ Nl'J-i1fl~'WL 'VI '1i'jEt'W\il'JltJ~lMil 1 1lilNU L'VI1'11Ii1tJ~1iTu
LeJ\lll~11:!-iNl3Jl'JLliil'\l ~iil1t1(OllUPll-Jbbiil~~\lnTH)tlmru1(i111'WbilIi1L
"
~(i1Jtl uuuvm
lt1i" l\i1 Plfl iilLbiil:': bfl'W'W~bl'l"J3''W L n til\l Lii3J\l1(i1 tin b1'W~1 blfll'j'W~ LPI"J3'Ubil\l:i'lilqJ'VI11dJ
'1.1
"
€llAv'iiBN(i1l'jiill(i1'l!fl\lbbBl'j'I~~bl'l"J3'W
(CGI-
Script 'VI1El ActiveX r-hU1J111b'llfl{!r'mlaJ'J:.:iT(i1i":,:1\l 1(i1u~11tJ IDS 'VddJl'14f111l-Jiil'W hlllfln'Vm'J:IJ~vlJ'W lt1bViElnl'Jfll-f1\l-i1Elff'W b'VI 1'1:IJ1 mIn
b'W'Jl::: \illlJViltll n ~11:IJ11 U \iInu tilu f\ il iiil~U b'VI1'1,T'W ~El\l ~ nu ni" emu v::: iilll-Jl'l"fib'iillvVdEl'VI11(l) tI'l:':l-Jl~VJ~N\I:lJl "
"
"
n nm.hnuoiim'luL'VIl'1laJN1:1J1'lf1
l(l)mmIn
rm Hinl~\lnl'J bLiil:::
tI'J:.:miil f11'W 'VIrult1 bvitll bPi'll :.:Yi-ii€l 'VIl'1llJ'lil'V:.: dJumi"\iI'1"l~Un11Umn~i'jtl1:':~'VIijm'V'l 1~ ffUb ,, 1(i1Unl'J\iI'J1"lffElU u 'V'l'VI l'iHU'1J€l,l'li€lff'Ub 'VI1'1'.h\il1\1nu~moJru:':Ult'f\!
1:!-iLn(i1t11:':11'J'lJU u Iii 'VI n'V:.:vh flU 'V1\l1 L'Jln Nl:IJ1'JfI \iI'J1"l~Unl'J'V'l tn I'Jl:IJfI\I-iiEl~'W b'Vl1'1~lJ\l11 f.llt1i 1 , ffU'VI1€1 ] l(i11)~11t1 bbG~h IDS h rum n l:JJlt1i€l€ln bLUUl-JlL~ a (;I"J1'Viil'flU'iifl:IJiil1'W~moJru:.:ti 'Wfl n''l1 n,TuiiEl~'W b'Vl1'1~~€lNljn'Wn:i'ltJi:lJ1 uae Pl11mi1 fl'\I rrn Hi IDS bYifl\il11 "l'l'111U'iiBl-Jiil'J~lKud"l
"
"
:':,),ll
lVitl'J:':~'VlBfI1'W'1Iil\!
IDS ~liil\l
1 'W'J:::#Iu bil\ilbl{n~u6?
1aJ1tll
Pll-J,ruil \Pll1:IJ~h
'I
1'I'W\l'll€l\l1t1'Jl\i1R€lSl ~-ii~11tl"l:':
'l:::lKUth.li'V:::dJ'W~~(i1nl'lffqJq)lruW'1n'QltlLnElU'VI:IJ(i1
"
b'l'J11:::niil1n'llEl\lnl'J~flt'fl'Jl 2 tI'J:':n1j~El
'W
'VIiJl~'1Ifl\liifl:IJSl~l'Wd"l:.::i:ifl~
RJUlJu5iJnJ:mssutl..,oaya
Liifl\l"llnnl'J~[)1iI1'J'V:::~eJ\l1-1iL'il\i1b l1m'l:IJnU #I\lJ'W~\lvh 1'14oJieJ:lJiillaJl1'V:::bU'I..Ifl1ubtlEl'VI1 ~
'lJ El\liifl fl''Wb us :':1f1'W'l!€I\l «ill...... 1 fl..lPl1U\Pl:IJn'V:.: 'Vl1'1 ill (liEl\innd\l'l1:IJ lt1lihvn'W II 'LI
Isu 1 Ult1j
Iilrieu
L~vnll
(header) bb~l~"]~\ldlU~bdfl'iifl:IJ~\ill:IJ
l(iltJ~11t1n1jbbu\lbbtJnj::;'VIll\l
thu
1'V1 ).j'V b :.::i'l1"l11:IJ 11f1.J'Vi 'VI1mn n:i'lR113J V111aJR\l~ nV:::i'jn11'J:':1i 1'Wb!]1'1 fli bfl\l11 M1 iTubEl\!i'j V bl'1
'I
"
nl'J~flt'fl'JoJifl:IJSl~\I'VI3J(i1flti
i.J
'iJ
n1'J~~hV111-i1El:IJiil
'iI
~"
'.~'
~
l!HlJ'-I1 €lUl\1
l~lH)
':U
l"llUflT73JlrI7'flfhJ1im.JCI
olfm.J~Vil!HlJ€l€ln'-Jl€l m:::~l?ln'l:::"Il~
""
~D'I11nN1lJ laJVlJ1lJ'hliD:J.J~~rrm.J
rJ7ti11J"llfl.J1ifJ3JCI 1 'WlJ1\1trn'Mrudim.J~Dl"1"1:::
'U 'iJ
"
~T1b'l'l1hn"l::: laJ~l'-Jl'HHlDI?l
1 mJ
b~fJ ll1~\I'I4'-JI?l~'-J1J".iru
"
'141mh ~lJ'II€l\l
lu~n'1
bt'lWD1 l~f)
'"
"
ul 'WWI?lbl?lD{b'I4~ld ~1:J.J1".i(1'11l
"
iil'W ltii"lln".il~fl:':lB~!il'IlD\lbb~fl:::1ll".i
11?lI'lDfllU'lJ'VI~Ellu
nlsSiJiJlulliilLlnsru1U1untjsnns:nlnlSaSliJlfUiJaEiliJla
UDn"lln"l:::1'l1lJrll.Jn1".i1lJi;1'-JolfEll-Jgl bbih olfDl-Jgl'lJl\1"ljijl?ll'WlJ1\llu, llil~Dfl U\liil"1:1.J1".i(1$\I\ll'W
, " -u
l~
b"Ii'Wnl".iff\llYil ".ilbI'!D{lU~~Ub~'W'vl1\lolfDl-Jfl,
"
nl'lI?l'l1"1ffDlJ~mu:::
'Ilf)\ll~~~u~l
~vn\l,
nl'i1il'i1"1 ssu
b~'W'VI1\1 l~'W'lJEl\lolfm.Jfl dJutli'W nTl$\I\ll'W1Jl\1DU1\1eJ1"1liiD\I n\l bbif11 iff,!!qJ1 rub Ylrll,rU bbf.l:;-oIlnl?lnm:J.J ~\I
:J.JlU~ ~UUUt'l\lnlJm'lvll\11'Wflun,cu1tiibVl ,
"l '1J ... ... 'I
f.hl b~nUD~
~l#lruv1"1:::~l 'l1b'I1UI'l CU~:J..IU~'IlD\lolfD'-J~lh:::bll'VIffru rulCU~1lJ~:J.JdfifJ iifl:J..I~JJltii dJ'W~\lVibb~n'Vlnn'W ll'!v~ub dJUbi'lV\I ~ \lv1 b~'W'Vl1\1ll'!vDll"1v Nfl n".i:::VllJ~flnU ti'lU1~1'l11:J..1~:.:wm olfeJl-J vi bllurh$\I ~
1 V!1il'l:::VI-wn11 bUI?lb~HnnlJ
"
bUvllifn
"
bb~:::olf J~:iJl"Ii m
"
1 YiolfD'-J~bl'l~EluVi1ul~bYhtT'W
"
"
"
"
U bUlil bifnJ'W'V::: bllu lull?l vfllill Ul1M 11?l u lu lu'i l1ilI'lEJ~ n'l'lIil€llJiil"UEJ\I b'l4rll.Q'V:::
ill'li b~1)\I uilanrn n1 u'lJru:::v1 N1ilti\l mJ'I4Ul ~m.JVJl bI'!Elf'IlD\I(7]'WbfJ\I 1115\11il bl'l~fl\l'Ilfl\ll'!'WbEJ\Ibillnl'! U~::; o/iD:J..I~ luflubVlfl1
"
""
I'lU,r'WilUl\1fl::: b~ ~!illl'!un1'iG'lbbnu~EJfl'!
"
"
1 U bl'l~EJ\I'IlfJ\lN1il ll'!uv1N1ilJJltiiflJ~fi\l~\I
"
"
Nl?llln &1 bG'lU bbifbb~1l ElV m 'ivi ".i:::UlJ~EJ:lJVJ1bVI {Iil au su iJ\I ~ill'i $ \Ill'! U~ N1il1aJla;11J~ti U bEJ\Ib1I'W~ \IVi a 1 vll1l1n 1'l b'Vl:':".i:::lJlJ'II D\Iu ~ n in EJ b'l4iiEJ'W fl'! unu&1 n 1 ".il-l 1 1 A'V'i'i6~l-J'W'M6un'11'Wil Ell'VVI~\l11Ji1~ v,h V
"lJ ~ q "I q '!.I
"
"
"
"
I.
'WEln"llnn1'l(7]fllJ~Ufl\l~ undnYliEJriEJn1'WLb~l
HI urm
ii1llJnvdD\ll
lildJ'W'liEJ\I'Vll\11'Wnl".i
'<1~~
TCP/IP
••
un,n~nvnJ'Vl,j\l
'l 9
~11'J
b'1iu:jh'l11;'1~UBci1 umJmru.fi\lffl:1Jl·H1~\I\ll'Will1n,nh
9..1 ~
mnnlTvi1l1,
~ .
dJwFI'W 'WEln"lln.Qv\lil
j;l:'::'liilt'l~\ll'lBUI'I'WB\lvlfl~l
b'Vl G'l1.Q
"
dJ'W1ifll'l'Wb'YlA) bb~:'::1:'l"lm1Cll1'l1111oii1r1d'il?llt1l~\l111:':: 11'J'lJubbj;l:':: 'Yl'jo} bb1lmnEl{ 1 (.fill b'Yl~rwI'11rrn u b'11 :::1:::UU1'W1:::~U bil(>1b:'Hn dIU 1 VI qI'l\lilll'i'rl'1.fEl\l'VI1\l 'Vl'Wl~'Vl~nvr'W~l'W'1JD\l IDS n l-Jbil'W£I'WWllJu ,n .fi\llBl'l'l1'J<ij1J ,dil unn 6nilftiidl'WddJ'WbI'l~B\ll.'h11'Wnl'ml:::':'::uu
u 'WlTW3-J'IlB\lnl1lJmn
1iEl~ fl~ b'lll-JEI\l b'l4'W 1$l1t'l1'J~h'W bbElV'lV'lbl'l.ff'WJ'W'J:'::&W1JEl~fl~~1J d\l n'W!?l1l-1U ~ n&i!;1 ~il\ll'll3-J n " "" lu"i 1(;11'1 1'l'VI l1'l::: rrrs b'I/'J'J1:::VIln ~ i'h'W 1(11G'll'W'Vlii\l'llil\l1J EI~ flJlHn t'l Nt'lV'lfll t'l 1:IJ bu'WltlIi11~ D ,n ~ 1l1'J LIi1I'1 Ifll:IJ11'J::; E bil'W~ bfl ru il ft\i1
bil'WiiD3-Jfl~f1n~D\ll1n~
"
"
bbvld'j'Wnfl1nm'l~1Jd\ln'WbEl\l'llfJ\llu'l
ii\lmdVll\ll'W~n'jo}ru:.::.;r,mfiTd
Ul'J::; ~n~il\l
b V'l'll
::;iiil1;jG'l1:JJ b~I'Jl1iil"r\1:JJUl"I ::;$iil-Jd"m 1r1~ -n1~'V'Jub11'W bbrolEl81"1W1 biil h1 'Wb~EI\I~'WMfJ nSlm"i~roI1\llU'Wb vhl1m 1\i1bn\i1~'W V\lilil::; 1 1~flmnml'J~bn~~'WU'Wb b'l11(iJ ~V1b'll bEl\l1:IJ'h"i1'\I bbii11,,:-;,j'\lil U(>1b~nYim -nb11'Wbb~::;~'lJ~ l ~\li'W lYir:rt 'ii1:JJ~'I4~ il(;1bl~nVl~iI:biim:'::~\I fl 1(iJI'J bQV'll:::1 'W
Ju ,ilUb ,,;j1'J\liiil'W~Clnrh'l1'WWl1'WbbB'l/'JV'lfll'Iiu111 ,
bbilll?l\lvlEl:rt-nbvhJ'W r
o nU'l::;nl1'Vl,j-J
"
iP111~11flill,tnw,hm
'l:::~U
~U(;1 ~i~mmI'JEl~
tJEI,:lfl'WWlllil\l"lnnl1~t'lr;1D"lnN0'W ~ 1~ b~~ Ail11'1'lEltJln<il::;d-J'iim.JflmVll 'l'1~iI-J'lIEl\l' ·nnI'l1l.J11n ~ '1111 1$i~'WVi1(iJI'J~bd1"r1~m~~\l1:IJ1t1l ~\I~b 11v1l1t1ln bbFlb~Bn11,,:::'I11iiil3-J(;1J'W 1111-E\ll'WVl1fJ 1:JJ Vlln l:IJlri~\l~ ~ D-J m'lnt'l1Dtl4i'-JltJ
'I'll fll11'l1~\lYi
~ EI\lfll1n'l111uH-Jl'W
bbvlEl81-JtJ ill'JYifflil~f)\I-ruiiil3-Jj;l
9 "
"
biil mrlEl'W bl'l~B u 'Yl'WYi,,::; ill13-J1'In biililfl1U bQV'lI:.::1i 3-JG'l~~ E)\I m'l bbG'l::: 8~ 1:JJ1Uii El~G'l~'WlV11:JJ~ D-J fll'l ~ 1~.fi\llbFl~ t'l8i1'Wdb ~tlll'llil b&iI'Jln I'Ilm'ln'l111u1 'ii1'Wrrn DoS bl'1~El\ll'lill-JVJlbli1il1"vi'11111t1l~uV1 Vllmtl1I'JU'l:::UU'Vl1DI'1f)l,l'vh 1:'l"ll.Jl'ln b1ili1Elfl1;limh\l b(;1fJ{'lIfJ\Ib'll bl'lilfl'Wlil'Wtl1'W nSl::; bil'Wtl1'WV11:IJilu'l::;(>1 Ylfll'1U 11 bU'Wb~l'l1il\lUl'W bl'li 'l:'::U'lJl1DD'&1fll'J use b,f)V'lV'l~'I'l.ffu 1 Ubl'l~il\l'llil\l,
",
bbG'ldiil~(;1~~€l1:'l"l"ill13-J11J'W bUI¥I l{nn"l:-; bil'WbVI.)jEl'WI'1'Wb~'Wn'W'Wvi'11ubiiDtl1U 1:IJi'ltJ"i::;(ii1Wj~il U b v ~ ~ 1il\l'Wilflill'.l1 n'J:':: b"ih~.J11'W1Jl'W blii'W b111m 1aili11 snln &1'~1'l1El\ltI1UJ'W:!1'i1tJ1Yi blii'Wd-JlI'1ElUI13-J'Yl b nau
9
"
_.
"--;"~'
.... ,~.,I:'.~
!
~
b~l'1JEhlii1u (ii.,jMmlJ~l']{~b
-- -
--
--
1a1) ii"l:::£)u&iLliaufubU'Wl:::l.nl!l1tJ"n~ru6(
Vl1alh1J'Jl!IltJ"iHruun"l:::1:iJG'lU'V1Ul~h1.J llJ11>"I U'!U"I::: dJu~u&i'V!1a lal&i Yl1a dJuN'Illmhvi~u~fJ1" .,::: V'ihlJl N~lhw ni?lllJ a ~1-Jhntilll-J L~l'lJa\liilU'YI~-J~.,::: 'YI~abLiir1d:::~-Jl~>"IuVl1alLlia-JnTman onrun 1tJnvhllJ1~
"
"
lal111~'J"::;
&aUbI1lJ'Yl n~~-J 1tl Ci\l bLii11.,::; d'ju~lJb~lJ"1~'W en 1.Jl:J.J boiilm.Jl UkJ.Jlflntil , 1~ 1.J 1'W 1 mu ~u a'W'W~ L~i'W~1 ViU~n1T'I::: n nil t) n uuu aJl bVi alJ~nl'i ~ "
'J::;u l~'J:::l\lf)::;
nl~-J
1 'J
1.JltJl~ 1ViD~m":lmh-JG'I~,
hn1lJi?lDlJtl~El1.J 1Vil"lDUI'11i?1aDLrlfl (Syn Flood), a-Jrl'W'YI~l1.J"1 uuusn 1Y1":l:::iTrJ"l:::1-J b~a\lAT1~11~t)()1i1u 'VI1nblnriElnlUmn"1"1'W llJ
bbDlJm'YIl b~1'lJD\liillJb YiDfllJ11b ~1'lJEl-Jiil'W uu&iLlit)UfDrl'WtJ":l::; bI1'Yl1 (Port Scann ing) dJ'Wliiu 'VI'W
" l;iIlm"JClfD~il1~n'il::;mJ~vll-Jl'W1'Wvit'l()1 , ,
b~l'lJa-Jiilu
"
'YI1m111tJU":l::;UDdJ'Ww;Jauiil'Wbb~1
LG'!~~'iI~~01.J~1'W.Q1Vibb'lJ-J b'J\lm n~'W l()11.J'VlltilldJ'WU1~~'ll'1'Wlru ~ b 1'Wnl"l1 'l"I'Jl:::Vlrl'W&-ilU boiilElDn1~ U , (iJ'\Iln~nl!llli::;'1JEl\lrl'W'!'W"1 us ::;~~n'Wfl~ n'i'J~'1Jil\l'V'll n 5'Wn'Wlt'l'VI~0'W1nri a mu LiJu mJ1 \I~ 'YI1n11"1":l
" " °1
jjl'lq~m"J~
El~1\11":l~E11tl,!'Wn tliil\I'W'ITillilfl nVl bb~a ~I\liJ El1.Jvi n btlU m":li] 0-Jn'Wil1.J~1\1'V1iJl G'llm":lblfD~ii\l G'!(iJ
"
IDS "::;lbfl":ll:::Vinl'JlJmn
"I
"I
'illn~nl!lru:::'Wbfll!lbbfl::;wq&in'l'WbVhJ''W
...
~\lmElmf'T'vi'il::;":lltJ-Jl'Wf;j~Wtill~
'I "I
1cii
fi\luiJ11
IDS '1:::~w;nmnl-Jl'itlaJlmVitJ\l1~nil1'libl'l~f)\I;Jmhb~'1":ltJvi'l:::G'lll-Jl'iCli?l'Jl'i1~Dm'ilJmn
"
,,
1~ClnM0-J~\lYll-J~
"
UEln"nn.Q
~\I"I:::t'llaJl"JCl';lbbumbfl:::~Al1l-J~\I~i?I"l1'i1~1J'I1n
nlSOrlUClUi)i)nunnulo
'iI~\I'1 bb~1n1":li bfl":l1:::Vlnl":l1Jn1nJ''W 'VI1nLiJ'W~,~Ul'lilqJ~:i:l1'l11l-J~>"I11aJ ,oii11'1~1'W bum i{n bbt'l::: 1tl":l1~I"I€H'HU'WtJ~l\1~n'il:::i'A'il:::11'1ai1~1J1l1AtJ 'Vllnl''J~~ Lrl~1l\l;JEl bVltJ\Ib~nuiltJ b'li1'!'W ~a 1-11brl~E1\1;J0 .iilJD'WVin-li1ll-Jf'1~\I'YIl-J~~~nl":l~Elt'lI'irl'WDUb
"
rep lIP
{fm~ru::.:~iblPl'Jl::.:Vi1lEl~fj~El'WVI{f\ll~1'Ilm'JfI'l::.:m::.:'Vhl~mllJV1
."
1lJ~"llJ'd
flU'Vil..:1V1 fl1'lvll\11'W~lJ~llJ'lJEl\l
IDS 'l:::l'VI~EllJnUrn'llllPl'l1::.:Vi~V1l1(;1VI"I'W
IDS J'W
vl1\11'W1(ilm)1'l1 'W11~bbf'l::':vll\11 'WEI (ilf'lEl(il If'l11lJjJ'VI~Vl ~\l1'Ill-!1'lfi ViElU1'I'Wf)\I E1~\I N (ill.ln ~lwr'J1Vl L Y b ~ 11
wh
nlSUiJ1URllUSUi)i)nlS)IRS1:ri ....
"IlflV11wrmhlm1l1\1MlJ rnd~tJ1'Il'loJ:imJ fl·1J'Yi"l:::1'l'l1"1~U~\lNI'l1.lfl~Ut'l:::LWnUtJ:::n"lflnj.JL'VI~1J'WElElfl'"l1fl 'W'lU ~ use LoJ:illv1 ~ LhUU'lIEI\lfl1d~El1'l1' bUWlJEI-J Un7!FlJr::nn--rnln1n (Intrusion lh:::nEl1Jnu
b 'VliPlUFI bf.l:::niill1l1 b
iJEll,;liilLbiil:::fll'l..j
fl1n
'W
'"
IDS 1111..J1drl'1l, EJ J UU\I bU1Jl1d:::'lJtJ,l'W nlbfldl:::Vlf'l\llJimfl 11 bUlJfl1d*~1 bu(;n'Hn uii1V1.r(;1 Ln'lJiJEll,;liil~l.l bb'lJUbmh.11lJ
1(ilEJ'VIlfl~'l1.Jbb1JlJWbi~md:l.J
""
bb'l1'll(il
nG'il1LnVl~lJ1lJ
IDS ni'lI~1dfl(il'l'lWulJ1fl'WVi
~ 'l'J
IDS l1'lilEllJil1QllJiPl11:IJ~
'Wnl1l
blPl'l1:::Virn'Jun1nlJiMl
'I "I 'lJ
d.&
"
iPlll:IJ~'Wt'll
'lJ
IDS lJi~hbG~:::ti1IDS
"l~\l'1nbb'VI'lJ'l:::1:JJllII:IJ1'lm~(il":j€l(il1ll1V(;II ~~11~~1J.1I,n~lnfll1N1J~'VIld'l:::UU~111.ll~tJ5n
"
i.11V1~utTnl blPld1:::Vi~~~l b~Elil IDS "l:::vl11 VillJJi€l\l'l1l-J'VIii1W:::1..:1'V1~-J 1'I1:I.JI'lrlVi'l1"l.r'lJ1Ji~IV'1nG:nl-J1'lfl(il'1'lW'lJ1$i1l¥1V bii€l\l Jiu lWitud::: coliJ'!1ij\lll1il:::uiic b1JIJ"lT:dJiwEI 1lI:l.J I'll'l IDS mh.'lii€lv
lW'lI:::fl1'l1Jfl'lfl~ , ,
<I
IDS n'1l1iJn~'Wfl'lil\l"1i€J:j.J~
lU(;IL1{fl'lJ€I-..1~offtll"1:nn1'liJD-..1n'Wfl1dUn1nDr!Lulh
'lJ 'I 'l
1l¥1v l'iilwfmfuf (firewall) EJr!I\11'lnl¥ll~ la1[(ilV 8l'11'WiJ~ 'V:::Ji EJ-JEJ1 Rvv:i~'lJ'Vll'ld:::1JU rll'VI'W(ilno
'lJ
5nl.l'l:::nWI'1~\I
'f1\lbbii"l:::ilfl1'l~\ln!lvib'VI:IJI:::1'I:IJ:Lmlnfll:I.J
bb~fl!l b'VIrhJlJ
rneurrm lJi ,,
Uiil::.:n1'J'Vl(;1 eu rm b'V 'l euu (Penetration Test) bVimU'Wfl1'llllfl'lJ'VII'W 'l:::'lJ'lJD fll"lf\l'VIi!\l s 1::: IDS fl"l:I.JI'lmi1vlJimn ~i1v1E~1\l'1 1(ilV~Vl~\I IDS ll'VI~-..111i'J{l€1~&" bbiil:::vlIfl1'l'VI(il~€I'lJb'lI:::'l:;U'lJ bb1il:::Vllflil UWmnfll(ilt',h'W
~
"
vlI1ViN'lJ~'VII'l'l:::'lJ'lJ~lm'lfll.l~utl'l\lnJllM(;InlJmn~'W
'iI q ~
'
.. . -~~.
,~,
,~ •• ~
-
~
:'.
• '.
:o:J "
-
•• ~.
i\',mii
~l\l'VIiil
IDS ~dhh:::1I'1'l1U~il'Uoill\ll.nn
lWnl"l"'lh1'1 1mmr:mJUfl£Jli1.r11'1
bbill:::nl"l"l~il'Ulll'1
blc;ifiiioilmfil'lilf.i'VIfl11'11.l"J:::n1'J~\l~~'1:::'l.h 11.l1o}1'1:::Liia\lli1'i:::'VIun 1i
"
"
nlsa:liJoAJ1UIOUibuUAAa ..
li1a\l"J1n
IDS ~~'Wl(i1'W'11nnl'l"'lhiim.Jfl~\l'VIJ.Jli1ii~mI1'inWn'vhnl'i1ll"l'i1:::'I1
L 'VIiih,r'W'1::: Lii il\l 1"l1al.JI"lWl-J ii\loil €Il-Jfllf 11 11~ii nl'i ~ mn, Nli1lln~'VI~a hi,r'Un'1:.:Lii~\le:l1'W'ii;l-Jfl~\l'VIl.Jli1~11'1 1J.i11-v:::dJ'UnlJv1il\lLl1J, ~a~l'io)fal.JliI ~h'Wl'W~l1{n 1tiHi1'W'Vll\l~ ~D\ln1'~'l'1~il1J
.."
~\loilm.Jfl
"
nlJli111'U'L'VIWli1o)fal.Jfl,nl,LL'lj'Vlfll'lfl'U,
"
"
"
1iliifh.
ih:J.J~ bbfl:::n~nJ'J:J.J~'U'1i1
"
IDS Lll~l'I1JLw~€I'WmJ~!Ii'l"J1'OJ
1'W'VIJ.!U1'WLLfl:::LViilnl"l"t1
!li'l'l'OJ~\l~a.,j'vhnlJ~nV1\111'1'«l'lYi'lJa\l'Vlnfl'U~a
"
I'll'VlJ~Y.WYiriiln1'W'lj11U1'U
""
"
~~11'1 LLc;i!li'Tn-v ~'Vh'VIii 1Yi~ n'W\ln'OJ "lJ :':~1"l11l.Jtt1J'lJihll"l'U '1'1au n "lI ~ ~ 'Vlnfl'WD1"J"J:::dj'WEl'W~'ll'1n'"hn1'i 1li1UN~1I'1rian1'Wfi d'J'W 1~
"
~\l,r'Un1JU1
dJ'U~VllJi11Jm1l.J 1111\1
hbLilI:::iiI"l11l.J11JNli1"IHl1JiI"\l1'U l
il~::HnHi,ru"J:; L
"
dJu
"
El'Uv1-v:.: 1J.iill:::l~ li1~'VlEd1'U1Jl"Il"lfl'lJa\l1"l'U~'U LbilI:::~ln b 11'Uoilfll.J ilI1li1 '1fi~:; Mil\llaJ bDli1lN1'I'ii .Jill L 'VI~"1,r'U m
"
LLri1J I"ll"lfl ~'U 1li1l'1rf11ll LL~lnl'J~li1~\I • all nJru~~ll.J1'ilJe:ll'U'iim.JilI'lJ '1 ~ 'iJ o)fi),Yhl.JElU~l.JJi'U'11'U'U 11'11J11'11n~11"l11l.J1.I ilItlli1tll'l LflUVlllihn ttn~ru:::t11'11nc;iDm".liJD\lnU
tl\l~~U1JUb 'iJ
~\I~dj'Uo)fmt\l
Ln~~Dnl'J-n''j:::'I'111 U
"
nlsoau[diio[uUo
IDS v1:i141'V1U Du1'UVltJ\I~Wlli1'1 :::i1li1'l'U'VIii\l~l r1' 'lilil"l:J.J1".lrlrl1'V1Uli1 11'1 n1J~h L '111...1 rnsa U1\l
'YIii\ltJU1\11li1Lda(;l,l'1l'l1Jn1'i1Jmn ~
"
N1
"
'I
ri\l¥l 1 «\l11.1 v\l1 'I'J{1 a ill ~ LviD41n ~ nl".l L oilltlil n'lJD\lo]J ill LLfl:;~ \l ~lffqjv1 ~li1ii\lm'V-v::: D~ l'Vlqj'YIwl\lc;im~l"lJa\ll~fifia n1,hl.J~n~1J1tJv\l~'U1i1LUli1"lJil\lnl'i~n1n
"
IDS 6~i:'lf)~'VIii\ln1J~li1ml15'11
i1r1'c;itlmn1JLL!:lmntl{bmJViLJil'll
" Ln€J{
Nli1LLilI':':1J1J1J1\llil'l'Um'V~Nnw:.:
LlIW1,r'U 1VhH'l11J 41 'V::: (ll1lJ~ 1'I11'11l.J:J.J1'iiil\l 1:': fin 1 u (;Il(f] a(;llV1u(f]DV1u l.lwali1tlumn-1iu LLfl:-:biitl11'V11nrl1'V1U~ lvin1".i
""
"
1 '1use
bilu'U 11'11Jll'1nl".l1n~1V'l11l.Jll
flilli1f(1'I bL1Jl.J
"
••
~~1::9W1J
rep/IP
"
•
+
bnV'l'll'Wbll'Wn1,umnbbf'l::: ,, h:IJM'Iln
IDS 'lIEl-.lb"nlv1tJVlldJ7b~~\lLV'I'1
n1'l~'hI'l11:::Virln&iEl-.lbb(9] LV1'J~'1IEl-.l~'W'VI1-.lbll'WbwV1bV'l,~tlf'lEll-J bb~V1 mru,1'1'l1n IDS 1dJij nf'l1n L'Wn1,G'lElU'VI1'WbbElV'l bV1,G'lYiijtl1:::~'Vlilm'V'l Ell"11:lJiillm'lrl
'11 El\lfi1,1"1:IJ MbbVi"l~\lJ'WdJ'W'vn'I'I'W usz
"
uunuue 1~11&i'W'VI1-.l
bb Vi"l~-.l bb~:::b'I'I!fJn1'Jru'l:::bf'll"htJ~-.l'll'W'I'Ilnm)V'I bl'1'JiilYiummmJ'Wbll'W'1Ifl-.l'l1'LiltJ-.ll'W 'VI1\ll'ldll-JJt'WI'l\l'l11fl'l'l'Li d 1'J\l1'W'VI1\l'VI'l11'l "1;'l:::b~ElJ'WNV'I bf'l,:::lJ1JEl1"1'1::: b (ll1:::'I11.Jn 11 1~ IDS Mlb~rJdm"l'l:::V11 1Vib'1l1MEl-.lb-lh ltl'WEl'WL'Wl'JnmntJA'W b'VIl'lill'ln1''Jtl!;'lEll-JbbElV'l bWl'J~ 5n1-lru:::dm<i'bll'Wn1,1h.dJil • nl'Jlbl'l'll
1:1 nif 'IJ
'IJ
""
IDS '1Iil\lb111tlh:lJMNil'W8n'VIil(i\'I'l'd\l1~bll'WEl~1\l~
"
V\lbbelmnEl{El~l-.l
El-.l(l1l:lJ~Mfl\lnT:i
bbG'l:::1:lJ bnVlNG'l1V11G'ltlWtJn~nn"l::: b
?'iml1,:::UlJ 1Vibb 'l-.lJt'WI'l-.l bf'l:::UG'lElVli1rJYiiilV1b ~-.lbb b vhJ'I.J tT'W?'iElUt'1u'l:::(lllhw 1Vibb 'Li'W(ll'1'llil'J1El~I\l 1W1mJ uae 1'11\lI'Wb'VhYi<Slbll'WNl'WNYim:::'V11NV'Ib'l'li;;hJwli'l1d'V:::u~EltJ 1VidJ'W 1tl(llll-Jnll'V1mmbPl::: n':::1J1'I.Jn11~~fj11:J.,J'V:::~Yi~t'1 b Wl1:::n11(llElU l~m,n':::vllvi
"
'"
~t'1nn'l1:IJlt1cifl[jlEvi~Wln[)'I'ImrJ"I:::
nlSliirlufiaWClWalCl
-1iEldEll"11dJ1'll-1im~uvidlf1ru'1lEl\ln111'11IDS 'VI5nmdl bI'l'n:cV!nTJUn"m'lJil\l ,, IDS 1cif~ mh\lVllcifn~11
'VI1nN1-ilill"nl:IJ.n'I.Jn11H-.lI'Wvi~'l/'jmbi"l:::dllh
'""
bb~":dh\l ~'WMilElI~"I
:cijfi~nnl.Jtlnffl
'VI~1rJil~I\lYi:iJ5n1-lru::: 1nfh~fJ-.l'VI~mJl-.lAf-.lb'VIjjElw'f1Jn1d'V'lml'Jl:IJUmn , nnrll'1'1'W(i\L'I4(ll11'V<11Jn'Vndl:lJU,::: bf1Vl~\lmhl 'I1'wlvi'll El-.ltl nl 11'111 :::ViYi'l :Cvllnl'&U f.l bflH~n'l:::
"
bb~l n"l :::ijn1db~i1'W L'WVI'WfiYil'ldl"l'V'lU bbfl:::bll'W nli'lf\l'VI.a\lll El~h\l h IDS ~~nril'V1'Wt'11Vi:iJ1i'l11:I.J bU'W 11
I , 1f\lbb'Li'WEl'Wl1'V11nDS 1~
'V'l'lfflnl1l.J\K\ln~11~(ll11"1'V'llJtf'Wbll'Wn111,!n1n'VI~Ell:lJ
iii 1:J.,J1'rl (lljl'1~U'I/'j'l&1mdJJY!~lrt\lJ'W
"
lWim n bll'WwbA1-I
IDS 1~~nril'11'WV11111 bdEllM1J Ping Packet "I1nbbDt'1bt'1d~b~:IJ&1W1(9]fl11'W bU'Wb l'I bi1'nY!H-.ll'W l(i1ull'lln,'J:::U1J U bbPl::::iJn1,'VIt'1ii1EllJn11Ping ila tI'1n
10 bb~nbn(llI11rJ1'W 30 1'W1V11Vib~mxi1bu'Wnl1V>1tJ1tJ1l-Jh:lJ&11(i1fJb'VII'1UA Ping Flood bll'WM'W rJ1"1"1:C'V11 IDS bMElUmJbb llJ(llPlEi(i11P111l'1U 1Vi 6 ldJ1Wiiln11lJmnY!bb Vi'V~\l "V ,,
2 : "at:U:UiJl~"l·r~iJfl1"a1,!fl1fl(Intrusion Detection System) •
",'
"..
..... _
"
:~
I~
-.
1.
'
"
.
______
'l.-:-~·'_.,
\,
rrn b~h)'ul(i)EJii1$'iiifl11umm~\ltT'U
"
mn
b~El'Ubb~11:JJiifl1,umn'l1\1 q q
UtJEJA1\1dh Al1l-Jlll
kbG'l:::b§:JEliiA'd1lJ'VW1EJ1l-J1I nln'V1-Jn'V:; q q
1:JJ1til1V1Y111lJf>i'U b vl1~A'd"i bl(1::;1:JJ1tii'Yl1Vl1-JiJEJ-Jn'Um.h-Jl 'YIm:::G'll-J ,r'U~E1 IDS '1:::mn mtJ'Ub~n b~EJ\I bln:;Yi blG'!1'Y1l-J1lJ1 b'ii1l-J1"11vn1:JJiim(i)1uVl\l
OJ
bG'!EJbl'ln1,ii b
"1:;1'1 lm:; u 1 (i) ,:; 1\1bbG'!:; e bn1J'YI~n~l'Ul'll\1 '1111'I1tT'U"I:;vh 1'I1~1Ji'VI1,j:::1J1J,j\l'UEl'U bl"l~vrl-r(i)1'Un1jll~u&1v1'Uf'I\I 'UEJn"llm1n1"ill~EJtJ dJ'Ufl1jUmn'Y1\1 'I 'I tJ1"1'1:::fivi'U'Ylci8'UEJ1'Unl1n1,Uflvn'U 1V1 IDS ijnldL~fl'U
1'1 Lbf'l:;Y1f'11W'l11l-J
IDS 1tii
1'U,:;#I1Jlln&iVil:JJii
bbf'l:;n1db~ eu N(i)'V'H;o!1(i1 Nffl-Jll'Ufl ci fl1'YVl1 'I1n1"i b~fl'UYi b1J'U'lIiJ\I'Y1vrlnnsu 1tl bLG'l:; 'iJ 'i..I
"
tnn ~ fl n1jiffv m ~ EJ ~l-Jl1 unn in iJ1Yil11'111l-J 'l1l-Jljbi'Y:::v1v1fl\llEl EJ'lJfl\l su ,mn ~1 G m , iI1"1"1:::iiLVlEJ\I 2-31iJ\lj8EJbvl1tT'UYi ll'Ublln1Jn1"i(i1"il'1~1J~'U1EimrlJ~'U
11bVl1J\ll~nUiJ EJ
'IJ
IDS G'llm,rlt'llww1J1tii
~m.jmflmaff\l~'Y:;nnl-JiJ\lbf'ltJ
'IJ
'YI1n1fl\l'iJEJb'Yl~Td'bin'1111tlNal-J 1tl1(i1EJJiim(i11'11Al1l-Jfl'Uh h
'IJ
OJ
IDS btJ'UbA~fl\lii
,-rfll~lAl1l-Jtl
(Proactive) al l-J1, J;I'VI1 NlfIbbf'l,:::lJmn l-J1jrlUf)\lll'U.!lEJ rI n rl1~ 1Ji~1\l'VIih rifl'U Yirrrsu q mn'Y::: bnli) 1V1
~'U 'l1~flriiJ'UYifl111Jmn'Y:::nj:::'1h1Jid1b~'V , q 'l.wn,nnd
IDS tJ\lfllmlrl'1ilEJ1'Ufl1,bn1J'YIffn"l1'UVll\1
..
iJ b~nVllElilri
tf'lliJ\ln1,lJ
LI'111:;'I1LLf'I:;~1I~'UNn':::vll1til1
q "
J11EJ'VIff\lbbl'l~\ld
v
IDS iil'li:I"]~f)\lijm)(i)1'UJT&1YiiNll-Jl'b1~lJfl1"i1Jmn1~m.h\lbinwiJ\I
1;0
'U
btlfl1L'llU())
'"
U1;'1 :::~fl\l'i'l'Vl1ru1l'l
"iJ ~
I'll btJ'UN(il us
"
lru ue ~l1rllll-JflJ
b,:;jmtJ'U nl'lU
f) \I ll'U ii1 "11 IDS n n'1111tl1 -li1'UVl1\1Yi N (i)bbf'l::: 1\1 lil11 EJM Arl f'I~'U £N nu
'I.J
l-J1nnl1"1:::1~'Unl1UiJ\ln'U"i:::UU~B~(i1'UbiJ\I
• t'i/1~ItIJll
replIP
1960 1~fJ:i11~l(1tl".i~iii\l~
,
1 Viiiil:!-Jl".itl1-1l'~mll".i~l
n~u'Vll\l,jhl-J
us :::ffl:!-Jl".i(1'V11 b~U'Il1\l~'ii:::
~\l
Nl'u:1ifl~ f;'l1tl1Viri\ltlf;'llrJ'Vll\1~U
~U1'W'1i'NlJ
~ bR~lojjD\ln1JiiubtllD{b
bb(;'l:::vr"uvilJ
~'W bb(;jmh\lhnMll-Jltl".ilMiP1Bf;'l.Qnv\lfl\l:i1'ii(>]1Jn'V>l~fl..:liim..J1nl-Jl~
:w1~:i1f.J(;'lm~'Vlm'Wbb '1..:1vb1'111 n 1 'Wl-J-Jl-JEJ\l'lJ \ll1n A m.J'vh bMDf[~ uYfl1tl b D , ,l D'W'Vld\lEJl'Wl11'V>1'lJD\l1J'l'1(>]lb'VI6'l1unn bnDf~"'VIfll , N~U lMtJbQ~l:::m'l1'Vl-J~bb1J1J uYi'VI~UU 1 v'il f)1J n~1f)" DDS JU~IUbbM1'ii'iifl1Jn'V>l~tl"'lJB" n&l~'l'hlUYfl1tlDl"l
1 ~J,J~
"
TCP/IP bb'V11J~"~'W
~Dmjt'll:!-Jtl
bfN1~ #I"J'WN..:IYim41
bU'W~B\I~nl!lll"ll1Jl'inu~ 1tln1Jlfjn~'l1'ii"1'W
h b.QD'VI1Yi:i1f111J.Ji1J'iiDU 1 umu'VI5..:11(if
,
--
._.
•~ ---
~~
.e~~ -------_--
"'..,.-'rll
.~",
.II.'
------
---------
hmlvi~:::Jl':111'V:::yh
-7i\l hUl1'W'lllJbb~h
"
zliff
Application
3.1 Transport
TCPI/P Layer
Network
Link
tl'runl1rul
.". .....
'l'Jiil1
'Vu(i,ml'l
bbtl1.'l1'l11:J..1'Vln".i:::(i'j'1.I tl'runnru
~ ~
2 3
Net~ork
tlmtJ'Vll-l1tld1AI'lE!~d::;(i'j'1Jd Transport
'Ill ltlHi\llUM
'iJ
E! mtl".i1A\PlEl1.'l~~Vl ul u D
'iJ
Application
q
1U b'W'V
'l::;Vlll\11J'Jl1 b"ljEJ{ bfl::-11.1 b b dHvJ b lEl1 POP (Post Office Protocol) 1oEG1WrUM11U1VI~Vlfibl-J~'VlmlJ~ b 'B{'II'l n fl1 ml1.yhl'l~fl\l b:J..I5LI'lflbElU(ii (PC) "lIEl\l~ii
"
I.
'''11~t1J1J
TCPliP
TCP
d
,;u
d"
UDP
1'x
"
"1
Ith IVll'lill."lTCP/IP
nil'W'Vl'il:::I'ill::"flnt:l'l'.l1~i:1::lil ~Vl U
,d..
..
...
1Ij;j:;;UDP'V'ltlft'lI'YJ1HI'ld
rep
IlJ'Wlu'.llVll'ltl"fl~~lJU'.l::tl'Wf11'.l~lJ-ci.:j'lj'il:IJj;j'.l:::'Yrh:J ~u v'W';hil~ il:IJ'fl'il1 n ~Ui'll'l'il hH1Yl mh1l9illU'i IVll'lil"flilfll."l1n1ufmVl'.l1'il'iJtllJ ftqjtyltll VltllJ~u:h~il:IJ Ill."I:: i:1tl'l
elil ~'lum
~IYi'Wlll."l:::'hiil1Y'1':i:J..J1u'li'loij'W1~ IVl'n:::1ufll'.l1l1'llU'YJil'll'lil:J..J'i'l1IVlili
vhmle:il'WI'l'l'il::'Vl':illJlI-a111~m.Jl."I
Vjflllh5 nEl'.l-a1uiifl11:J..Jth~
W11'1l ml'.ll~ fJ1 ~mvh 1'111U'iUm:J..Jlll'11'WN~Vl !;1l~~'l'11:J..J M~'WVi ~'l'!'W!! ilVlVli!j!1'l-E'U~':)'IIl'illJY'l11:J..J ~ f.\j'l'W ~ al ~ Vld IlJ'We ~1'! ~~'l'l1um Iftil fl'lil'l.h I~ I'l~Hl
1'1'11 IVitmfl'W
1'Wfll'.l~il1;n'.ltlu
rcr
IlJu~l'Wd'Wm
n ihen
Iih IVll'ltl"fl
UDP
'l'W'lJtll:;;~
"
IP t'li:'1l:J..Jl'it:l~ml.:J~tl:J..J"fl'lu1~'Vln~1'W ll:lflnlmtl1JlaiiilUl~il~liliin
"
lll:l:::1'i1Iil.:J~M liY'Wq'lll~!Vl'lf'lJil'll;]llt9tl~~i1fllJ'W
res
iim'i~uci'l~m;!j;j'l~ilUl.:J\lfl~il'lVjf1ilVl
"
UvlVjnilUl'1'l'Wh1fld'll-ll1il:;;1'l'l~mm
v
~'l~ TCP
~tl'l
IIj;jn'hJtllJ f1l'i~lJU'.l:;;fl'W~il:J..Jl:l~tl
Ian
'l'Wfl1'i~i1 il'll'l il tIVlillJ~lJ fl'WVj I'lt'l'l'l1 'll1U'.l:: ft'VlTIi11Vl;1~ l:l.:J'bJ 1'I.J'ilVll'lil n i al:J..Jl'it:l~1J!;i'l~B:J..J"fl'.l::"d1'l1~{1Vl1~ 1'lI'Wnu !!Vl1l-liifll'i~lJU'i:;;n'Wfll'.l~lJ
\I
vll f.\jmtl
'lJ 'I
~ il
~~l l'UUfll 'iVl'i1'il"iJillJ V'WVUn'Wlil'! '111n ~ tl'lf11'iVl'i1'il asu n'll1~lJ ft'lii tll.J i;1EJUUUrvi:J..J 1~:J..J~ IlJw'lIud
11ii lIilWwilll'l&UlJ1,nJ'i::
iiil:J..Ji;1 MtlUl'lii'I.J'i:::ilVllimwn
"
"
!'I'.IJ1:;; -ft'l
"
"
TCP/IP
t1'i::nDlJ~h
Ib(;ildj'YIi.hVibbMn~l\1nUilDn
1t1 mwVi
rc= .
UDP:
baOtl'.l1l1'Vlllfl::b11iloil1t1( D~1 'Wmlufltl ~ r1U1I~1aJl:in il~(il b(;il b!.Jil{ Yll'YIihVi~(flnl"Jbb(;il:: 1'l11JI'l:l.Jtn'i1'u ii!\lTIil:l.Jl I'liu I~tll f ,~
sln nl'.l1'uii!\lf]l:i
u 'IIlU
"'~~ .•
,~ ---~-~~-
'~
~~~:'!
--
---
--
---
tuft
3.2
Application
!flw'llf'll'iJ.,'J
fur (lJIflflfWh.,'Ji
hJ'ij(jJ TCPI/P
Suite
Transport
Network
Link
Media IP
mjh!bUl'H11m~lbEJi)'f
"
dj'W11.h1l'lAfl~'I'l~n1'Wnl'J~mnJ'.iim.JG'I
"
~,JnG'l1mhAru~
'Vh1Vi'.iifll;jmnmJmA~f)'wVi1tJir..J1.Jlill~V11..J1[i\MflhJJ1l'lfW~
IP ii'bfl..J
ICMP
vll'1'lUl~b&~:J.J
"
1l'l~"I:.;djlJ 1tJ'J1l'lI'1El~~Aiw1ii'l'1jT.lfll';lbL1Il::bb~..J
ICMP ~hm'1l'Wn'W
IGMP:
Protocol) fl~1lJLUIilL1{mG'lLVfl{
"
VhYlUl~lJ
ARP :
IP 1VidJWbbElIl1LVI,fI'lJEhlNetwork Interface
RARP:
"
IP
Internet Add.ress
'VI njiu bl'W; L 'V'J'll~1?i tiuu BlJ bl'lD{L Ul'l'\l :,;M€I-Jl1'1'l:J.JlL1Il'll1l'J:';q}1P11~€I1oift lJn1d~flfll' El€l b
"
IP Address 1V1~ril
IP Address ;1"l::dJlJ
~..Jbbl?i bb1ll::rr'W
bbl?ibb'Vl'W~'V:.;ri'lY1lJVl1Vibfol'lJ~..:J 1l1'Il!lJb1nu'lJl?imiifl..:JnlJhJ 32
"
8 U(ilq}l'Wl'W 4
'IJfI
'Ufln"l'ln.alw
IP Address tTwJ\lr1nuu-.5f)f)ndJ'U
"
2 a'J'U~fl
a'J'U~dJ"Hbfl\i1b\i1'H1'llf)\I
"
"
"
"
IP Address ~'l\l'1
W1\1tT'U~\lijnTl~\i1 IP IP
tUYI 3.3
Class A
netid 14 bits
hosnd
16 bits hostid
rnnivuu«
Ufll1i!Mg<I~1UflJ flfllg<l(fh~7 Class C 1 Class B 1
I I
I I
0
netid
I
8 bits hostid
21 bits 1
I
o
netid 28 bits
Class D
1 11
11
Class
I1I1I
Class
A B C D E
Range
0.0.0.0 - 127.255.255.255 128.0.0.0 - 191.255.255.255 192.0.0.0-223.255.255.255 224.0.0.0.0 240.0.0.0 - 239.255.255.255 - 255.255.255.255
"
bblJrm~:::'Yl';l'lUl11lf):lJ1il~Ml).JmtT'U~5m~ru:::flUl\11
"
"
"
L!'l\i1 \i1lfllJ Lf
'l.Ifl\l1lJ111?lI'lfl~iii'JU 1'Vlqj'l:::lJl::: nflUM'J tJllm;jt'l'Vl5n~ii'l~qj'l.lfl\l :lJlf1fl bLf)I'lL\i1"j/il'MUV1'l\l, bbfl\i1bl'l"jfflJ~'ltJ'Vl'l\l, 1'l'J'llJtJTlllfl:IJiIl, 11\1~\I~"I::: ~ EJ\lbU'ULif bl1'U'11\i1 Mfl "I:::~iiil~t'lii'lr1qj
"
'''I:::1M~\i1n111MflEjl\1ClnMfl\l
"
bU1In:::1lJ"j 1I?lAf)~~'l'ilrn1
"
Encapsulate l-i'l
"
{~~~
.
_-_-~-
.~
~
1tHflb!Jfl1'lJB-J Ethernet "I~llJ~~n
v
_-
-----~
User Data
tINt 3.5
tns Encapsulation
a-
User data
ITep header
..,.._ -
data -
J
--flo'
liP
header
JrcP
headerl
Application dab;! -
J
.....:
.+--- - -
IP datagram
j.--- - - - - - 1 U nl11ml-J'if
"
Ethernet
Frame
----"1
Ethernet
2 sll'WfifJ
'ifil:i.Ji1l'i11-l 1J"iifl:i.Ji1l'lJfl-l n lu",i1l?1l'lilfil bU~!J1J b~Sl il'Wn1"Ja\i'i1I'lYlJ.l1 !Jll\i"l:':: Wi fl\ltl"i:':: nil1J!iil!J b.Q€l1'l11:i.J 1'W "lI?IYI:i.Jl!J bi1l b ~'IJ'fl-J"lI?I1'I:i.Jl!J~b.]!JU ~il b€l-Jb'IN"JldJ.J1'11 b'Jl"'1~a\lli111'l"J
'iJ
"
"
V
'lJ
n1"J Encapsulate nAfln1'Jb€ll'i1(;]'YlJ.l1!J:!.J1 1d'1l€l-J,rUbfl-J l\i1!J"lIfJ-J 11?1f1fJt'nr'W 1 1tl"i 1I'lfl€li1lih:.:: 1ci 1 '1l1l-l rJl Encapsulate
biilb!Jfl1 .)lUl'W'1lfJ\I
..
n"'l:.::nn 1cibvil-.JYlfill!Jiul'llmhv11Jnld
'iJ 'iJ 'U
,rWll-l
1d'1lll\l1?11'-Jci'1v1UJi'..:Id
rcr
ci'1Ji'1J~ 2. '1l1l-l IP ci'lJi'uVl 3. 1m-l Ethernet bbfil:,::Nl!J~f1J'ifrmfiln"l:;tilil-lbbn:;:'lJ'fJ-lflfJnI?11:i.JrllJi'1J OJ '1:'::b'lil'lfil-l IP bbn:'::'IJil-l IP <'):;b"lfl'lfEl\l rrn ~l~lnl'J Segment l\i1!JMfJ-Jun:'::'lJ'fJ-J Ethernet rinu bb~l
rc=
"
Encapsulate b1!J1J1fl!J
(1a'1lfl-JlJC'lNi1n)
bb~1"11n
rc=
d-J11.lu-J
IP b1!Jnl1
TCP
"
IP Header ~-l1tl
I.
"'I:;b1!Jnl1
~~1~g,1111
Ethernet Frame
rep liP
'V1mtlOJ::: b'I4'Wl1lJ1\1l"lf\lllm.Jfl ~"lli1€l t.ib'WU\I ~1l'Il€l U u~nl1v1 b 1~'V::: i1l1€ll.J;'1J €l\l b!l~ b~€l{'1J€l\lltl,i:vH'HJ
blTv:::ci\lllmJ
flltlfi\ltlfl1uYl1\1 ~'11~1''lJ
'1J €l\l'1J1qjv1 ml €l\11'VIq,ivi€l'VIfll tI'l3\.J ~b~'W€l~i1~1 tl 111\11'W€ll'V'V:::i1bVl tI\ltJB I'Iln ~~ (i) u Yl\l~~ til btiwllu fl 1i\l fhuu 1tl1~ 1J1\1I'l{\l010J'V:::~ ~U ~tl~€l\l U~ n1'v1~
"
"
B\l1fl''lifl\l'VIfll uiu
b'l1 ~'Wbtl ~i1\11tlMii bbUU~11?l5~ b,1 iI1 'V H\l1'W 1~13J b~J.Jtl"l:::f{'VIBm'WbYl1~l'll'
bb~1'l11J.Jb~'~bd11?l1,'W1'V1flI?l1vJ~fi\l1Jifl"\lfl"Vl~lnl1,r'W~.nn
", "
"
"
tUVl 3.6
rns
Demultiplex
1f'iJ'JfI#Mfw,n
ConnEthernet frame
demultiplexing
lGlO~'lnll~11hlVlA~"
tu IP header
<)
1'Wvh-l1i1Yi~,h'Wm1~mlTlfi\ln1' VElt.J'VIir\l'1JD\ln1' Encapsulation Encapsulation ltlbb~l tr'Wbfl\l YI1nn':::1J1t.Jn1'l 'liEl\lVifl:::i'W(Y11lJbflb!JEJ1'Yi fl'\lltl 111, Demultiplexing
Demultiplexing
~Elnd:::1J1t.Jm'l
Encapsulation
tlfiEln1,1'mm\lllfll.Jfl~i1\9i
ilwlll'l
IV
b~D'Vhm,un:::i1i1nVifl:::.gU(Y11J.J
J{ Q,.."j
tv
"
.:4
,r'Wbb~lil:::bi.'l lJiI{'V:::thllflJ.J1.'lm'l'lJ.Jnu b
b'li'W 1 bvJ'l'J.J1u1:::.;rU Ethernet, 1 Datagram 1u'l':::.;rlJ IP Lbfl::: 1 Segment 1Ud:::.;rlJ TCP 1'iJbb~1.'l::: mUfl1n'V:::vhn1'l'f1ElVl b rm
'l.
"
1 YlrldlJ(Y11lJ'1Jt.J1\9iYitiiil\ln1'l
bbfl:::
bbfl:::b!l\9ibVlEl1r;]m1ElI'lDDn ltJ'VIlJl?l
-\1
"
~. ,~
"";i'
~.•. ~-~~--Ol', -~ ':'1:1: ...
.
---
~ ~--
rrn
DtJn-.mr~'\I:::&mnnJ'w
Oemultiplexing l£t''U(;lfl'U~1'1J1imJiiI'\Iln
Encapsulate l£tU(;ltlU~'l:::l'hn1'~\l1im.Jiilmn'U'VlnbmrJfl1'1Itl.JLtJ,1(;lfltl1il
"
"'
"
b'l1'U 1Jil11iflJ.Jt'l~\lluJ\>1'l'ln'1b
"' 9
h 1 'UA'l1:IJL1Ju
"iI
biJ\lniimjlJ1n~iibbtl'V'J'V'J~
n-h
1 lbtl'V'J'V'J~ll'liu~vl1.JlumjmrJ
1'W
bl'1~iJ\lb~Uln'W
b'lf'Wl'Wb0J3{'VhliJ1bl"J~iJ\lb~VliJ1'\1'l:::blJ'U0'\I
TCP/IP ~'lfiJ'Utl~lfi1V~bl1ilTi,)1~'Vll11J
nbl1J1J lViii
'YIJ.JllJbiil'llVW1t'lfnJ1'WWfilbfilfl1 lVifll:::1Jl1'1iilJ.Jiilb'1:Jn blJ'UL'1ihu'W'lltl.JbbiJ'V'JWi'ibl'li'WiJ:::1, 1'U1~flL'1tT'U u iJ'V'J'V'J i;)bl"liu bbl'it'l:::!fl1~1 Vi1J1n1 ,iJ u1 'Ull"l~ fl.,j I'i 1\1 'I:::i'YI:IJ1Ul1:il'llV'J 1 (;llh:::~1!fl1 i ' iJ l~tlm.h1im.Jiilm lnl'l'Sl'U HTIP 1Jillrl
"
'"'
"
Hill
"
'V'Jfl11'l 20,21
"
"
1(;1rJvf',1t1'11l.1 Ubfl'lJ'V'Jfl1\?1'1 1 :::i:ifll1lJ ~lf1qJ r'f1J~\I'lJtl\ll0J31vJb1 iJ1 lvhtTu ~\I bofi{vJb, El1'\1:::Ji D\lI"JDlJ'JEl1'1Jm,~ bl"ll W~ (Req uest) 'I11tl'IJElt1J1J~m''V1
1'11:JJ'l'\nl'lt\l~iln1'Jt1Jri.,j1iiJl.I1:iIL'ljl'liu
9 "
(session) l'11lJ
Reserved Port
1 u,:::1J1JtJiJ1J~m, Unix iim,iiI'\I,'U'V'JEl11i11Jl\1m,U 1-10231M 111 Vi~1'1111J1 'V'Jdl'lj1il'~:lJfl'V&vhf!,!oj'lliJ\I bl~~h'Yl''r1J Windows NT :n1aiiil,11'W11 Super user L'VhJ.\.!~1'I1:J.Jl'blH'V'JiJ1Iill'W'lil\1
LL(l]ilUl\11fil1'W1Jl\1l'1t\l'l11n'Yh'UNEil'W'V'J1Jl'1l11 Unix Reserved Port n1Vib1il1'\11Jil1'11lJ1UD.,j'V'JiJ1(;l ~ 1 ~1023 UULiJ\I 0'\1 TCP Lbfl::: UDP (l]1.,jn11i\llU'V'JiJ1\?11'Utrnl!lru::: L~Vlr'fU~El H,:::1J ,Lltl'V'JW~Ll"liu 'YImmf'l'll VJD'~(;l~l'Il:IJ1,b1d:::1J 1M'I::: b~'WoJiEllJt'l'IJUlfil 16
1i\llU 1M~\l~U =
"
Ulil
65535
'V'JiJ1(iilUU(l]fl:::1tJ,1(iil'liJfl
brl~D\lb'n1aib~ilH1t1'L(;lADt'l
64 K llfl:':'1J£J\I UDP
I.
fln 64 K fi1'11f1Jn1,rl1'Y1'Ufil'V'JiJ1fillYiiJ1i1'Un1'Jt1Jt'I.,j1iiJl.Ifl'l:::mhlfi.,jiJU1\1ii1~lflUfil1U1J'l'\(l]D1t1
'''I1~W1J
Tep/IP
"
IP • • Internet Proto
1'Wfl1'l'l.hl1eJ~f11t1N'>ltr-J'l(j1V1mv1.Jf11V'VI1-J
'"
llJl1~1(j1'1
IP di1nlil1fl~I'IE1'W'1h.,jQf11\?11'WnT~Vllb~'W'VI1-J'lJ'WN\l~m.Jf1
q "lJ
bi'lbVil{iil-J'll'Wl1J bi'lVhi~El-J ;u
"
'lJElbVltJ-Jbbl'lb(il~v:l.JolJmJf'll Vibiil~'liil'l'l'II'JbbtiilN"]
dJu 11J, l(l1rlElIiI~ unreliable "1iI:-; connection less (b1J~VlJbiiliiil'Wbllu'l:::lJ1J'1J'WIiI'\I~ilUlqJ'll(l1b'h bbMllJ1'lJ1.J'l:.::n'Wl1oJjfl~(;'l'l:-;ff\l1.JlillU'VIl-JVl1il1aJ) b(;'lbUfl{~u~Hi IP dJ'W~lN\liim.jlil-;Jl
'IJ
fll'l~
IP iloJjE1~flV 2 JJ'l:-:fll'ld
dJ'W$iEl-JVlIVl'W'VI1-J1unl,t'l(l1iiEltl\iw
bVl~ldlil\l11J
1'lJ N\l'iJil~f1 ii biil~ mJll'II'J bbf1:-: ~ilfifl1$i b ,x'W btl\! fll'lN\liiEl:l.J1;'l $ilV
"
IP bU1U'lJ biiliiEl'Wfl11g\l'lWlVl:l.J1Uvi'111J~
biil:l.JE1
Am.h'i1(l1V1:l.Jlv~ilEl~g\l11J(l1l:l.J'liEl-J'VI1\1 hJ"V'Wf.1\11J1;'llU'VI1\l iil:l.JEll(l1v 1 t!'lY'UiilWlVllV'lJ'lH1u'llolruiin'i1:-: b 'I11'i1(l1VlmV 1U~th'Ubfl'1l~(ill:l.J":IVlth'lifl-J ~lVfl11'1'11\l1'W1.JnWi"l(;lVl:l.Jlvtil'iJ:-:ri\ljJfllV'VI1-J U ii11VVlI-J bllu1u1a; bbGhlVl~il'Wf1\l1u1 UJi1'lJ'l(l1Vl:l.J11J'lJil-.l tHu 'it-J'l::: b~'Wll
"
"
~1u'V(l1V1:l.JlVnbiJ'W1$1 'l\?1t'hflqJYivn~lfl~1-Jfll'lN\I'i)!?1V1mVbtl~V'lJb'V\V'lJn'lJfll11'if[t1'llMl"1eJiiI
"
NN..]1lJfll'J'VI1I'lJ~Hn'W:-;
"
fll'lN
\I TIEl\ll'lU
~UV'W(l18'lJn~'lJ'lln
IP 11n-J'I'I~fl1aJn\ltliillVVll\1
(1-Jbbiil11t'lVN1'W1mlJ
buhl1m,-j1;'l'i):-:N\ln\lJJfllVVll\1 mh\l1lJi1
d:J 1'I'I:l.J1EJ
iholJm.)!;'l ~
n\ltl !;'llV'IIl1\1n'il:-:1~~Dal1n'W(;i
D fil Pi-J aJ n\ln'V:-: 1tlrttl'l'11fl ~l-J ~'W $ifl\l1fl Nl'1'11'lJWlll-J'I'I:l.J1 V'l1\1 '1 1 1lJ
.d ,
. ili." .
,
..
.. --t"".• ~
,
"
~ .
-,. ~ l .)0. : • '" ~ •
,.'{ ,
-~ .,:~-.~
."
"':.,
,.
-
4..~'
~ --
- ----
'.
',.-"
-,
~~~
; ..
·;Fd
~
- --
..~
_..
--
---
Unreliable
~lVtl11ltl"jll'lI'lEliil
IP LIJ\!l'Jnf'lln 1'Un1"jvnL~'U'Vll\H~'U'lJEI\!-nm.Jf'l
1'Ufl1"jci\!-nmm
'IJ
1tlfi\!tlf'llV'Vl1\!
1","l\! 1~ LLM1~iinl'~l'ld'1"lfHl1.r,h
"
(routing) 1tlU\!tliil1V'Vl1\!
"
.i)i\lB1'V'V::;fi\!
'IJ
i11~ ~\!J''U'Yn
"
n d\!~l
V IP LL~11a.iiifl1"jl'lElun
iil1i.J
tlf>lltJ'Vll.JlJ~l\!fl'J.!lJ"jru
"
Connedionless
'V\~ltJfi\! n1"j~~all1flil\!
IP 'V::;~iiam'U::;b l
'YIiiEl'Unl"j L~€l~MlJn'U"j::;'YI11.J~'U'Vl1.Jn1Jtlf>llV'Vl1\!
1l'ltJ'I'i'11tl
1.mWl"l::;:i1n1d'b~IJJ.!~lJn'U 1~J'W'V:::~IJ.J'Yi'1mh\ll
'IJ
1~
L d'11J1"J'V:::MlJfl1tJ~h\l11il1~
IJtJ1nfl'\I'1iEJ:J.JfH~ill"jn'Y1'11~"y'U.yj1il'Y11'U
"
1:J.i1'1f('l'11J"J~\l1
'IJ
IP jjfl1d'bfilJ~MmLUlJ
connectionless
l1'UfiEJ'YI1n1'uL'i\lo1JlJd.Jf'lNl'W 'V::; IP
"
'IJ
§'U~d\!ri€J'U'YIU1'Y11E1l'l1~m m"jfi"l~
"
"
Fragmentation
LL~l"J ::;~IJ\lthm"jll-J
u Vi~'V~\I
~\!n~11:n1'li1'l11J.!a~~'Ufjn'U'l:::'YI11\!Vl1~1
bbm~~'W~l
"
d\!bVltJ\!l'lf\!b~1Jl
'YI1nI'l11J.!1J11Li'i'Unl1~"J::;t'i\ll~'UbLMiil::;l'If\lJ'W
l'I1Wi1Lbm~iil'lm"j(]~'V::;Lbti\l~8tJ
bvi€l1'11'1J'W11?l'1J8\!Lb-Wmnl'lii'1J'W1Vlb'YIm:::ffd.J 1~
L'l'l'Y1~uiB~~ bLMiil::; ~
II.
'''J1~:;jj11
repliP
zllYi 4, 1
lP Header
4-bit version
16 bit identification
8 bit time to live (TTL)
13-bit fragment
offset
8 bit protocol
32-bit destination
IP address
option
(if any)
~ ~
data
TCPIiP
iJlil.
4-7 Header
I'llllJrJll"lJEh'll1'lt'H.Vlfl1
1(p]1n~i'111lril1lJ i:lflmJi'WI'i11tJfiTt..nj'V:::
btl'W 5 20 1t1#1'
Length
YllJlfJfllllJ'l11'l11J.lEl1111m.Ji'li:l"lJ'W1Vl
"
5*32
Ufl
Yl~mvhnu
iJlil 8-15 Type of Service (TOS) delay, Maximize Throughput: Maximize reliability, Minimize Monetary cost lVlD Hhtl'WM11i"off1Vfb'lbf1iJ'MVl~'Wh
lWnTH~EJn
b,1 #l'iiDl;l i'l bbM~:::(in $11b1n'llJ mjl" 1 'lnf11J.lil'V'1u'W llJi:l n1'l'thfil'W-d 11l1oE"1'WLbMmh" 1Vl Ulil 16-31 Total length blJ'WVJlIl(ilYiuflnVl'1..,!1'W1u#I'".r"YllJVl'1lD" Ul'l'lJfI"VJ~~-dmrVl"11'lJ'Wl(;WmJ.lfJll'liEll;l~'1Ifl\l 'lJ'W1Vl1Wi~,,~Vl 6553511J#I' IP Datagram (ij'lEJ'lJ'W1Vl 16 IP VllW11bbn'llJ'V:::ij
",
"
"
I"Ir,,~:::51211JWi1'W
, ,
'V~.,j
""
",
~"
"
"
fl\l'li f1lJi'l
1 Vllliiluml-J
VJ~ri1-ddJ'WVJlIl(ilYi<JlblJ'WYi'V:::WiEl"
'l:::U llt'W'VInVll$11bbn'i'3.J iJGl32-47 Identification iJlil 48-50 m'lan iJlO11-63 5 Fragment offset
bVlfl'lh 1Vffl'lm'lrirlilVl'lim.Ji'lilDm.n1M
"
dJ'WVlm Elblll'll'1lD\l (»1 Wi urrs l-JYifl" 1'Wm ruYi~ rmm 1 bbn'i'l-J bblll:::'t.l1n ~1Jl-Jl'nl-Jn'W 1YllJ" :::i1(ij'll:l.J1'VlnVll
"
1ii1'WnTlnlYl'WVll'1lbbYlU"'llD"'liDl;l~
b'W 1 [illWilbbm:I.JYi~mbVhmJ.l'W#I'
"
"
4 ; IP ; Internet
protocol_.
"':.1aI';\<'>--
-,,~
- --
---
--
fi~ 64-71
Live (TTL)
Time To
djuYJI'l~Yinl'f1Wil~lU1W'lt-l~\I~l'IYi(il1~lbbnJlJd'V:::rlnbdl~ 'lI ,
'lI
(route)
bViau a-l n'Wii1'I1l'11 t1llbbnJl.JC1L n 'il1'i11l1l'1 U l~:wYi ~'W'fl"?I t1l1VI'llli'fl"l.Jl1ti1 \ 'lJtJ\l IP Yi'Y:::~m'ill'i1llL~a:'1'vUnlT"I::;1i\lllmv'VI1~ ~\l1U~l\1l'lt\len'Y
",
'Vllnl1~1'Wl'Wl'lt\lYi\?llt1l1LLnJlJClm'ill'i1llb'l'hn1J
v
TIL LL~l!J\ll~1i\l
":h
1 I'lt\l
l'Illillbbml.J,xu1'11~bmmtJbL~lLL~:::'Y:::1~f.lm'llWiiin~€l11.J 'lI
fi~ 72-79
Protocol
mh.'l~1t1lnrlTJ11.Jbb~1-1h-l~u":hirh.bll'lfltJl'l~mJ'VI~lvWllYienAv lWn1''lJu~-l'iim
r
IP
"lJ
. J1'l!K\I,_T,.lbvlD,:::1J h'iim.JI'lYi IP ril~-lt'i\lD~ddJU'lJD\I q 'iJ 'U b'liU TCP, UDP, ICMP bUUlIU
11.J'illilflD'fl8:::hn~a-l'i::;1J11h"rVJt'l~d ,
ii~ 80-95
checker
Header
ii1'li-li€ll;j'fl~\I'Vll.Jt'l1'WlilllillLLn'i3.J
N t'I~~l\?11'Wm'i~\loiiDl.J~ "
"
ii~ 96-127
IP Address
Source
fi~ 128-163
Destination IP Address IP Header bU'W~lual~ruYi~Iil'1J€l\l IP Iill1ilLLWH.J
ri€luYiL'l1'Y:::Anl!ll1'i\l'litJ\l11\lLb'fl::: Lb~l'Yln,x'WL:W€lbl1'Wm'lhl.J~ r1lwil-l'111.lbLwi~::;VJI'l~'/JtJ\l IP
'f1~mntilNl'lnd:;'VI1JwimUl'VlmV
..
"
1~ W1\lJuunlbl'l'il:::'I1Yi~l'll''Y:::''lVl~l
IP
bl'l,l:::'I1!1ifl 11l
IP Header nU1J
bbSl::::W'Vl'W1Yi
b'dfl\l~ln
IP Header lliltlWlllEl\l:nlalbiJ'W'iiflff'Wl'l1rl
b'l1f'!~dl3.J a ~1t..!t'll~1
Lbn,lJJu
"
Demultiplexing
biJ'W'f1~n LViavhn1dffnVlb€l1ofl€lffUb'VIAD€ln~ln
IP VllWl1bbn'Jl-.Jn1'it'i\liffqJqJllli
"lJa\lM1Jvll\11utllilb~f11.l1"l1lb~:;'VltJt?lYll\l11.l1al
"
• tl';J1~1t1J1J
TCP/JP
lWflml::;l.ln~
"i1w~I?1(;]1.J'11t!b!'J~ b~fl{~::;~nrh'l1t!ti1~t!
1 t!.fft!ti1fl'W"lIfh.'lnT'i Encapsulate
"
"
"
"
1'i11'Wbrlti1 ti1fl1~:': b
"
11.l1JimJ 2 mru~fl
bt1fl.J~ln
Encapsulator
n~[)hhbbn"jaJN\lfl~nU
"
r;il'Y111Jmru~blJ'WDtln"iru ,
TCP/IP vrl11.l'YI~Dm~~:.:dJt!
TCP Stack
"
1'W"i:::1J1JuliU~n1"i 1'Wmru~ bil'Wb"'~fl-JI"lDm~h b~lfl{ ~.J 11.l"jbbn"j:IJ b'YIl;'hflnm€lnll;f~~::; n ru ij~'WaJ1fl~l\11l-l"Jfl1J"'f11J bLi'l::; 1'W1Jl\1nlru fl1~~::;l'll'Wl ruiPil b!'Jti1~ D1"Nti1'W lt1f b i'l1~ ...
• n1'a~~
hlRfil'viN~'W~l~~"
l'Ubo~bl'lil~bvJm.j~~lu
-llflaJi'lvh'Wn"i:::u'":lt!n1"i -u n,::;1J1'Wnl"j
1'Wmruflurlmnfl1v::;
ll-llJifl'\I IP
"
vlfl'l11\l(}.i[;l
Tv!
'llfl.JN11Jvil.Jl'WN~l.ln&iltl~lm~aJ
"
I Routing P
IP Routing dj'Wm::;1J1'Wnl"j~'W'I11 tli'l1~'Vl1.J 1~~vht!n1"ifl'\l(;]fl'lJD\lfllln"iru Wh1ifll;jWvdi\ltli'll~'Vll\1 ni'llnr;il~qJ~vi11 b~ml1\11'Wn1"ifl'\I vh'W-llflaJi'l~ln
,...
IP ~mJ1t!b{1l?1b:Hn~\lv::;'lhmlt!vil'11ul~fl'\I~fl-llDaJi'lltl~t!
"
~t!'Vl1.J luv.J~'I1aJl
"
Vi
hnut!il'Wbl?lfl{l'WI?I~&1~GII~, 1'W"llru:::fl~fln1"j'vi
h~
"
lnfl
n1'~flffl1-llf):lJi'llb(;]i'l::;rl'r.J
"
-llf)aJi'lv::;JiD\lb~t!V11\lvh'W 1A"J\l'lil~el'Wfl~1Ji1J-Ef)'WaJ1nm~
"
bb~1'W
"
iJ 11"l'i"\I'lil~ilt!
"
IP Routing ijltli~nD[)ml1J1Jmmh.J'1l1qJUI;'l1ti1
I
1u
'V
IV
Jf
iltJnsnimlilUi U11I1Sn
w
-.)'lllt!nl~lu'W Host
'"
...
'"
'"
"
dJ'Wn1,~mn'i"'Jln
IP Address
4 : IP : Internet protocol ••
Router
hI
G'lil\lb L U(Pli{n
~hU'iiflrllV1W(Pl"lJil\l IP oiitl:J.J~"J::;~\l1uD\lnw1(91uM".l\l'iil:J.JdjVlbi{n1jJ
1&1"J::;~il\Iil1«m "jlb(Plil{dJWN'VhVl'th~fl\l~hw'iifll-J~
"
"
1u1 Vi ~\l,rWbUMLi{n'llfl\l
IP ff\lLbi.l:n1&1Miln\lnw 1w'Vll\lmUJll'WbbMfiG'llm".ln~ilG'l1".lnW 1cli1(;1UillRU b".ll btilfl{dJwLil1 b1ifll-JU".l::; Q!lWboiil&l1Unw rim.JyjV::;flTIU1Un~1m,jil\ltiiW'llfl\ln"i::;1J1wm"i 'r'Iit\lyjb~u1'iiil\lnUn"i::;1J1'Wnl"id'WilblJ'Uff\l b t1fl\lvlnv::;ij IP Routing 'llfltlTI1Jluff\l"hwG'i'1r1'1Jiln~1'U
b'lltJbV;fl'Yh~11mojjl
1"11'Ub~il\l"lJfl\l
IP Routing b1iiUr1ilW
msn ~11 ff\llw~1Wd'WtlG'l:l.J~1"it!U~ tl Network ("ilU~::; bDU(91"J::; tlTI1J1U 1Wfl1UMfl1tJ) bUMbi{n1uY1dv::;n~11fi\!bQ'Wl::;bUMLi{n1wFl11:l.J'r'I:l.J11'J'lJil\l IP (IP Network) b'Vhttu 1jJ"i1:l.Jfi\lbU(ilbi{mJ"j::;bll'Vl~W
Network
1u
iT\! Hh::;Ul'llbb
bil(Plbi{nffi!lG'lt'1,r'Ub1imJMEJ~~&l1U ~\lffitJ"il(;1~EJ~ IP ijn"i::;~1'Wn1"iyjv::;bbun Vim Ub~'lJlld::;~h~1'lJEJ\ll!'!G'lt'1 ::;'lJEJ\l i{nmJ n"nnn'W b'i'im'h 1Viflu n".lru us bUMb ,k\!VI~l UG'll:l.J1"im'ivT'H1.n 'WVlw~11v::::~\l'i1m.J~~lMum,r'W 1tJ1'W~r1'Vl1\l1(Pl 1&11
"
"
EJ~l\lhfiMll-J bittl\l"Jln
~EJ~~~ ~mh'r'lw(91~u btl\l bb~::;EJ1v ~ uutul IN\l1~(;Iu:01&1 fl~(91nUEJUfldru'Vll\1 UllTV'l bbMEI "i nl ~ m ~1\l1
"
t?11 I'J
"
"
"
t!W'Y!mUFll1:l.Jl1i'i\lbbi.ll11Ub~WEJ{~~lfll1b'1iw
"
IP LUllIbi{n~nfl~fl\l
"
1~'U
Hann,swu~,uuall
IP Routing
IP Routing
[08111 Default Router
Q
•
--
--
EJ
g
Host B
. Host A
'i1l~rl"1ll~U'Vll\llb~::;tJSllU'Vll\1Milii\lnu1~mlll"j\lb'1iwfll"ib~m.JMElbbUUv(91Mil"l(91 (Plll-J~U"ilfln
"
::J
"
••
'~1~:t1JlJ
repliP
2 3 4
fil1!'1~~~'W'Vll-Jlbi'l:-;tliill~Vll\J~ilb~m-l~1~D~1'WbuMb1im~~1fl'W
b'li'W 0bljf){bilM'VI~a
1 usr
2 IP Wl~lblmJ.J'1:-;blnff-J1tli1\1~y,jai'l~bd1lLilEl{
qJ
lvi8vllm'Jri\l
'ilJ.Jmi1J'WbilM bl{m~fJ1n'Wn1Jb
'il~n'Wilr;;j\lWll~hun'l-J1tJ~b'JlblilEl{~h\ii81tl
"
'l1 llilEl1Lr1'vllnTl'ri\JWlllihUndl-J
"
1tJm,m~tT'W
mn 1:!.i1~\ii€l IP
luff
'i'
4.3
nTl'i'tJi'll,jU q.,... ~ r
~u"wnn'Ywl'iJ
(Shared network)
&l~ ~g
Host A
.......t ~ l...;;d
tr ...
. ...
Host B
:i7:wlu
li1
~
Host C
tuff
4.4
tn :rtlm'i 1:r:i'~u'i1-1
2lumf5fn
Network A
Network B
'VI1nbill'lbi{niiLfhN
2 bilLilbi{nb'VI:il1l'WL'WtlTIN~
bW~-J'V'JeJ biil:::nl".ivll\11'W L1.1 nl".i ri\J IP (1Jl$illbn'll-Joiilm:::'VIll\JbilMb b V"hllll'W hJLilllJoK'WLileJ'Wo]Jl\l(;]'W'VIInrff-Jlnl'l'V:-; b~'W'il~1l 2 ~\I~D
".il birleJ1beJ\ltT'W'V:-;ilLuMbi1n~~eJ\I~(1Jr;iD(iil~
Network A bbi'l::: Network B .fl\Ji:j'ViI'l'Vll\Jn1".ibfl~€I'W~'lJD\Joi1€1l-Ji'lbVhJ"""~'W'VIl\I"~Vl hJllll i'll U'VI1-J'lJeJ\l-lieJ:IJfl'V:::1tl~1\1]'VIln:w1'1iil u1'W bilLill i{m~
i1l".illirleJ{b 'i'lu\I~'Jl&'im
"
I'nJh bbn".i~~-J'VI~l'In Jia 11 ~ltJ b".il bMil{il U ff\J oi11l-J ULilll{n b 1 fl.r\ll~unll
"
"
"
Ul n'Wlbilh
~1mh-J(jnJilbbm:J.Jbtfi'W'VlWvlnl!'1iil~AtJ'Vn-JbW~\l b'Jllirldii:ill'i'lU\lff\l11lbbiil:-;ff\lnfrm:-;'VI11\J
m'Jri\J\iiEJoi1EJl-Jiill(iJu
qJ
"
'Vlnm'V'J
"
4 : IP : Internet Protocol _ •
ti\l1~t'l'\ihJ~11.J'Vll\1'1:;Wlthlb~t.rvnnnnn--h
y'
'I:; jj dll'l bi1 n ~U '1ViLaJ1v1 fl:J.J§jfl1Vll.Jl'l'l\l bb~:; WI fl\lci \I'iJfll.J iil r-hu b11 bl'lfl1'1'1~11.J u iil:;:W'VIe iu b~ ( clh
bWU'Vll\1YiVllW11 LLn'l:J.J1II1:J.J1'lm~t.l'vn\l1tl1v1 1?1\1,rUnl'lfl\l(§jflVllv11 bLn'l:J.J'1Jfl\l bl'lfl1~\i dJui1'1~l.J b 11
I'hilqjhlnl'lri'1'V1Ul'ltl1:;~'VlEJl1'IN'lJfl\i
EV# .~
IP Routing
ntJ"I'JIflJ.Jfilfln1.J'll'i)"
..,
4.5
IP routing ,rU'I'11\11UflVUU~t.J'inU'lJfl\ln1'lci\l
on fllJ
Lvh,ru
"
fi fl b'l1 bl'lflf
"
bfl\l"l:;1'll\ilUll'll.J~~ ifnYi(§jf]
'I'I1nhlllWitliilll.J'Vllllil1WiflV1UbU!iH
b£fl:J.Jflvn",:;'I'11n1'liil'\I'iim-liil(§jfl hJBn~mJl
"
n bU'IN1:;blJl'l bifnYi
..
"
...
Vlbbn
b'll b>'lfl1c1i'l(§jfl hJci\l(§jfl bLiil:;nfl11~:J.J l'l'l'l1l1Yi(§jflvl1W11bLn1~,ru bb~db'IN'll:; ci\l;fl'iifll.J~ Lbill iil'1'IH:;l1\111iilll.J'Vll\i'l'l~fl1lJ,rudJuBnb~tl\l'l'lti\l il-.y:;ci\I(§j fll'll~h
1tl b~l.JU~tll.J
bLiil:;b'llbl'ltlfcli'l~U'1VitlV'l:;'VI11\1'Vll\1nb'liunu ...
\bn'l:lJ1tl b ~tll.J '1b 'liu,ru Viiil:;!:l fltlVi iil:; ~tlll-.yu ni l'iJ::;l1\1tliilll.J'Vll\1'1'1~ fl'l'll.Jl'l b iill d
"
"
U bUl'l b ifnYi(§jfl
"
LUl'lL %n
"
ufll'lci\i'iim-liilUmJvillll'l)
"
, "
b ~tlnW~i~\loJl
'"
b il(llL i{n,ruYiiil'l'l
...
lVlI'l1'l-.y::;ci\l'iifll.Jiil1tlv-Jb'llbl'lflftVl tl'l:;nflUv111.JiiD:Wiil~\id
"
iifl:wm'l'l~ld'iJ:;biluEJ1.J1u!11iiJ!nlfliV
"
"
IP Address of
next-hop router;
'I'I:lJll.Jn\l IP Address 'lJD\ib'llLj}1fl1c1i'd~uVi(§jD1VlEll'l'l\lflVUU
"
hu 'llWi~\I
L bliiil1tl'hl.J'~-.yl'lrul(ih 'Vl
• £'il1~:::1J1J
tcr/»
~'WVll'ii€llJ~1'Wm#i~-lb'llbU~bviEl'Vn le1Sl#i1J~iV'VI1-l'7JEl-lvrl~h
IP Address iiI'11-ln'W'l'JElffinu
IP Address '7JEl-l
"
,"
"
bi1(?JbinuElvrbl'l'iSliil'1'l-lnu i
bill'1biimbElvrbM'iSl'7JEl-l le1Sl~
"
,"
'UVJ1:'l~'7JEl-lNext-hop
"
~'UVll1 'Ub'il~~-l
"
"default"
router
mih :.:vh
1 Vinl1~
l1'lfl"~'VI~Elbil (?J ifn b1:'l 1'U b'il~~\1 b'Yll"J 1.'l U~lVll~h b EJ b 'l'nn b"Jl bl'lai bbfi1:'l:':~l~l-lnij
'"
1V1VEllr1EJoVEl:lJG'liirl1WUM11'riEl'Ubbill1'7Ja\l b'Jl bl'lrJ1 oJ-l'l'l1n llJ'l'Ju-1i€l:lJG'liil'l'l-ln'lJ bLm:lJii-l:.: n nN-l11J if-l ~vJ El1.'l#i bl'1Elf bSl:lJEl (il\ltT'U b"Jl
"
"
"
1J1:'lIEJ'VI1J 'UiiSl(1} D1<J"l:':~loJiTI1~Ell:JJi11h:.:a'YlBJl1'I'JU1Jut'in'I'JfJ 1 , "l:': bl1'U1alll b'Ji blllilfl:JJ~1 bUWilDJ bnu bdl~J
"
1oJi-ll'U 1al
"
l'
-1iEl:lJ1:'ln"l:':Sll:lJ1'iri b&'i'W'Ill...J fiJ1J1.'ll tJ'Vl1J lal tlll Vb'VI?JilbEl...J111 'I1bi1(?J ( 'V bifnSll:lJl'lri
'I
"
'11VlVhj41nVlbb1.'l:.:1lJ~
ElJVhm'ibbn1'7J
1r1",jJSl~IJ"1JfJJ
bill'1b ifn
b~:JJ
:lJll 'ii...Jl'U'I~...Jl 'UD'U billElf bu(?J1i...JijdJ'U ilil'U 11'lfl"~ bbfl:':'VI Vusu bill'1 bifn n"l :;i1rll1:lJ ciJ tnn bb~:':fl5u m iu'iiEl'U"l'Wbn'WnlT'J:':
1oJim'lb
'il~~J
"
Hi
bl1ElJ"llnl'Wl'lfll1il"
~El1'Ubill'lbifnl'li.'llSl
A bb(;]fl::;bUV1bifnJ'W~n:lJldriii41'Ul'U
C J'U1,nm'Jbli141'Ul'U
",
216_2
~ 65,534
bU'U11Jlriivln:lJl
n ~\ll'Iflla
A bbfl:':l'li.'llfl' B b'l'l'il:.:mEln1
b'VIGhd~-l{ln l.E1:JJVl:lJ(ilbbfl:.:1:JJSll:lJ1'Jmll11Jl-E1J'J:.:bV'1lUii
"
4 : IP : Internet Protocol _ •
"
---9
~. .
"
. "'1(~ .,.~" ..
-~----~-~~~ ---
- ---
----
_._---_.
nT'ivh
Subnet fieJnTmu,nw(ilbl1mjmJm1.l1'Ubw(ilbl1mIj5m~Ell'f1bbMf1::':bu(ilbi1njhJ'l
..
rwl'vi
b'Vfl.n::':~l-Jnl.llJ~ •.nruleli1l~~:fjmj
id bbPl::.:bi'J'UNetwork id fimb'Vlu~'l::.:l'f1l'il
,
'"
lCi11.1 1i'Vf5nmd"b&imnl.lnld"'l11
IP Address lJlmmtnmdJ'U
Host
",
fiEl'l11I'hl'U~lu~dJ'U
Host id b~l-J
IP Address 1alil~l\1b'Vfm:-;1Nl-Jn1Jm,j:j[J~'"I~\l'lJil-J11"lG'H;'lt1.JbbMPl::':bU(ilbiin
~!..I# 4.6
IP Address lUI'J~I<'i B Class B
"
14 bits
8 bits
8 bits
11
Li'f'iJl'lIn1:i' Subnet
Jl1'{11~
dJ'U'lJ
2 Pl'lu
1(;1mU'U'lIeJ\l
subnetid
uae
hostid l'Vfl.J~i'l'll'Ul(;1b~mNb'Vf~mvbJ
Class B
b~l-J 'VI5,mld Subnet 16,382 65,532
4,161.028
254
254 1M#!
Subnet tTu1J.hhd'Jw¥lil\li'l'll'U1WlIil-J
subnet id i'l\l~1'l11.1(;]lWlJil
11.)
-J1U b'IfU ill'l''1 :-;i'l-.J'l'W 1'WbU!ilbi1niJ tJ ~fl\l u Pl:::-.J'l'Ul'U leJ'(;'j~lJ1n~'Un 'll'Ul(;1'llEl\l subnet id use host id 1'VflJ(il1lJ~&iil-Jnld" 'Uiln'illnn1d"~1illlJ1'l(llii
-7rilfiElnEl~I-J'Vfd-J'lIeJ\I
v1utJ-.lVl,n '7
n
1~i1I~~El~1'Ubu~bi{m~1.Iln'U n1'l~ilNld"al11.lii51.1'lil
"
16 ~lu1m~~bbi'h
(;I1'1l
fl~ bbM 1'1{-.l'J::': U'Un1d"m::':'il11.l1]eJ l-Jfl11.1 bi'l~eJ-J~U '1-.J'I'Ul'Um Pl::': b iJ\I l-J1.I ~il~l\l n
uar
~-.l bbPl::':
111n bUMbi1"m.l'l::.: bllWdQ n 'llJ~!il1.l b'Vll'1ill"l~eJ11'11.1I"i'll 1.111.1 q) q) 1 ru;iiil-J'ill nrrmnn n ff Smurf (CiIl.1'Vl~20) bb~ln:fjlEl nli1llJln~nld"~Eli1l1d"TIEllJfl1l11.11UbUM
>J "
bi1'n'il::: buu5~'{II1!il1alil
'llCii b11'i11nnl'lQ
nhl-J~
b~ 1.I-J Yln bn MbWi ~i1Eln uuu bU(il b:.J1"nfflu 1'Vf4i~\Iarn'il:::'I4~ n b~ 1.I\lnl'l u 1.11
ElElnbbl.l1.l1VibUl'lbi1"nil'll'Ultfl111ru
~bflU11.1 bUihl'llnl"ll1Jl'llJ ,
Subnet ~-Jbll'UPl'l'U~QmllmHlun1d"i1ilmbl.ll.lb~lJil 1!il1.ly(11ubb~lb'llarn'J::':'{IIl.Ibl1'Un1'l Pl'lulm"1i biieJ-J'Jlnl'l1.'lli1l Subnet Nl1111.1 IP Address 1UI"l~li1l B bt'i'muu
B ii~'Hf\ll'WnUbb'{ll111Pll~
fllUI'111l1i11 A 'l:-;'{II1.I1rii1dJumJum~d"1:::i'l~1al
••
t~1~:lJlJ
tcr/«
fl~l\1 hnr;n:w
IP Address
Subnet Mask:
V!lnn~11(i\ln11 subnet lb~1~f)l-l'V:;~fl\lnt'l11(i\l nlru~d'i'Un1"ifhv!'U{;l Subnet Mask ~1~ n11~:jhQvn:; IP Address bWfJ\lf)~l\1b~fJl,r'U netid bbG'l:;hostid t'm.J~",j:;u1'Ul'liillfl"c;il\1'1 , IP Address ~\ln~11fl~1'U'lil\11[9j ~
d
,r'Ub".i1ni.'l'1:Wl",jnmlU'hrll~\laf)\l1~1lJmmTn il~1'Ul'liilla1[9j
~
v!~\I'Vln,r'Unal:Wl",jmbVn
hostid 1~'Vlnm"ibtJi~ud'itJunu:w1{;J",j~1'U
" '1Jf)\lI'li.'l1~HmhtJ'U
b\c;ib~EJ!jn1",jbbtJ\lbUl?lb{n~mJ l[9j~nTJ l netid usz hostid 1~Bn~f)1tJ bbiil:;ii1~jHmr\lrlu 1'Un11'Vl1rll'Vln Mask tJWf)\I Subnet Mask dJ'U~lbiil'lJ'1J'Wl[1) 32 u{;lbvllnu
host id blG'l:; net id + subnet id '1Jf)\l1~aM"_r'U nl",jrllV!'UWlrll'lJEJ\I ltJ bblJm~ rnnu IP Address
"
~EJvllnTHbU\I
tii'lmh\l'1Jfl\l
FF.FF.FF.OO
(Hex)
255.255.255.0
(Dec)
IP Address bal-lf) btlf)\I'11n IP Routing
net;d 'li\l'<$1:tJ'Uf)~l\1~\l1'Un".i::;m'Um",j
"
IP Address n'1:::ii11:Wl1Clmrll
Netid+subnetid t;T:.)E)~.i1\)
Hostid = [IP Address] AND (NOT ([Subnet Mask])) IP Address = 192.168.15.20 Netid = 192.168.15.20 Hostid = 192.168.15.20
Subnet Mask
255.255.255.0 0.0.0.20
Subnet mask
= 192.168.15.0
=
'VliEJ'\fiIWI~lfJ11(il11 "Netid
dJu
N'JU
"
lliia
IP Address
fif'Juri(i}1Jn1JiJliI'11f)v riiJrhdJu
riil!"]')
Hostid
Subnet mask
0" lYUbEJ.J
4 : IP : Internet Protocol _ •
'\": "
v
.' h.
--
" -_
/tt~\;\
--
--- --
--
--
WI.,jtT'WVl'\1'J:::~nbGllHdl'WtJn~lnnTHhvl'W~
IP Address Vibln~ihHU;;;'
"
nl"Jnl'VI'W~~l
"
rI\lbbiil'll'lJtJoJ
lu,ifln'JruvhAb'dJ'W IP btJ\l
mii~\1i1tJ1"loJlI"l1
"
WloJ"JltJiil::: lEitJ~~ tJ
h)11
1111-1111111-111111-1_'111111111111
o 'VlnUIll , o 'VlnUIil ,
...
'
W Address
1:JJi'J 1:JJi'J
o 'VlnUM , Host id
_ lal
l:JJlal hl1Ji
ct
.coII''I<
bbtJlil lil'iil"~Jl1 uttJ 1m'l'II1Iil'U b btJ\1 (Ioopback address) lJ'ltJfilI'11iil"II1W.'V'l1:::Jl1u1'UbVhtT'Ubbv1"1:::1:JJiii\1\litJ 111 tJoJmVln,ntJ'U
~ ~ Q.C'.:Ii
Net id Net id
1 'VlnuWI , 1 'VlnuWI ,
'lJ1tJ(lll'lla~(;lUIiI'l\ll11i1\1bil{ilb lin~,::;1J
1tJ ,
net id
Net id
4.8 IP Address
m"Jl\1~
"
bbW::: 3 C>'IlfitJ
miil:JJGlll-J1'Jmlll-J1nll'1'W"HiJ'UbbtJ~l~'JGl'lJtJ\l1®"fl~ai
"
1~!J~1'U 1 'I'InJrll~j:j1irul'll"l:::lhVl~hl
127
l'Il-J1tJrI\1 Loopback Address fitJ§i>lnir1Jb1ilY11~lbtJ\I 'I'Il-J1tJ~\l1[J~l'1VJnt;hl'Udli1lbl~nd 'I'Im1JrI-J M16ilm11mtJ-J IP Address "ioJA1,'i{:::YI~m~tI\1n1'Jnl'11'W>'lAl (AtJn1'JmElL'lrll~l'1"rtJbtJ-J)
'VolnD~
o flnDUI ,
Net id uae
••
~~1~:1J1J
rep/IP
~ln
IP ~L·.i11~Rn~1~J11u'lJ'Ylr1E1U'Vl'lhdf'HU~l.n'T~5u'Vl'd\l~dlr1ru'lJEI'Il IP ~E1nn IP . -,
" 'lJ 'iJ 'I IlJ 'i.I
Datagram ~:; IilEl'llj:;'lJUEI lLVlj~'lJEI'Il~a'll V ut'l:;e)'f1J ~Bj:;'lJ~U'Yll'1l bbt'l:;l1!in b v'Yl1\1'lJEI'Iloiim..Jt'ljlVl ill b LQvn:;lul:;#i'u An~l IP fhliue)u1l'Vlln~'Il~1'11E1'1l IP Address l~nnIilEl'lln~:;wmnll~
LL~fll'Vlf1Jn1j
IP l'111'in-ff'llb~EI'V:;boElh'Ylnnt'lln'lJEI'Ilmjvh.llu'lJEI'IlT~P/IP ,
.Tu
"hLliu~EI\lRn~lt'l:;bBVVl
bLt'l:;1'in~'Illl1n1l1:;#i''lJIP IP 'V:;N'Iloiim..Jfl~'Ill111~.Tu.J'lLliu~B'Ila'll~'IlhJlm:;#i'u Link Layer ~EI <J Ethernet r1BU bbfl:;lUj:; #i''lJEthernet ttu VmnJB'Il IP Datagram ~\I'Vll..J LU'UbL~Ethernet 1'111 Frame'Vl-G'Il Frame bb'WUBU1lEthernet ll-iJ~n Source Address, Destination Address 'V'Ilmh1'il.. riln1jVi
1V111u
l:;#i'U IP ~'IlIilEl\l:i:ifll:;lJ1Un1j~'Vi'11~j:;#i''lJ Link Layer nm:;#('lJ IP :W~11l..Jffl..J~U;5L~mJ 1~ 1v\lnu ARP (Address Resolution Protocol) dJum:;'lJ1Un1jLl1~VUI'11j:;Yl1l\1 IP 111dJu
Ethernet Address ('Vl1BVi b"J11~nnU lullEl MAC Address ~mbBVlbV11~Vll\1FJ11l'l bLJ'hJil\lEll1mru b'liUnl1Vl LAN) IP Address <J.TuLliuL-r1V\I~E1~~~LbEll'l LV1j~ViNH'nl'VlUl'l,rm.J11'11fllYlf~ 1FJ~!il <J #i''J lV1#i'l'Vl-G\l fll'V'V:;Ll1~VUI'11 btJUblElV1bV1j~~UL~B h'Vl~ilmh\ll IP Address ~!1lnb-r1V\lLL~'l'h 1~1l-i~1l..Jljn~E1G'1111ai lL~b~E11!1lm'ii~\l1'11 lai[1n~EI\l lFJG'I()].Tun IP <J " "":::n5Ul..Jl~E1G'1111~~nr1~\I mj~il~ljoEEll..Jfl1(11'11~illl..J1Uj:;#i''lJ ~'HtJ'UbV;JtJ\I~.Illl:;'Yl1\1fltJ~~flVi IP <J 1aJl'Il U~1 ~1\1n'lJ1U ,:.;#i'u B Lfi il1 b-W 1i,:1tJ11jru 'Yl 1f11 Vl'V:';1'Vl:1J1 u Lfl'lJ1b:;-;,llirl l'I i ,n ,w (Ethernet Address) 1i'llbtJULt'l'1lVil:::1JMV1I~hmjn'lJBl1mruttu1bUULfl'lJ'lJUll'l 48 1J(II(61'lJ()]) 'V:';~ll..Jll[1:i:i jri1~ V11l..JVim-i1~E1'1lnlj mJ~\l1'11 ~
'"
281,474,976,710,656
Address vioJlnULflV
r1iluVi"":';Rm~1l1tJfi\lm:::1J1unljlunljLtJ~uu Encapsulation vm
IP Address n'lJBLlitJ1bUt>lbLill'lbVl,~Ju'V~
..
"
lJ'IN
hw 111
E1:l;j ~
"
CSMAlCD (Carrier Sense Multiple Access with Collision Detection) lJ'IN fl"lm'l~ 1-Efl"l£1-r1J-ci\lNqJQJlru'h~n'W bb~::;('Bb'Vliimrh)7uci-J-ii
vr:ifl~n'W1(i1ciilw'l11~b~1
10 Mbits/Sec
"
IEEE 802.3 ili IEEE 802.4 IEEE 802.5 IEEE 802.2 fJthJhnr>!l~ Ethernet l.h::;nDU~ b~fJ:iln1jjl~n'W'lJfl\I:l.Jll'lj!l'W IEEE 802.3 mil::; 802.2 'V1l1Vi1f1"iJah.J'lJD\I bb1J1Jb~mimJ1flll:Wln True Ethernet (~""Jlnlll'V>1 rll'VIf1Jbfl~D'lh£1 Token Ring CSMNCD
'VI~fJ Ethernet
~llfl\lal~1"i~1ii\ll'W1(i1~..J1J'W
"
~..J:ilm'J1.l7lJd..Jll'l'J!il'WU1Jfh'W 1'Wnl'l't..h TCP/IP 11.l111..JI'Wnu~\I2 :w11'l'l:lI'W11ii 1~E.J'1iBU..Jr11J 1'W nl'lb-lfm.Jt'ifJ TCP/IP 1m;l"MnlJ0 blW{bU(9]bflbD~ use 11f\ll'W1(i1~\lG'lD..JmM'l!1'W~D
1
2
Encapsulation
Hi
EJ1"l"l::;lillmj!;1ci..J-f1J-iiEJ~ii'l1(iiMl£1 RFC 1042 'VI1nl11~i;'lMi;'llm'!;1ci..Jfu-ii€l~(;'llM~\I bblJ1J~f1RFC 894 bb~::; 1042 l'il option
"
~iPrmu'W default
"
hr1&i~1f€ITll'V1'W~ RFC894 nu RFC1 042 ~1(i1oJf~bbiJ\lnu'I'll lVi1l.lj 1>'1r11l~ IP &lm'l li1..J1'W1(i1~..J :w1(i1'::i1U ~[i)rllAq}lUn1' 2 IEEE 802 ~1lmj'l::;ml..Jlu , Encapsulate [i)l(iilbbm~'lJ1l\l IP ~\l1JU Ethernet
o bb~::;
"
Frame l1bU'W IP, ARP 'VIiEJ RARP bb~dl'111lJ RFC 10421'W1lJM~ 1'l11:I.J£J11'lJ0\1 thernet E Frame bbt'i(i11£1-iimhnl'1'lHl..J Ethernet
12-13 nguHhu'W~':-;1J
'I'll 1'11b'l1i;'l1:w1'lmb£1mbtdl'1"'lnVJ~Widbfl\l11
uuu 11'1tKJd
••
'~1~:lIjJ
Tep/IP
IEEE 802.2{802.3
Encapsulation
802.2 LLC
(RFC 1042)
tl1#S.1
IEEE 802 Encapsulation
802.3 MAC
802.3 MAC
28
18
28
18
• •
'"
"
fhu1u
IP Address "V~C1nN\I
El~1u IP Datagram Lbiil~L~El"V:;'1hm':id\l1u Link Layer Ju"V~tiiEl\lil~bTIEl1bU(1lLbEl(ilL(ilJfl'lJEl\l~\I ~U'Vll\1LLi.'l~l.liillU'Vll\l.yjC1n~fJ\I~\I"V~ii!1j.Jl'Cl-r1Jfi\liiEla.liil1~ m:;mUn1iLUn1i'V!l 'lJEl\lIP Address
"
" .yj':i~1Jil~\li1 •
"
MAC Address
mn
IP Address 'lJf)\l1.li.'llU'Vll\lElu1'1.,m1\flbl{m~UlnUn1J~U'Vll\llml'(l]~U'VI1\1'1~d\l-:i1Elj.Jiil
11.l1J\llrH'l'(l]l.liilltJVll\ll\flu\fl,\I vnn IP Address 'lJEl\ll.l1illU'Vll\lf.)~I'1Uiil:;bUllIL1{nnu 11fl(l] 1 w ~U'Vll\l'1~~\I-:i1f)a.liil1tJ1J\lb"blllEl{ bL!II~\I2 L~Elu1'lJ!lil\1n"V:;(ifEl\lL1.l~tJUAddress dJu IP MAC Address ~\l1"i LVltJ\lbb!llbl1'1~b~Eln 'lJf)\ll.liillU'Vll\l'V!10 IP 'lJEl\lb'llblllf)'h'vi1Ju IP
"
"
"
"
"
~-
----- --
"':"'"'~
-
'.'."~'~
i!'.&.. .~,
-
-----
---
----~-,
----
--
ARP
~:cci\l
Ethernet Frame
~L~EJrril
ARP Request
l'lJu\lYlnLeJ~W;~mj1Jtmj('\b%n
OJ
(L~Vnl1nllmDr;]1'l1~W;)
'lJiJ 1Vif?lDU MAC Address
LVimn~11 n5um
Host
LFl~D\llr;]i1
IP Address
(iJl\lrlU~t*iiJ\lnljLLi.'l~
L~€lLfl~Wi~djUL;h'llD\l JilEJ
ARP Reply
vli1Ni'l"ilurIlJ.JrhlMu ARP Request n'V:-:t*iD\lf?liJU " ~\llur1'1r;lDun'V:ci1"r-J IP Address Lbi.'l:-:MAC Address 'lID-J(iJ't.HD\l
IP Address
MDun5u 1'lJ
L~DLeJi'l"MvlGi\lARP m:-:UlunTi
Request
lJi1u
ARP Reply
n5ul-Jl
LE'J1!f(ii'lJ1.'ll!'JYll\llar~\llll,",l
Encapsulate
MAC Address
1'\..1
uiih'l-Jg-J
IP Datagram
tJiill!'JYll\ll(i1mh\l
flnMil-J bbiil:::mj~Di'l"l'JlimJi.'l~,hw
"
"
Ethernet
luj~li1u
n'V:-:L~J.JMU;U
ARP Cache
~:-: L{1't..Illm::-:mUnll iil\lU'W
Ethernet ARP
~ "I:-:Lnl'l-TI'Wb~J.JDriiJufil'llriil bLnlJ.J'IlD-J
,
IP
"I:-:nn
LLiil:-:n'l:-:lJl'Wnlj l'lJJil!'J
MAC
ARP Request-Reply
"
Encapsulate
V111Vi'lJJd~YlEJl1'V'11 u nll1lJN-Jfll'l
rllJ
IP Address
nuuu L1'l1!f(ii nu b
ARP
lmJVJnFl{\l
"
l1dJu
f?lTn\ltib~£Jnl1
'lJ 'iJ
'V:-;vlln1JnJ::'V1EJ~bI'111!fVi
MAC
mmltJvmLeJ1!f(iiJulVi(fJ,l'1l'liiilm'll'W
Address
b~!'Jriil'l.J'h:i'l,",lbtii:IJmhb~lY1iillJJ
iTIVibnu1.'l"lu
b~DFl{-JviiJltJ"J:-:1WilJJriiD\ll,nWDn
IP Address Address
dJUiiltJ~~flbbiil:':1!flJ.J1Jm'lJ~EJUbb'lJl,Nl~~wN11i nDl"J'V:::dJ'Wl'il-viNr;]'V'I1.'llVll$l
~ •
lu
ARP Cache
tll:i'lnl'l
'U
"
vlL,m(iitJiill!'JYll\l
Ii1"JUbVl'iIiJD\lflullruYild Dl'V'V::ltJ~EJ'W1'lJbl~1n1Ji
"I ~
~"i:imjr\'1Y1'W(i1D1EJ'IlD\lliiJ~iillu Yllml1.'ll~l\l
ARP Request
n~11~DliD:lJiill'\.!
bi;i!ul'lJmnm,tlJr-h::'Yll1-J
"
ARP Cache
'V::1J\lFl-Jb~il~tJ1Wi1ubli.'l1'Yli!\lb'Vi1Ju ~-J'V:;riitJ-J~n1J"'I11
'iJ
lY1lJl~D lVilMiDJ.JmJ'V'Vu'\.!btiil::;vlu~JYu-vi~Vl
'iI 't
"
MAC-IP
LI'l!'JvYll'lJmu'lJ€l"iilJ.Ji;i! lu
ARP Cache
'1:;bnlJ
11 20
ARP
Ul\1 vnm1.'lEJ";)lnJw'i11u
Request
Cache
n"l:;8niillJ~\l
tl'UYlm!'Jfi-JYllntiiD\lm,1ii~MDn'V:::MD.,jvll
lY1lJtl'ubD.,j
f+-----
Ethernet Header
••
t"l1~:t1l11
rep/IP
11)~ 0-5
Ethernet Destination Address dll'1-rU Ethernet vrlltl'l:':l'I:1J1un\l LLilI?lLl?liQ!'lJil\l1l1illUYl1\I bb~dll'1-rumru'lJil\l ARP bllil\l'JlndJunl"l"lii\l oilmJfln\l'Vln 1!H~Ji'V1il~UUbi1I?lL l'I~il'V1b i{n 1unllU"WI?lI'll l!IJi #l\lJuVlnul?l
'3..l 9 'IJ ,
'lJil\l~lil~d~\Iliiil\lb1Ju "1" ~\I'mJi?l~il FF FF FF FF FF FF 1lJ1>16-11 Ethernet Source Address dJUbbili?lbl?l'Jiil''IIil\lN'V1d\l Request Lil\l .ARP
b viil1 ,:,'t~~;H'l'V1liiil\l n1'J1?l mru G'llm'JO(1lilUn~um l?iil ~1\l Cl n?iil\l au
"
11Ji~i12-13
Frame d dl'VI-rU ARP 'J:;;Mil,:n1JU OX0806 11)1>114-15 Hard Type ,:;;lJlh:;;bll'Vl'lJil\l Hardware Address 'V1ARP fh~\lm~El~
"
"
"
1un".irud~E1 Ethernet Address ril'l:':~il\lb1JU 1 1'lJ1>116-17 Prot Type i:':1..J1tli1(1lflillil'V1liiEl\lnl'Jm~l'I:IJltJfl\l~E1'Jnl,m~ Address 'lJil\l11l,11?l1'lr.Ji;'w::::1'J mrudMii IP Hardware
Address 1Ul>119 1U1>120-21 Port Size i:':1..J'lJUli?l'IlEl\lbbEl~1bmQ!Lu1tl'J11n1'l1)1iI~Cl1:IJ ~ 4 dl'Y1-rU IP OP Field b1JUn111:.:uilblJU ARP '1IUI?lLIn , 1 ~ ARP Request
2 ~ ARP Reply
3 ~ RARP Request
4 ~ RARP Reply
Sender Ethernet Address l'il Ethernet Address 'lJiI\lNN\lii\l'J::::ilrilil
nu LUlul'l
6-11
"
Sender IP Address ~EIl'il IP Address 'lJEJ\lQd\l Target Ethernet Address 'l::::ll\11it'l'TI1-rU ARP Request L')'j'n:.:iJ\l1~1 (fi1ibb~1f1\11~liiEl\l'Vh ARP Request ~n}
"
"
1u~ 38-41
5 : ARP : Address
Resolution Protocol -
""" '::.':
... !:,'.
-
-';_",
-
~
-
., .
'VI~\l-VlniJnT'jlii\ln";j:;-V18 ~;:;1(O)f1J ARP Request
:. ';
-
--
---~
ti i\ln'V:;111I'h1'Ul1J(9)~
'"
"
38-41 j.J1L1.l~81JLYi81Jn1J
IP Address '1IfJ\l
uli'"j'VIln'Vln11~r;H~'Yilalf1J1J".ifl
h ('h1i'U~fJ1JnV'l\ll'U1181..h~ ,
"
Lml:;LU~bl{nV'l\lMfJ\I
ARP ~flB1Jl8(11f)'Uai'U
1 2
3
"
bll~u'Ul'il1'W
OP field vm
use "
0'\1
l.h'hHardware
L~fJiJnl".i
Ethernet
"
1Unl".i
IP
mn
ARP bb~ll:JJii.:i(llfJ1J~:;vllfJ~l\lh~
"
X l'U1Vi 'VI~idl~~
"
LfJ\lil
VWl81j.Jvll
IP Address biJ'W,"h~€l~V'I€l~~fflj.Jl".im1.l~1.J'Wlal
IP (IP
" "
"
"
(9IfJ1J ARP Reply f11U IP Address 'lIfJ-..l1~ff~~'W1Vi,ffj.Jl!J\lbbfJ\?Ib\?l"'jff'llfJ\I(9IUbfJ\I n-v:; vl11Vi"iifJ j.Jiil~1~ff~~-..l'VIiill1.J"i:;lii-..l1 y([elfl~~'UJ'U b1nlii-..lbiilj.Jl a\lle'lN~'1IeN Ln~fJ:; h~'U b".ill~ 1.J
'"
••
'~1~~1J1I
replIP
anu
ARP
h'i'vm ,
IP Address
h..!bil~b11n~
Ethernet Address
'7Jfl-Jbl'l~fl-JVi1lJijmj~ dJunl'l
DoS
vh1Vi
'1Jf)\lle.li;i!c;1'i11d'Jubnt'lb1~ ~-J'V:::vhll11!)~#i~u1Ubil(i1b11nlJJffllJ1drlS1'-J
DoS
"
ltlfl-J'Vln
Address
"
ARP Cache
:ih:::EJ:;L1~l
n1dbtl~!'.JUlltl~-J~'1Jfl-J b~~bb(?)blJU
"
IP Address
fJ1'V~:::vi'11VilaJfflm'lrl~fJ1iIl1l~il'7Jru::: bn1mlVlbVl,ffbnll11'U
ARP Cache
nv:::$ifl\lD'I'lb(i1'V1mh1illJD dJu"li~hl'V11\11r1~~Ualm'lrlH~-JVll::: " " n11D'lNb[i)'VIoJJmJ~1u ARP Cache '1JfJ\lbb~~:::lemtltlbvifJn11vhlVi ARP 1~11Jo]jfl~~N[i)'111i bb~:::bn[;lNflb~EJVll!'.J~ 1
"
"
TCP/IP SUitei:i'VIiJl~&\l'lil'HI1'j"LbPl~rh5"j
'iJ
lUbPlb1Jfl{b&1rnnlJIP Vf1mPlltlfl1Vifj"jn11 IP fimYiv1Jb'vi1TCP bb~~ UDP fllili ~uflynlJ~nb'ru~ 'lID\l Message ~ ICMP vhnTl~mn'j" UDP (ililmVftl1ilnm'l~D1ili11 ~\l.a ICMP
li
"
'l:::bi1U111'U~lU'lIfl\l
-r1J~\lojjDaJ~'VlnJl'Uvl1\l1uiJ\lU~lU'VI1\1fflm'j"nlinPl1m:JnMtlfl\l
"
"
:tuft 6.2
leMP Message
78
8-bit Type
15 16
8-bit code
31
16-blt checksum
iil'lVi
0-7
"
......,~
-
1JIIItY,--------------
UGliIi
UGI~ 16-31
1~uvi'lhJfll1~Ul1'lJEl\l
Message JU'rhil~iioiif)l;lr;;l~1~VI~\ll,mnni.iaubb~1V1u
"
ICMP
• •
• • •
• •
• •
•
• •
•
• • •
•
• •
• • •
• '~1~::1111
replIP
Description 11 0 Time exceeded Timet-to-live Time-to-live equals equals problem: bad option missing 0 during 0 during transit reassembly
• •
12 0 1 13 14 15 16 17 18
0 0 0
•
•
• •
0 0
0
•
•
mask mask
nls11i.,1UrJa., ICMP
• • Query HIri'I'Vl'hJi.lEllHlll-JG'!r:Jl'W:::'l:::'Vl'i1'111'W Error Hilil'Vl'hrnU\ll'WiitJNWI'VIJllllW1~dlWl~'W
6.3 v:::l'l1'Wll ICMP Message ICMP ci'l'W1'Vlf!J"I:::vlTlllih~'llU\ll'W1"l11l-Ji;Jl'l'VIJllllW1~ t!'Wfl1'l'l:::mJ1Ji~\I
'llfWll'll\1~
lnWl~'W'lJEN IP Llc;imh\l~fli1l11
hJt'lfl'W~'Wll
ICMP
Message
t!'Wrll'Vl'l.'h~'llU\ll'W1"l11lJi;Jl'l'lNllll>111'W
"
bill bm)'h~EJlrl1J
IP lllll!":G'!\I
"
v:::vll'Vlih~1'Wb1;'llvtJ~b&1rJlfl1J 11.Hr\lll1111V"/ll\1fl~~
lP l'W'lJru:::b&'iulrl'WfitJ\lI'I\ltJ1l'i'u ICMP
IP dJ'Wfilci\l
"
(l'W~fl'l~ru:::dv:::l'l4'Wllfil'Vllfl
tJ~b1;'llUfl~lJ'W'lIi!hJ IP bwmdh
..
JCMP Message
'l:::~fl\ll3J1,ll:IJI'l(1ci\llJi
~-.j~fl\lfl\l:IJTl!hflT'JflJiifl:IJllllm::;l?1lJ
..
IP bW1Hfl\l) Ulll:::ri'l'VlfUflT'i"iltJ\ll'Wl'Ill:IJ
Nl'l'lNllllW1J'W ICMP v:::13J''omJ\ll'WiFllll-J Nl'lVW1W1'lJtJ\lfll"ici\liimJfll'Wfl"iru(FI1\11mi1l1d rn "i"il EJn'W i;J lllIWlVil;W~"ilU , iiEl l'l'VIJ
..
..
bYiElUEl\ln'W
Lili91iitJ~VI'VIJfllW11'Wm'lci\lICMP
Error
Message
l1:ilmtJ\I ckmidl
ICMP
lth ..j~l~I'l€ltJ
bEl\li'hJ\lM€I\lEllI'TEJIP dJ'W~1I.hif'Wfl5u1tJiJ\I
"
ICMP
..
..
..
Host
B uei Host
B 13J 1
Host
B v:::flfl\lff\l
ICMP Type
3 Code
~n$1El\l'jl1l1V1ICMP
blVlflbnl'll3JG'!lm'ln~\I~€In~ullltr\l
'Vl1fl13Jniimll'Vl'WWll1'nv:::vlllV1bnVl
protocol ••
~~;
~
~~
. i,.
~~--
,_"'"
-
':
;l
2 3 4
"
q,.,
~,.J
.:::II
II'"
Link Layer
tJmlu~ltiilbbm~bb'in
b{jEl\l'Vln~ltiilbbnmvhlnbbl'hml-l'W~mJu ~\lJu'l11n:ni:lQJVl11un1'iaflt'l'11
"
(bb8nmdJu'l11ll1tJbb~ndl<'1
1Vlqjb~tJ\l5ub&itJl
"
~nJil bbm~~ JiU'Vl1\lllJltli b<UW1:':: :'::'V !'I t'l'M ~\lJ'WbbEl~b~'it'l'1'W5mofru:.::.Qb~ b'Vl \11 m.hm 1id'J'W bbEl~b~11ll'tliU'Vl1\ln'V:.:: llJltlif'lJ
bbEl~b~11ll'V1b1J'WmEl~191t'l'(l]'I1~mrlll~1"I1G'1~
Message ltJ1Vi
ICMP Jwr1'W'lJ'Vl(;]Ellu
~nw~tr~V1ril~q!"lJEl.,j
ICMP ~'V:'::~fl\l
IP 'V:.::iinl'i~\j
ICMP briml1G'11bYllil"lJEl\l ,
IP dJUW1'VlU~1un1d~\I-7Jm.J~
'"
hh1~I"lEJ~'V~~(i)nl''iI"l~\li.'l~
ff~~u£nu
1 '7!(i)"Ilfl\l-7Jm,Ji.'l~b~Vnl1
.. tun
'"
(1Ul"lllaJ1'1J1"I1fJ\I
'"
UDP
'"
UDP) bWd1:'-:
"
7.1
~----~
IP datagram ------~
UDP Encapsulation
Il<1li :-----..
UDP (i)lJi1Undl--J'V:'-:f.ln Encapsulate i.'l\l1u IP (i)lWi1bbn"J~iil\lbb~(i)\l1UJl1W~ Encapsulate bUi'l 20 11J~bb'lfl'V:'-:biJU'lJEJ\I IP Header bb~:::1u1lJtil~
~ .... 'IJ 'il
"
7_11\iWb~EJ
UDP
In 1~'11un1d~dl"l~fllJilmj'umd
I
UDP dJu
"
"
H TCP
bbil'W'W~bl"l-E'UlJ1\1U"J::: b.fl'Vl~EJ1'J'V:::13JJiEJ.Jn1dI'l11l--J
'lJ
rlnJiEJ\I'lJEJ\l-7Jfll--JG'laJ1 mrnfiEm'V:.-: b~ fin 1mUd 1(i)l"lfli.'l,j bY;a Ell RVU"J:,-:ff'VlTI.fl1'W m'l~flb'!l'l-i1ill--JG'l b~, 1u nl11~
~.'lI
--
.
--
~..., "
, '.
..
-----
---------
--
'1J~
tUYl 7.2
UDP Header
d
lu~ 0-1
2-3
Source
Port Number
'Vlmmii'l'Il'l'W'Wl"IJa'ol(ll'W'VI1'ol'V1'fl"'ol'Ila~ii'l~l(illbbn"l~'W 'VI:J.Jlm~'II'l/'jD{(il'IlD'oltJPllE.J'V11\1~'l:_;dJu~'hJ
e-
ty
,d,"b
::
Destination
Port Number
oiia:J.Jii'l~l~hbbn"l:J.J ltJH''ollu
"
1516
31 8 bytes
1---------+-----------1
16-bit UDP length
_l_
data ( «1~)
'lJ!1i
4-5
UDP Length
dJ'WVJfl~~"l:::1J1'l11~ml'I1D\l ,
8 'VIl.J1Ut;'ol
'1J~
Data b~'W UDP Checksum ~'ol'11l-J~ tl'olUiill :i1 IP Checksum 'Vh'Vl'Wl~(Illl'lf1DlJI'l11l_J~n~D'ol'IlEl'ol UDP (;n~lbbml-J UDP 'l:::bln Encapsulate
6-7
"
tJ~1'W IP ~l~lUml_Jbbfl:_;
"
......
'Il'W'l:::vll'Vli1TVi
bQ'Vn:_;c;rn'lf11)1J1'l11l-Jbln~El\l"IJa-J Header IP
"
bvhtTu l'llciifldtJ1Jl'lfll-J
~{J IP ~lJilbbmmb\l'iD~1-J1~
"
1~£.,JM1-J
~l~lbbnlmbPl:::dJ'Wnflln'IlEl-J \?l"jl'ViifEJlJI'l11~rln~tJ-Jciil!J
"
IP $I{JtT'Wn1d
~Dm"lM"jl'il1iiD1J1'l11l-J~nciiD\l1'W"l:::$I1J IP Header 1flE.JHi Checksum 'lIEN IP '11~'ol'"lln'll'W~'olI"iEmvllnT.iIil"jl'<Yiifa1J1'l11:J.JrlnWiEl\l'Ila'ol UDP 1flV1~ UDP Checksum 8nV1'V1U\l
"
"
• ''iJ1~Ul1J
rep/IP
UDP Checksum
32 bit source IP address
UDP
checksum
UDP header
-*-
I
naln 1Un1'JYllrll
l'il
I
ll'iEJHi~'J1'Vt'H)1Jrnl3-J!ln(ilEl\'l~ihj
checksum vfl~'V::.;dJ'Wl'ilN~'J13-J~El\'liiEJ3-J~~'Wll'l
lb~"l::';:W'll'lu~n\?h\l'VlnmlYlll'il
'"
UDP 'V::';Ii1~l~n1Jnl"Yll
'"
16 i:l~~\'IYl3-J1'l
'"
1
2
~'Wll'l~iJ\I
Data iJl"llll~~'WUlli:l\l
l~~l3-J~'Wl~~El\l~EJ~~'l~\I
'"
fi\'lU~11'V~\l1bb~1 1Jl\1l'il1u
Header) "lln'WU"l\lVllIi11
~i:lrii~
:;
0<>1..,.
UDP ,h:J.Jl"lln
Source IP Address,
Destination IP Address, Zero, Protocol, UDP length ~\ldb~El1'11'ri1 UDP Checksum l&1Vl1nl'J
lIld1"li;'Hl1J,Jl1'Wff1U~clll'1rudlYl11J
UDP !1f1811Vl1n1'J11J-ff\l!ln~fl\l~\'I~Ul'Il\1
'"
bbi:l::.:1li:llU'Vl1\1
neln 1'Wnld~d1"lNEl1J
~EJNt'lVl~l{il
1{il~ checksum
ff\l usemn
'"
"
UDP mnVl1Jl1
checksum Error li1'11' N1ull ~lU1'I1\1vh nld~\loDEJ3-JiiltTU ba~ bb~lJJ:w rmu ~\l n~1J11.lu\'INff\l bb~fl~1\'11",
''It'ldbEl\l~Vl1 1'11'UDP 1&1iEJ11 UDP b1l'W11.ld1l1lI'1EliilVi1lJ:Ww(1udmVlbLiiI::;bia~alJJl'iiJul&1 n1'JGi\l-1U , iiEl3-Jiilbb~~::;l'1f\'lYlln:wiiflN"'Vliill",1'Wd::';~1J ql1m::;~1J 1Uff1U~El\'l
'"
"
'"
'"
IP b1lU ICMP Error Message bbtlib~iJiifl3-Jiilff\'li:i\'llliillU'Vl1\1b1naiEJ\I bb~bn\il'ii£lN\il~i;11(il UDP bfl\'l n~u lJJ:Wn1'Jvwr'W'I'!1mb~\'I1r'1'Vldl1JbbMmh\l1(il checksum
"
"
"
bll'W option
fim~iJn~'i1::;:W
checksum
"
"
"
.'
-
.. ~~
-
---
- --
---
----
.
..
--
\Jl
'..j;.!"'
,;
JJ
~-------
---~
Jj,nT'Wn1'l1i-Jl'W
1t'lmlU-JltJ'W
IP
i'I-Jl'Vf~mhw~dJ'Wo/imJ1iIl'Vhnu
UDP lt11i-.jl'W~TU1'Vfqj"'l:;Hi'lJ'Wli?1'lJfJ-J[>llMlllnJd-J~~lfllld
"
65507 1~!.JYhlt1
"
Application:
1'Wnl"J-r1J~-J1ifJd-J1iIll(f]iiI:::f1f-J llfJW'I/'j~ll'1'2i\j"'J:::MfJ\1Y'i1n1"J'iiEl\l~'W~
'IJ
mil !.Ji'I11d-J..J'll~fJ1Ih
'VI'Wltll'llld-J"'ll
'IJ
j
nlJfu-~\l1imJ1iI1
"
tilV1U~'lJU1~
~
'VI"J€Jn1"JJUff\l'1Jfl:J,-Jiilll(iJiiI:::rlJ-J'lJ€J\llbflWI"I1iIlr1'1.f'W'W'W'1fll'V'l:::MEJ\ln1'l iJl[ii!1fEJ\ln1Jl~:IJ~\l 81921uM : 1\iHJ~1'W1'V1qjmJ'l11 TCP/IP ltiHi-Jl'Wnm:::umJi)uM 64K ~.,j'Vh1'11 UDP fl<ln[>l'lJ'W1~ ltJ[iil EJ ~!.J 1 64K tK\ltT'W 1('1!.J v\'11tJ'lJ 'WI 1>I'lJ UDP EJ\l
i-
'i.J
1if):lJiiI~lUl'W'VI,j\ll'ViltT'W
IP "n!1flllmd-J1'11~lnll
IP [>llAlblm:IJBfli'WVI,j.,j~
••
&~1~~111J
repliP
rep
,
'WU'Vlrlil'W'Yl1.hd
'"I::: bl1'W1tilll
11.l')1~l'lm~1'W1:::Wi'u IP 'Yl~mbilnd:::~\1
~.
niil1n'lJiI\l11.l')11'1I'lill!l
"J::::ih1'l11ViVl11"JSl"ElUI'l11l-Jf1n~El\lbVlEJ\lbv.'Vn:::Ml\illbbm:IJU'W1i1Ul\1b~V1 1 mJn'Y
dl Elll
"
FlU-lim.J1il~l\ill 'iJ
1 ~l~lbbm:IJ)
rep
bb~1'Y:::bl1'Wl1iiil:IJl!lJ\.lbiJ'W
bYiil1r1bb'W1"1l1~\1 2 ~\lilI"'l11:IJ'I'l~iI:IJbbiil:::
"
stream ~i1iiI'l11:IJ«l-J~'W1l
1'l11l-Jfin 1M i1\1'Vl l'lf,J'lJEl·.ml1~i1G'!11b n 'iJ 'I ~nJolf.lJ:::b'1i'W.Q m,~€Iii111ahv bUI'! b11"nt1\1Fl'W (connected)
"
"
~1 £.J
rep
"
rep rep
~\l41bU'W~il\lH
IP M1W11bbndl-Jmnnl1
1 ~1~hbb1l1:IJ1'W
Nl!.!1U-~1I'.1d\l
bb ti'Wil'Wbbiil:::«:IJ~'WTIn'W~1V
lCP Services
~Mb~'W1.l,:::n11dlI'1Cl1'1JB..:J 'lJEl\lm1gimn1-1t\liiI'l11:1Jb~El1iEl
rep
.yjmh1i1..:JEl~bN:lJEl~il
1'l11:IJiibl!l"~U1J11'1'lbbiil:::1'l11:IJ~nLliEl..:J iiiia~Wi'..:Jmhd~a
HiN,J
"iiEl:IJ1;'lYl"l:::ciI ~·h'W \
"
rep
d..:J1M!.!
rep
q
"J:::bu'Wc;hrivl1f.lJ1l1'1J'W1Mb'Vll
1('1"'l:::Y111'1in111u-ff\ll1'Wiil.l'"i::::a'Vl5Jl1'1'l
bbl!l:::
'\l1b£a1im'!\lNM "ill
rep
bbt'liil:::r-rr..:J"'l::: b~£.Jnll
tee
!"1fn!:J.JtUR t'll,JFlU
UDP Yibb€l'l'l'l'l~bl'li'W"I:::dJ'WNnTvl'WMll'lJ'W1M'lJa\liimJiilYi'"l:::ci\lii
'lJ'W1Mb'Vll1('1 bbl!l:-:1:lJiJiiEl41n~~11lJb'VhVil:lJbn'W'1i'Wl~'lJEl..:J
"
UDP m\illbb1l1:IJ
(64 K)
"
"
"
rn~
~'I'll~wrl.;j
'
,:.:~.-~
~.
•• ' ,!
»; ~
~"i~!:""
-- -- ~--
'-'~~,
---
'<. :
--
,0'
---
-- -
--
b~f) bYimJnlJ'lJ'Wl~'lJtl,]-lim.Jfil
IP .fi\lf)~bmf1D{~1f.l\lL1I1~iill~T1b1~l'lili\lL~'W ~
bbf.l:::i'1r'Hil1V1rlnbb'l'J"Jm~'Wl'1 ~
TCP Segment
AU MSS [Maximum
Segment
Size)
111rnHlTl'llJ
V1
TCP ''15fl b~:W';&U ~fl 11iltlv(11tJ rmrh'l1'W ~'U'Wl 1il'!Jl'l 'lifl:lHl~'tl::: fl~ f
fll':i~'1a ~ Ll.'lLtJa j~ll.'l'l
H'fl~~~II'li'mmJTHli'lllJl'l~M
L'I1m:::"l.J~
MSS
1~Iil1JllJViil1'1'l1fl11bb
MSS
2 ~'l
fl~1Jm1m'W'!J'Wll'l~a\i1a1 lliluv(11lJi'l1
~1t~~'I'llfmj1Ja'l'lieJ:Yfl~tl'\.mr'!Jil~
Segment
f,hw!'I1~I~Hfl~l~l'li
t~l'hfi'1J
MSS
~\Ilflfl'lfl'W'i~~'l
MTU - 40
.r'WW'I 11ilUi'l1 default 'tl:::rvhfi'1J 536 'iml lP Datagram ~.;j'Yfl.JI'l1J:;l'VhfllJ 576 !1J\il~tJ !lJll1t11'r'1j1J TCP Data)
201mlt11'Yfj'lJ
~an
~1Jm
bb(;] \1hjilm,[1lEl1J 8
~h'W TCP
ufhL~1'1JlmHll'W:::'1ID\lnlla\lI'l~\ltT'W
'}J
3 4
l11u\lN'd']w~D
~
.fi\l'"l:::G;HWll'la8..JnlJ-liD 2 n~11~eJt\ln1~ilnl1[ilD1J~1Jn'V:::n81111f.ll1J1'11\1L~1fif1Jiim;lf.l TCP il checksum .fi\l'"l:::I'I'€l1JI'1ii1~-0'\I TCP Header bbiil::: TCP Data b~m1J'Wnll , 1JEl\ln'Wb'ii1:::[il11'ViiJ'mrhiim-liilyjili']~lJ'Wnn~tJ\I ~ ~ lcii~1Jiiil~fil~vhm'l;rn'ViilEl1Jn1J checksum '"I:::v1..J-litJ~filVilfi~1JbLf.l:::'V::: l~rllnldlilf)1J~1J-litJ~ii1J'W ~ ~ -litl~f.lJ'W b~D 1 V1'V11']~11JBiIi\lrllnl,d\l1 bbtl~~~ bl'1i'W1'1l\1~l U~ iii\I b~'WN~l'Il' bbf.l::: 1~1(iinn bbnL'lJ1::: wh \I1'11\1 'I11n TCP ~ bbG~b'lJ'ln!rhi'1iP\Jl~NI'l'I/IJiilll'lbnVl~'W TCP n~1J 11J u..JN'a..J ~tJ fif) biiJ'i1f)'W';i11~lcii~1J ~ Lbn1'1llill~bblii
t\:JJ'r'I1D'I11-liD1Jn~1tJ\lLbf.l:::~tmn~
••
£"i7~:::111l
TCP/I~
b.QfJ\I'Jln TCP fJlr1fJ IP 1'Unldci\lim.JG'l .fi\l IP bfJ\lm'J<J::;C1n <J'mb~'Wm~ bbG'l::;Vl1 lif ~ ~m -1im.JG'l~blf1lb'l'ldm~'WIIlJ'Uci\l~\l'lJG'llfJi'11\11'U~h'11JVillJ'ln(i1£h,1~ 'VIihvl"lJa\l TCP bda1u OJ ~ ~ -iifJ~ G'lvl vhn bJ..J'UMmJ'U'J::; u liifJ.Jth-1ia~G'lbb~G'l::; dl'W).J11Jd::; audlwl''U n
'iJ IU
1ifC1nliifJ\lL'I~1Jdru
'iJ V
ria'U'J::;ci.J11l1J.JApplication
Layer ~a
11J
Datagram J'Ublnd\l'1h~''W1Wi TCP vl1uifJJ..JG'l
OJ
'IJ
6 1
n1dci\l-11J-1ifJ~G'lWilfJ IP em'l::;iimruvlIP
"
.Jl~\lmhl-.y::;~fJ.Ji'1'J1U':h
d'J'U IP Datagram
'"
~\I
l'U'JJru::;b~rJln'W'iia~til~d\lJ'W'iJ::;MfJ\I
~
mr1~ IP 'VIG'l11iI1Ml bbn'j~~.J'J::;1tli-iifJ~till'l'jU«\I'V1~W' r1\1J'U ~ 1'Umd11Jiia~ G'li'11\1 ~1~1lJ~\I MfJ\Ibl'l~fJ~u'l'l b i'JfJfll<J'l'Wl'W'VI.Q\I b~fJ'H)11J-1ifJ~tilUtil:::dl1Jdl~ifJ~
'iJ '1.1
G'l..r.J'ljl"lr1fJu1'Wui'Jbi'JfJ{
q 'iI
"
"
1utr\lbbfJ'V'i'V'i~bl'li'W ~lU
d\lfJl'J-.y:::ii"lJ'WlIi11mU~l nfJu1 'U'VIl;'llU~ltlil bbm~n biJ'W ~\lJ'Wb ~fJiJa\l n'UnTJd.J'iifJ~G'l 1M "lJ'Ul\!11'V1qM~fJ ~l dl'Ulu'iJ'Wvh 1ifi'11\1~lU11J llJii'Vl'1-11~"m~<J'lbwu.J'V'ifJ~'Y::;dJ'Wui'Jbi'JfJ{~ b ~n'iifJ~til
IlJ
"
"
mdd\liia~G'l~\IC1n41n\!ll\il~'iJ::;fl'Ulml'l1r1vhm'jci\l'iifJ~G'llfib'l'h~r:Jlu1'u;jj
'iJ 'l.I q ..., ~
u'l'l
lCP Header
1'W TCP Header
'IJ
'J::;b~~M'Ul:::ll'~'VI~lmtil"lJ'V'ia{l'lM'U'Vll\1bbl;'l::;'VI~lmG'l"lJ'V'ifJ1l'l1lG'lIUi'11\1bb(f]
•
5'W~<J~\lbb~liia~G'lflndl'U'VIif\l~Hfl'Un11~fJL'll'j 'j::;uv'hm'li'Wnu
'I
~fJ IP Address
"lJfJ\lM'U'I'll\1bbG'l:::UG'llUVll.JnliifJ\I ..r\lrl<J:::fJ~lu
"IJ 'lI
bb~lfi'ln
'iJ
Encapsulate IP Address
IP Header
dl'UA"lJa\l
m'j~a al'jbb~G'l:::~~.J'iJ:::MfJ\!ii..r\loliB rt di l'l'lJB\lM'U'Vll\1bbl;'l :::Ul;'ll ~i'11\1iifJJ..J bin 1u ~ ~G'l~.J'iJ::; ci\l- 11J Clnvluse ~ C1nbbB'V'i'V'i~bl'li'U dlUI;'l:::LflEJV1'V1Ulvl'lJa\lbb~G'l:::Y1G'l~'U TCP Header ~ Source ii~\ld
l'Ub'il~i'U I'lil
d1J\l1~~~I;'l\l lli1uvfl11J'V'ia1l'ld-.y::;biun11
'li~i'J blfJ~
"
"
Control Proto~ol _
. ,,r::
· .."
••
'-+'
--
,_;,~,.,':,~-,<~~~f, _, '
--~-~
~---
-~--
1~fl"#i1iflltJ'YI1-Jm[!i'l"#iM'U'VI1-J
~~\I nTl~(Ilvi~ ciil!.J 1(11 mTu bU~l"l:-;Vll-Jl !.Jfi-Jbb8'fi1'fi1~bl"liuv1L Vi1J~nl'l a ~lJ'W'fiI~{(I1,r'Um~mM1i WG-Jll
iii 1 !.J'Vll'l'tT'Ub~-J 'fiI El1(11ii"l:-;b ~tJn~n
m.i1-J
"dHw!]f){Wfrfm" Vlmmfl'll'filfl{(I1~b1Jl'l
H'V:-;~'UEl~n1J
bbEl'fil'fil~ bl"li'UVi1 Vi1J~nl".i 1(11tJrfl1tJ bbEl'fil'fil~ bl'1i'Wbbvi iii :-;tJ'l:: bll'Vl"I:: ii YI:l.J1tJLfl'll'filiJ'f(l1dJ'Ul.J1 (11.i!!l'WfllYl1'1J 1 'I111'1flLEl'U\ii1$ib~!.Jn ilJ~m".i " Sequence Number : blJ'W~1;l(ij~':-;1Jfi-JYll-Jlmfl'llihi'iiJ'vttoiifil\lD-J
"
1'Un1".i~El('l"l".ioJiEll-JflbLvi "
" ,
1;l::::l"lr-JbyjEllVi~-J 2 NltJ'V::::1M1J'YI".i11J(I1".i-Jn'U11dJ'U1Jm.JiiI'lIfl-J'1Jl'l 1(11 nl".i1.1111i1 i-J1 'W"l:-:1$i1:J.i1i ::::1i'Un'U bbt'!::iiL'llfl1JV\ ~n~~\1 bdfl-J"llnn1".i&ml1joJim.Jt'l~l'U
"
TCP ,r'U~-JYll::bbiil::::,hfl1JLll'U1h'W
Lb'V'l'lnbl-J'W(Il'1'Ubflb!.J~{'lIEl-JIP ~l'lI;'l\l11i vh1VioJifll-JiilblnbbD-JElElnLbiil:::: ('l'\l1tl1'U f'11JluVil:lh 1tJ\I n'U mn1lJii"ll'lEll-JD.J'lI El\loJill.J G'Hl"l:::: 1!J f
"
Ell'V'V::::rlnvhnl".i
"
""
'iJ
"
fl"ll.JT'Jmh'WoJimm
ij,)
"l:::1Mms'lElVl\li;l::b8tJl'l1'U1JVlvlEl1t.J
"
1iVJ I;'ltiidbll'U~i'11J'WiJ'W·J:".:wil\l
'i.I
n'Ub~j.J fl :E\I
turf
Encapsulation
8.1
i<t------IP
~fJ~1ffJlJfI
t+---TCP
TCP Data
31
Header
32-bit sequence number 32-bit acknowledge 4-bit header length 16-bit TCP Checksum option (1:11 i'l) number 16-bit windows size 16-bit urgent pointer
I
20
II.
'~1:"i:t1JV
repliP
Acknowledge
Number : vll'YlWl~b'li'Ub~l!nnU
Sequence Number «t1l1'Unl,iil\lEi\lJ'UN~b~~~\I'iim.m'V::: Nril'l"'U~ b1il'lJ~'WJ..Jl ~\lltl'l'l~f)~ U1il::: UMfil'VI-rlJ ~h v~nn~l'lt'ifl eJl\lEi\ll'Unl,l?1flufub'li'Un'U
"
nlJ nl'~ahJ
"
"
b1J'U
"
"
Acknowledge tln&ifh"r\ll'U
Number n Sequence
wMh'Vl1n
Hrh
~~eNbVi~J.Jl'Vln Flag:
"
"
Segment ~ril~\I~.,jf)~tT'U
. ,,'U
~
use Hh1J'U~11'11lJl'I:J.J~\I'VI1:::nldf1JQi\l
I
A. ' . ...,.. ..... .:,;
TCP
'lIfl~1ill'lltJ
IV
"
<=>I
"
1~
"
DSH
"
"
"
Segment illtJiT\I
RST SYN
FIN l'ii1 'Unl'ib~:J.J ~'U'lI a &i ;ltflflnutJ flltl'Vll\l (
lid\! b Vimb~\ll
VitJfll tlVl1\1'Vl'illJl1tlAn1'iAl'lM
f)
rilwnE)oiu
Flag
l'W'tIru~b~tnn'Wn
1lJli'.:jl'Wl'WI?1B'Wb~~Ili'W
'tIB'lf11'i'tlB!~Bl.J~B li'W'I1~ltJ~;Jih tJ~~lJ'1l-lllifl~'l11ifBl;!rtl'WWrtr;d11.hh:::ln ~ Nrtllil"1 !l1il1lJ1~'VImtJ~dl:IJ~11'W 'lJru::~ l'il1l-l1i''Il'Wb!~1'il:::1lJiiifBl;!'i:'l ml~'il~'I~flil'lifll;! rltl ~\i11~tlfl~iLlW l;j'W'llBl;!rt~ If]~~'W!B'l iffll;jrtlwWrt ~ d'Il-l1~ ~flfil'V1'Wlill"h'H~'1mB f11rulJ'WI'hllil"1 n1~~'1l-lm~l'H1Y111il'l1:J.Jl tJ 1~ lbrl:::'illfl f11~~ TCP Header ii 'tI'WllilY1-l~ 11.11i1 J1.:jt!w~.,juiiifm.Jrll'WlJl'1VJrlii'il:::li''l1'W'VI1fl1l-lfhnlJ ifB1.J'i:'l,r'Wn'il:::f1flri.,j~.:jtlrlWll1\1 20 !~~fl ~ ~ ~
8 : TCP : Transmission
Control Protocol _
',~
-- -
-,
--
---
Window Size:
1~b{jEl-J~ln
1 'WnT;j-¥'!J-1im.J~,r'W VI1.,JN-¥m:JiEl\l
~(i)b(i):g1:J:l.J11t.ilEJAlla.J'h1'WnT;jvrn-1im.J~Yi:lJ1~ln
'IJ
"
"
TCP bb~:::vhnTj'
"
~-J~:::N-JN~1V1~E1-J~-Jo1ieJa.J~ill1~1I:JA#-J
bb~:::r:hEJfmn'V
"
mj1'Wl'11a.J(i) Urgent
"
Option:
"
option
Con_nection
ttl;;
Connection
Establishment lI~a:'Terminati'on
10.15.14.1.500 B.3 segment 1 10.15.14.2.80
Establishment
segment 2
segment 3
rieJ'WV1 TCP '1:::~lm1r:111Jci\l'iJeJl.Jtill~<:j:::MeJ\I:ilnTl~m'lJ'Wl 1Vi:il Connection bn(i)';'WriEl'W b'lJ:gUlH~:ilfl'WrnlliieJ~lEJ'lIEI\I~-J Connection H(1f\l,1 1(i)mu(i)
"
1 2 3
bA~eJ\llAtilbElU~"I:::'Vhnldci\lb'JJm:J.i'W~
,
1 'V'I1E1a.J~-JJ:::~11:l.Jlmtil'lJ~1(1f1J (ISN) 'lIEl-J(iJ'Wbfl\l bbiil:::bl!(>lSYN fllJ ACK Flag 2 n"l:::'Vllnl'l(i)eJ1J1'!Jn~1J 1'lJ 1f?'lEJn11
"
1 n"l:::l'1E11Jn~1Jlihurn1b~l.l~1
vi11ii
••
~'11:'i1:::lJlJ
rep/IP
b~tlr.h'wnT'jl;'l.1jl..:J connection
~ ~ v
vr..J3 .fful'ltl'l.mfh
I'ltludvr..:JlflG'lbtlU~U~:::b~{vhli1{ltl~£J'IJ connection Ju
bl;'liitlul1nldb~tl:JJ\9ltlCi..:Jnubl~h ~l:JJ1dnN..:J--r'IJilB:JJ~nu
"
1~ [;l~iI~"Iun':h'V:::iin1d£J~ ,
l~tJ 'irUl'ltlUVl..:J3 'l1Ul~f.Jnl1 "Three-ways handshakes" mw~ 8.4 "I:::lli!l~..:J1~~;(U1.tn'l!tru::: J:::1111\l1!J~~ 10.15.14.1 hostname.port "IlnWB{l'll1:l.Jlm~'lJ dJUn1dlll;'l[;l\l1'r11-t1u.ffUl'lBUnT'j 500 'Ylll1Ul~d'Jull'1i.ml'W[?)fl\l
N"~1\1 Connection
1~
V\I
10.15.14.1.500
10.15.14.2
10000 10.15.14.2.80
tuft
Connection
8.4
Establishment
segment 1
segment 2
segment 3
Segment2 :
1!JN"vl1 0.15.14.2 l~[;ltl'IJ-r'IJn1d SYN 'lJtl..:J10.15.14.1 1~£Jm1g..:J ff'ld'ldlrul'la'IJn~'IJltlir..:J1!J~[?) 10.15.14.1 l'1:lJ1tJb~'lJWiI{l'l 500
1!?lmolll'l TCP flag SYN usz ACK 1u TCP Header bbfl:::Hi l1mmi'l'lJ Sequence bvi1n'IJ 20000 bb~:::l1:lJlm~'lJ Acknowledge
I'lB'IJ-rllAl'lJm~B:JJ\9lB'lJB..:J1!J1i(~10.15.14.1
i1
'Vldl'IJ"hl(!i1'IJmdI'lEl1l111uil11~£Jmdg..:Jffbl!bl!lru
8:
Tep : Transmission
Contral Protocol _
., .
:":.,. .. t
~: • '-1. ~~
--
-r-
•~
--
"',
-
¥.
;_.
--
---
---
'Vltt\l'l1f1m::;1J1'1.JnTl~1'U1tl~\l
bb~1'Vl~"]"~llmr'Ur;~l:1.11'Jn b~l-.I~il~1'J1rJi l(91~n1'J&il~Tl'I::;m.n'U-lim'lbiiM'1Iil\l ~ 10.15.14.2.80 dlWrmlf1v11flVl\lt1 b~unl1 1~~#i 10.15.14.1 l!'1~#iM'WbfJ\l11riflu "active open" Nll1'rU
~-7
15~~10.15.14.2
"
11~\l~1 flf1WrU~ \l'iitl:l.JL'l1~U~G'l\l 'I::; rJiil\l'lhiU(ilD'U u ~f11'J11J-~\lo]Jfl:l.JG'l btl~EJU b~~ D'U f11'J '1.1
". 'l ~
nD(91~lmllEll-.l~
(;'1=1.
I
fim.Hh::;1111\l1~G'lbElu#in1J
t.
1il:l.Jmru:l.JfltJ 4 'lJ'UMEI'UI"lEl
v "
0::11
'"
1 2 3 4
tt.Jft
Connection
11"lG'lLElU~v11f11'Jri\l ISN 'W~E1l-.1n1J IN ACK Flag 11..!tJ\lb'il{'VIlblflf F b'il{'VIlnflfv11f11jMflu1'u b'il{vJblflfv11f11j~\l ISN bbQl::;1J1f11011 ISN
an
ISN 'I'I~fl:l.JnU FIN ACK Flag 1tla\l1~L'lbil'U#i ISN+ 1 'W1m.JnU ACK Flag server
termination
••
£'il1~::UU
TCP/IP
10.15.14.1.500
10.15.14.2.80
2000:12000 (0) ack 23000
tI1ff 8.6
Connection termination
Segment 1
FIN 1
Segment 2 Segment 3
Segment 4
f11~~
8.6 bbi:'l"(;h'l1\1b"}i'Um'iU~m·Hi1a:l.JliiB~fhJb~a-J:l.J1~1nm~~
8.3 ~1:l.J1'inilfhJ1um'i
~-J'Il1m'i~\I
iffL1!'ld1ru1vltJn1'lbllL'l TCP flag FIN 'lJil-J TCP b'1Jm:l.JU~1\1luij 'Vl:l.J1UbG'l'lJ sequence b'lhn1J 12000 11.lv\l15ff~ 'Vl:l.J1Ubfl'lJ80
ViU1E1!U1'j
10.15.14.2
~il{(il
(fI1rl?l{,HnlwhwtJim"lifN
UlJltJlfl"li1lJ ACK RFC 793
ACK
if
active
r1I'WuphhuflfllJnnlJrrdJ!J
FIN !'ifntlJlJfPlJ!J
"Iln1f'ilnlUlJI?l1lJ
ACK ilJ
~luflfmUlfo1mtfo1l?lpf'ilut'ilfll?lmrL~ilJ.wi'ilJlJ'I3.j'I;mh'Jnv!!rlfln'11fN
ACK
L'ifnllJlJliltnn?l"1::l'filvi1
!';liIiI~
1,;i1 U'lntjlili'i"
FIN
L'ifnl'-llJfPlifdJlJrrdh !"l'hdJlJ!'ifnllJl.mvli1!!rlfln"liil"
Segment 2 : 15~~
10.15.14.2 1~-ruiff'ld'ld1ru~~n1dWi\1lliiil
(FIN) n'll1n1'i
1@lff~
10.15.14.1 Segment 3 : 10.15.14.1 b'7iun'U1(PJun1'iG'/\IFIN ~1U'Vl:l.J1UbG'l'lJ sequence b'l'ilnu 23000 Segment 4 : 1Ub'1Jnb:l.JUvl3 n'll1m'iL'lil1J~1Jn~ull.l~,JtJ Acknowledge b'Vhnu 23001 ACK 'Vl:l.J1Ubiil'lJ
8:
rcp : Transmission
Control Protocol.
'!
!.
y~
10.15.14.2
10.15.14.2
ru bi'iaf'l"11-Jnl'l
l(i1']Jfl-Jf1l'l~(ill>iam~
rep
biJU b~ 1:1-J u <}-J if~nr:h rJl'lit..l'VI 'llUl1"V::;1JJ ~Hi nl'l 1 a:J.JflS\111.1n bbM'1~S~"::: U-JI'l-Jf'l"l:JJllb1-:iU ~
f)an1tJ :ij1~'YImt.JI'l11:JJ11f1l'l~flNl'l":::U~fl-J,
1ifl:JJ~b;h:JJl1~finmjl>ialtJ "Vunl111lN~fin~-J'YIit-J"V:::~-J FIN ACK b.yja']Jfl1:1~f1l'l~-Jiia:JJ~b"liunu ~ ~ ~ ~ b~fl1lJ!i r:h 1:1 l~tJl::: S-JP;<;)::; f):JJ~nu,ru Manl'l b11a:JJ>i l~uM~N a ~l\l S:JJlmu s\lii la
'lJ '"
"
lU'l:::'YI11-Jv111lNtlllii-J
FIN ACK
aflnltJbb~:::u\lllJltil-:ilJ
FIN ACK
n«lJm~Ub~t.Jnl1
Half-
i1-Jl'lruS:JJ1f~-d
1u'l:':~lJ'vmuNtJa{Mu\lI'l\l§:jat.Jl~uf1l'l~{1lf11'l']Ja\l
TCP
~-J~u
"iI:::flu1uNb11U:::
"
Half-Close
nVll:JJ
••
&"l1~:IJ1J
rep/IP
_.. . nn:il1UUDUIIOl8 ..
Packet Sniffer
"
1 mA'W'I'l1u'Vi'NnlJ
"
lAEJvnlJnl'J~nwv
"
l{m ViflLVll~).Jl
1Yl".iAlII't1~'Vi'l
..
1'l11:J.J;rlJ'lJ r:h U(ild-l"i11).JlaJ1T"11 nill,n ,:':vll'Ilflv ri u'li-ljj 'J fl'V'YI1E)'V1 fl-l nmh
"
U-ll'U1'l11:J.J~'WI'l-l'IIl-l-r"Q f
"
"
..
dlVl
"
"
1al1m'Wrnl~fl'll11
"
bbfl:::.In
1'l11:J.J
"
1 b~:J.Jb~:J.J'l1'U:J.Jlmh\ll, mJ
"
N~[i!J'Wl'lifl\l'l'll\lflll~mn,
"
"
n11111 u ~n bnM&ily.J by.JfI{m 11ifl~l\11WiNfll~'Vi'11 Vl1'l11).Jbjjfl~fl1 'W1'l11:J.JUflfll'lJltl'llfl\lflll ~f1~T:i 1'WJu bbtJtJab~n'Yldflilfl~fllil~l§l\l ~n'W':::'YIll\ll.r~(I]ri~ ~lm'Jn~'V:::
'lI
hJmn
'Vln~bfltl b~f111fll'~£)rl'ldd:':'YI11\l1~a(l]'V:::
bU'W~
..
"
lua b~nYl'Eill'l~,x'U
",
"
"I.J
al:J.Jl'Jtlfl'J:::'Vi'11Wifl~l\l111fl\llfl
tI bbfl:::til
ff-J bbilll'V:::
bU1t1tJflllvll\ll'W'lJEl\l
1 Vlfl'Ilfl\l"i1fl).Jfl~ bU'W
I'lll :J.J~1J,x'W 1Wirl'\INflfld:::'VltJ:J.JIn rm n1,{11 VlWlJEl\lfll'J~'W 'VI'Wl~bnlil'V1 nfll,(1) nw" 'VI.iAlII't1mm!n " bllldl:::EV1\llJflU~Il~iifl).Jfl~iil'W'VI'W11
" 'U
"
'U
· .....
~"'"
~
--_
-
--
--
Bn ~\lmj\lml1JrJ
"
lb~:::1aJ il1'111:J.Jdl~q)
"
bbl'1ieJ:J.J~~~eJ~11 ilia~
"
1ub U(lll11mi'W
~'YI~1
btJl'IlNEJl'1mnl'lb~EJ bbl'1-41dJ'W(lifl\l~f)al1if):J.J~
9 ~
b'YI~l,x'W11JU'WbU(lll11n
b'll'W1'111:'1~h'W~N1i(lif).J bflU
OJ
dJ'W1'l11:J.J~U~~1'I lL~ fl(lif)'l'tJf)'Wif):J.J~ lil h11 'W1'I~mvh It.w1" b~fl b-ih1tJ1 i\Jl'W ,x'Wfl'l':::(lirJ\lflmi\l ~\l11JU'Wl'Ij(lll11m
"
use b~flifl:J.J~flnff\l1t1u'W
OJ OJ
ll'lfl1bl~:::n11~aaldiflm'l~h'W
hliln~1'i1ilif):l.H'l~bUt.l.fn1:J.J~mnniimJb'Vh
"
l1vibl'ltl l1:J.J1m~'lJ
bbfhimJml1~lJ'Wnnff\l11J1J'WbW(I1
OJ OJ
blin
"
,.r\l'YImmtil'IllrI'l1bl'l"j~(iJ,
uruil, l1mm~'lJlIj:::~1!ill1h:::'lJl'lJU,
"
1Y1t'l'f,h'W. 'I'~ll1mtl1n, .
oX 'I :Jf ~,,".. '"0 1 ~. " " ~ •• I •• 1" ,. bUfl'Yl1b'WlJ'VIU"I:::'l!'11 b'YI'Wt:I\lfl\lflu1:::nfllJ bli;il:::n~mn11'Vl1\l1'W'lla\l bb'Wnbnl'lff'Wnbl~a111l.Jt:I\l b
n1:::VI1n11 1 'W~n'Mru:::WI\lmh]
a~l-.jiifl£J~G'll'll~f) ,
1"11V1lu'W'lla\l'Vl1\l1'Wm1#ai;'!11~\lViLiJ'Wfl11:J.J~1Jdll'\'q)
OJ "
Iurrn
Q\Ju:J1111 'Wfft111:::1Jntfia1"l"l:::man1(;'l
tl 1l'Wfl'YI:J.JUii\l1'l11:IJ b~ £J-J'llf)-.jm,&a 1
"
a~ilJs:niluuilaa(iunUJQS:
"I~\l'1bb~1~h11 Associates Sniffer ,x'WdJ'Wbl'l~El\l'YIJ,J1Ul'll\lm,~h7i\l"lI'l'VI:::lij£JuH'[(ll£J11~Hl'l Sniffer Network Analyzer /l1'!ilnDl'W'lifl:J.J~~\ll1lJ <J lLl'1b,j fl\l"lln~i'111buuvi
<J
Inc.l'\..1t'l'l11:i,i
L~a1o/i1uN~(llnru1i'lJfl\l(ll'\..lLfl\l£B
1t'1 tlf)lA£J
hJl'lllJ 111jl(lll'laG'l~i\llun'Wa~
m"lil~'W
"
lih 1"1n'W11 ffDvJ lvJ fl1 bUU bfl~fl\li'itJViWln fil'W"iifllJ ~1J'WbWI'Ib11n ~\l'VI1 n'V::: b1EJn1Vinn(il a\l bb~l fltJn,ru1l1:::bf11'1111'l11"l:::b1un11 , Wire Tapping Device bb~b~flbuu~L"iilhn'Wlb~::: b1EJn'1J1'Wn'l.!bb'W"iYlmEJlb~1 Yl'U\l&tJb~:IJ;1n'V:::l1unrJlIn,ru'li{jl'ld11ml~bvJiJ{b'll'WL~EJ1n'W , (;'l{jl'JbvJai~"I:::all-11'f.lvll"1'\..11$iJ'\..I'V:::~fl\lilEl\lrllll:::nfl1J~U:i1'W 4 ti1'W~tJ Dl'W«q)q)lru"llm UJ)1b11m"iil
Hardware Yll-I1EJfi\l~lImrufiL~n'VI'j"ilill'l~tlil\l'1Vial:1J1jf.lWln
:J.Jl1~ us :::G'll:1J11f.l'111 q)lruVil$i ff\l ~ a1t11J"j:::m~ ..m rJBnm bu'Wifl~~'Vll-.jl'lfl:J.JVJ1 bJ)1fl-n~ «q) ilYlii1viYl~n~fl~I'I/l11 nlJ/l11-ru-iitJ~~ n1dbbn1 'lJ"iiflNt'I'Wtill t'I'lifl\lWnmnru
•• A."1~g;llll
--
qnunumu
EJ~111JMi
fJb WJ)1liniJ::: b
rep/IP
2 3
Driver d"Jw1u'mn"J:lJd~viiJ~1\l~Y'l11JY'l:lJn11~n-iimJfl'lJB"~1{l'lbnftin:lJiiEl
ffruru1ruVi1Wi'ii1n !nfl'l
--
"
1 LLfl~l,h
u Tflu
"
"
n lIllnmd'lhilm;JlIl'iil
-iitl:lJlIl'lJD\lG'ltl1N1NElf,rUl1'ii:::: iil"lml1.1~n-7J El:lJ b iillWiAl1:lJ b '11 '1 b'l'll 1[i) Vll n m!":lJ1un11'!.h 11iil"\liil"~ cu 'U oiiD:lJ1illubnmtJu ltJmh\li.'i1oEl
Y]Ubblll~tiiD\lU~EluoiiD:lJlIl,ruv1\1hJ
"
"
"
"
Software bYlD'l'hVlW1~~l'lnlloiiD:lJ1ilVi1M1Jboii1mll'lun11tJl~m1ilN1illll1:lJl(1ll.l1h::::G'I\l~'1JD\l
"
nll&iml1u-ii
mJ1il,ru b ilB"'ii1
""
n-7JEl:lJ1il~uYi~mh'W~uml~,ru""
"
..
"
" "
"
"
oE
1 1
"
rrrsuun
bwdl
btJUn11
l1'liil~l'l
"
" iln&i
ltJ bb1J1JYial:lJ1il.lb-iil1'iilWimn~'W
"
-"
",
U 1.Jiil"'W 1",,':hbtJu
'iiD:lJ1.'l'lJD\l1!'1iil"~l'l
"
lWi:lJlni1DtJ'1JU1(illV1u~'WEJYIl1Ji'l11:lJ iil"lml1.11unl1~~flWib'W~ni'1JEl\llu1bbn'J:lJ,r'W ~~1Il&i bw~n'll1t1f'V'Wii\l1Ui 1l:lJ~\lVl1 niimd~ nll~Diill'J lt1f~~u ll'li'lEl1il biilbUDfviiil\lb'lfU
"
b w~
ni bbI;~ln""~EJu1'W'JtJYiG'll:lJ1il.lb-7Jlh
"" "
'1
VllnG'll:lJl'Jl.l
hlWi~ltJ~u
l'lnl1 uu n bW::::VI:lJl'lVl~'lJ€I\l m1~ €Iiil"1I'll €I\lbbM1il l ~11m (;]n'V~ b Vlu i'l11:lJ ~ B b El\l'lJ il B\l mtJ1 bLnd:lJaDvJ bWDf1Jl\ltJ1~
"
bfli'lYiWiEl\ln11~nVll-iiEl:lJ
b""l::::'l..J b'lfu(liD\ln1'J~mQyn::::n1'J
"
1iflNH1nlJJ'I1ii1~1'W 1111 '.1i\ll'W nm"" l~a'W hVi'l::::~~flWib 'W~ni'iiB:lJ1;'l~\lVl:lJl'lmWi 1l'ltJ'V::::vhn1'J~u'I11 bbrl pattern 'lJEl\lnl'J Login bb1.'l:::: Authenticate u ~1
"
b'Vh,r'W'WEJn""lnrnl:lJiil1:lJ1df.l1umi~~fl&ibw~ni
"
lWi1il\llul
i1'W~luoiifl:lJlIl "
iilUW b WD1"1~ (ifD\lI"lDtJ~ n-7JmJ1Il~b 'ii1:IJ1 iJUl'l ~f1m 11111 VI1n'V11m1~hT~ bl1J1J1tJfl1 'Yl~fI1'V'V111 l Ylnl1'V11\llU'lW\laUW
..
Vlru'V::::iiVl\l ~
niu nl1'V11\llU
"
"
b wdihh~
~i'lBm'W1ill'l~l1;'l\l
"
-iifl~iil,rU"" ~fI1l'1tJY'l11:lJ(;)iJ iliJ\l b b 1iEl:lJ tJ\ln'W'1Jfl\lVl1il1 1 U'1bb-wn lnlll niJ111n1Jn11~~1.'l&i b 'W~nifl'lu 'V!":fll :lJ11 1.1 'J!":'1'111 n Wi ~~~~ bw~nibbuu
b~1J~ 1'Yl~~\liiI'l11:lJ~\ltJlmnn
m1wl1Nilffl'lU
"
U n 1 'l 'V11
1'V1qj~..J'V11n1"nuoiiEl:!;llll~1J l1rifl'W
.. 7~
. ,,,.-_
~-
,
~ !:~.~
-
------
n bl'l~tl-J
I'lm.dh
b~1f){~ uuu
b'l'm::; ~:nf~ bb1'f~ 'linlJflEid-lliil bl'm1 b>'itlnTi~tlfll"j'iiil:J.Jfll ~ 'WbU~ b~Hmr'W 1~ nnnan ~ m':i~tlflwl1tl~fl~fl~u1fu-1im..! us ::;jj'il!~ni'UtJ1~ ~1'W~fl'1lJ1':itl'l11d-l1 dJ'WflUvJbvJtl{
~ ojjbV'l~il~r1m.Jlii1 b{;lil1v\'11UvlTr'liJl~
11d-lrr",mrn
"
bU {;lbi{n EI ~ bfll-lil bbfl:::m':i'W!.J1 !.Jl:J.Jvll1 Vibfl~iJ"'flEl:J.JYll b{;lil1'lJEl\l b 'VI~iln G'l1!.Jl.l1biJ'Ufl'u'V'JbvJtl{nlYn'"l::; dJ'UdJl'V1l.l1!.J u ':in'1'lJEl~ unn bntl1'Y1~~'"Ilm
"
iilltJ1j~I'l':iil"'bl'l~D\llcililb
ti1'U 1cil'"llnffu'I'J b'l'JilfltJ dJ'Wb1J1::: ufll urrrn '"II::: biill1..lu\I bl'l~El\l~'W '1t9lil11l bf1~El\l fl Ell-Iliil b(;1iJ1 dJ'U .n{~u l{~ij Ul-J'I11l-J1 b1J'WG'l'u'I'J b 'I'Jil{lJ1n~ 'YIln:ijm{~ G'l'~ Ut9ln1lJ~1
G'l'u'I'JbvJEl1'"1::;1iil\lvll..:11'Wmju'W bfl~El\ll'1tll-JoW'1bvlEJ1bvhtl'U (
trru ruin! bbiil::;U1::;:).J1fl r-m'ii 0:lJfl~ 0 ~U'U bU(i\bi1n l(1in G'l'1 3-.111 '111l.l1vll b1J'Um.1'I'J bvJEl{l~ b'li'Ub~!.J1 n'U rl
.... .... 'lJ 'i.J
"
uTf~'U ~G'l'1d-Jl':itlvll'V1ih~~I'U
b1J'U~
b'li'WEJ1'"1'"1::;i1fl~tl-JiJtl b
buvn:::~tlilnb6lJlJWl
L>'iElLU'Ufil"ih-Jb'l'JiJf[~ tlG'l'll,Jl':if.l&l'mh'UiiD:J.Jiill~V1'WVi~
"
n1S11l1.l1UUiliC1UulluJDS
nl':i~ fl'u'I'J L'l'JEl{fl'IlJ1,Cl&l'n ~1'U'ii E1l-J 'l~El~U'UbU(i\ bl1n 1~,r'Wi1 fl'lb'VI(i\~ilAru~ G
'll 'iJ
~n'jojn!::;'lJil..:l1th 1(i\I'lElG'lflbfiil{b u(i\~H'VI~nm1m:::'"IltJ'lJtl..:l'iitll-JG'llua-JV1n Em! tJ1[lfl'~ bbt9i 'l::: G vl'1vll'Y1ii 1~~1 u'Unm'&DG'l'W1J0..:1 &ilG'l'l'~n'W,r'U l~rln~\llllv\lV1n
"
'"
a ~ltJ
1[lfl'~~Eltl1'Wbu(i\bl{mbG'l:::
...
'"
d'1 !i1~1'li
"
1cilil~l\1tln~il..:ltl'U
"
1[lfl'~ Ut9lf'l:::vld'"l:'::~0..:1jjm:'::tJ1'Wm':i~fl'1l,Jl1b1~1(1i"hiiEll-l
..
..
"
f'lbb¥I n bn!i11l'lbu'U'lJil..:l
MAC Address '"I:':: U'W'YI:lJltJLfl'lJb::l'l'\lI::':~Id-J!.lI{(1)bn1Vln'1lU(1)~-1im'&Elfl'I,1(1)tJ b , fl bfiiJfbU(;1 bbG'l::': 1'W'VI1..:1 VH)'jojflbbl~hm1(1)bb'1{'I'ln'1lu!i1'l:.::1lJiJ Address '"I:::Cln ril'Y1'W(1)!i11tlvldilrJ1'U ROM '1JV\l!n{(1) u 11 bbG'l::': fl'1lJ1,mll 1lJ
1u':i 1(;1flilG'l
"
11'1b'VIUtll'ldll-1 fl'13-.11':itl'lJEI\ll-J'W'MEJb~Dm.j'jo}EJffl:lJl'lrlril'Y1'W(1) , ,
Address lcil :J.J'U'jo}EJn~Ell-J'"I:::all-11':im1J~u'Ubb1..lG'l..:ll(1i b'li'Un'U 1i..:l'"l:::ElTItJ1U 1'W1Eln1fl't9lEllu , n1':i 1'li..:ll'W'lJiJ\I~1{{;)bbd{"l:'::~eJ..:Ifld1J~n1J '"I::.:~nril'Y1'W{;) lVilllju&iml-J • • 1(1)':ib1 Elf'lJ eJ..:Il1{{;) u '11,r'W'11(1)!.Jun&ibb~11(1)':iblil{ [
1YifuoJjil:J.Ja~iJ
"
1Yi~..:IoJjild-JfllI'HJ
"
H'
"" "
Wi~ 3-.11u n
e:Jl{ (1) '1{ u~'1 bfl ~iJ\l1'l il d-JoWd{;lil1n"l :'::vll \11 'Wil ~1 'W u b
tln1Jii0:lJfl'lJiJ"'N~'W
""
"
hJ'l
IIn'll-J 1.11::::
ltl 'VlVlti\ll vi lJ'W ~ vi TVIi11~~ (Ol fj'u nTl ~il fll 111il3Jfl1'W"J:::: ~l'1lil\l !111(OlLll 1 fj'u nT~ ~U ~\lJ'W~\I iihh~fl\llbtJ~ mnn'V:::: n11'l"J~nl"l'W biitl'W1(Oldb1 fl1~m.Jl hnJll'lti 1~:i1
MAC Address
'l::::lJlJlJi]u&!nld
"
'lJfl'ihnl'llilll-JhhlMl"lilfl
9
l(OltllQ'I'n::::l'lrua3Ju&1~l'11fu'lJm.JflbQ'v\Il::::~:i1
d'J'W'lJfl\l
"
Vllnalm;~Nl'W'lJB'I11j.JiJll.J1Jin"l::::'VhlMlJ'lJfl3Ji'l
(Pro~~scuous Mode)
~Tli?11bl'hh'W'lJfl:lJi'l~U~\l'Vl:lJ(OlU'Wl U(I]l~Hnlilm
"I:::: J'W'llB\l11'l"J Qf\ll'111I'l"Jblrl::::dJ'Wm'lf1::::bii(OloJjilu\l~u'lJEl\lll.J"Jlli1I'lEli'l'Vl1Elll-l d bbti'WEl'Wll nl,"I'lI\lI'W 1'W1'v\1'liiaI'l5a h'l:lJl'l11'W bii'W~\l~mb'V!i'l:lJ ~ ElI'l11:lJUi'lfl >'Ilftl NN~(I] ~lf>'l bbl'lvY-J'Vli'lltJ~\lN~(I]l>'1dbli)'rvil~al~l'lJ;1"1'll\ll'W lmJ~alj.Jl'lCl'Vll\ll'W
9
"
El1"t'1:::: 1l'ltlm,~(Olbbui'l\l'YI1miiuA'Wm
ii1'lil~fl\lr;.j1'l1~fJ bll'iiJ~l\lll'l
bbf.l:::: l~ilalj.JTmrhm.l'll
b~il\l~'W '1n1~1'1lb 1El\ll 'YIqj ll-l 11 'Y:': biJ'W lU1bbn"J3JllI'l11:,:"HiEl~ 11ilj.Jf'! ,g\llii'W~\l~l'lll'J'W~'W lei!ll-lmn
1l-l1'1i b~€I\1Uln lU'W0 n ~illtJ i:Jl1hbbn'l3J~'Vll 1Vibl'l~€I\1I'l€l3JVIll blil €I1fi'l'll-Ji?11mnU dJ'WauwbvJfl1 bNtJu 'v\I1il~vf'1hI ll'ltJ\I bl~v1r'i/&1(fJ~\llu·mn1j.J dh1tl bba::::b11'Jn~'W:lJl'Vll\11'Wnalj.Jl,~~mjl'W'lJilj.Ja
~ '3.J
"
i'J"I"Iu'Wm1"1::::vlI1Vibl'l~B\lI'lBl-Jvhblil€lfbl'l~fl\ll!illii'WailyJ
'1Ifl\lI'l'W~'W lulJlvf'l
rnl 1::::m 1V1ti\l'WEln'Vl nitm!fru:::m'l1l'J:;"II tJ1Jil3Ji'l'IIil\lll.J'lllilI'lila bl~l ~\l~ ~ " 'Vll1 Vil:'lilvJbyJilfflll-Jl'bI~mh'W'lJElj.Ja'lJiI\l N~'W1M~Elnl'l1 'i/$fl nf11\l'll€l\l bUlill ~Hn11j.Jn'W 1~11 " " lVll'v\1hd 1OBaseT. 10Base5. 100BaseTx fil'Wlb~llbl'iloE~flnal\ll'WnldflJQ/\l1Jilj.Ji!l11Wl'W
tl'V~m:h~ru
,x'WVll-J11'J1'l11:Wlll Ulil b ~Hn €I:':bb!illJbl'l€I1~ 11i€ll-J~ Ell(Ol l'l1\ltllJ ~Eln al\l bWi U tJ1tl'W ~Ell-J ciiflJ'lJEl3J i!l 1 m:i1 nu n'Wue :;vf'l1i\ltl'W b~ Eltl":!:::n ElU b 1Jl tllJiff m~ru::::'11El\lll.J'll(;] I'lilrl bb~'v111 ViiIIilyJ bvJilftcii1 oE -liflunW1il\ll 'W~h'Wd~niil'WoJjm.Ja'lJEl" l~a(il~IfiEl a ~u'W~Elni'll\llWitJ1n'W
'lJ '"
"
"
1m'WYI'WYI 1'V:;~niil'W m
n'W~l bEl\l vct El\l"ll n
nl'~'iI:':
b'Vh11'W 1i\lbbi111tlI'l11m&1'J\l~\l
n~11mjNHn:i1'Vll\ll~Elni1EltJ3Jln~'VdJ€I\l
lJfUU1\llii'W 1l.J1Ji 1J1nVl~ElEl1"1'V::::fl\li!l\l'Vl'W m"JVI~n b§tJ\ll!il tJn1":!1l-l1-li\lI'WndJ'W~-J~ btl'W ~ ill\l ll.Jll-llcii ~\lJ'W ~1":!1 i\ll'W 11l-Jtl'W'lJil\l ~fl n f11\ltll ffqJ~l ru~\l iJ\lI'l\l:i1El~1(Ol vf'lltl u I'l\ll?i Namj ~lill3JEl r1\lbbirll'V ::::ll-lfllm,~"I'llm,&ln 1'l'W Ml In u f1:-;nl1~n iil'W'liEl~ a nu\l iil'W'lJEl3Jf1'i11m:-;tJ:::nflYll~El ~lJ'Wl:'ll ~ bWimn'Wlei! l ~ ~ bblill(Ol tJann bb~l n~n l1J'W1J:i1il'lJEl\lI'l'W -Ii bUl'll11n b~l'Jl tl'W,r'WbEl\l V11m.TlJbii'Wlftl n'il::::ltlWltl l-J1'i11n ~1 b'li'WEll'illtl'Wbvi H'W113J\ll'W'Vl:SElwtTn\lI'W 1'WU~NVllWi ~ltl'W LlJ'WLli'W
.-.
.~
~~.£,. . -------....
_ ..,
._ .,.,,·.::rP~-'-
z1i~ 9.1
1l,"W"hflfJ"m~ !'1I'JI!.1'J1fJ"
9
•
---
---
~iJy-l!rlfJf
Host
, ....
: III
,6st D ,# ,
Q
_
-<,0
Process
~m
To Host B
HH,h
------------~
ol
-I'
To Host B
Host
~l
Ill'
Record
~I
il
Dil'
.... :
Sniffer
.JJ,.
mJ 4 (i'f1(i]t)'n:J.JnULDtm"lvlbl{nhwH~1J·hwlu U[iI:;l1 " 1fJfl~8n 1'1'1'V1it..]ofi,rru111'HLm:J.J~l'l1'V1':J1~ ,Dufl"uvh Wf){ bvl f) I'1'mhuoVD:J.J [iIb~ V1J(i]D~l:J.JD ~1 'W~1JJu " "
lwmw~
9.1
1udhHl1'nl1
Host
b'11Ub~VlnU
<iJlnt11'i'F~:;UflV1..]1Vib14'Wn11Wi:;<iJlt1"1JD,,]oVD:J.J[iI~
tI
Host
A tiiD..]nl'~\l1'11
Host
B ii\l
h~ b~Diliifll;F~
"
"
bdD1~-r1Jiim..Ji;'ln<iJ:;(il'Tvflfl1J bblil:;
ihvnrhbD'Wiia:J.J[iI~~-J:J.J1'V11
au bD\In'OJ:::l'l1 mnhu
::::J.Jllil~ a
"
•
•
Host C
Host D
bda 1~l'llm,(ilJl<iJiil"DU
bmhJu111tJ':;:J.Jl[i1Nlil~'W1(;18n
Sniffer
1iU~D 1JJiil"u lv'hiiD:J.Jlilvh-1h:J.J1JUbDu"1JD\l1~, fl"'I1wb'V'JEl{'OJ:;-ruiiD:J.JIiI~\I'VI:J.J(;1bbl1ilt.h " " 1tJ bn1J1utrw bwaf us :::~i1U'liEl:J.J bvlmll1tJl1.::::J.Jliii NlilbViD'VI1iitl:J.Jlil~ill1,:; 1mf'l1(i]D 111 iii ~ " " <iJln blJ(i1blin 1 Ut11'WJU'VIlnf'l'l1'I'J b'l'Jaffi n&i\?1 Ulih u 'VIti"]~-J mhl n<iJ:;l'l11 r1iifl:J.Jt'<~\l'VI:J.JV1 ~\l1 ~ " vn~fl~~"] 4 ~Elfll'in'W 1V1t1Nl'W~lJYi1i\llU'h:J.Jnu 1JJ11iiD:J.Jlil1V1<iJ:::tl'lnll~!YlJnfll:J.J1'11,Hln~mhu ~ ~ ~ 1WJ[I'lElf'lUV'JbWD{VlUVI1(i1Elffi1'!fl~~\l 4 1lJ.1h:; bb~:;'i:;rnv 1V1'1bliltl';i1iiEl:J.Jlil~~-J 1tJ'V:;fln~mjlu " ~ ~
"
1 'W'iijfl"~f)iil"1 'VI:J.JV1
"
••
'~,:'j:-1J1J
TCP/IP
JlEH'Illl"ll :lJEl'Ub tlEl\l:!J1'Vl11fll.fJ , u ~ :';[ii,1"1ii1'EllJ lJl tnn bil [ii b l1n ~\I:i:i1Elll1 ff'!h)EJlJln~'V:.;
btl El\l"ll1111l"l:i:iailw
'1 FlU
bl'UbftEJbbt>lll'V:'; b"illltlti1jl'VffEllJ
"
bWEl{m&i~~\llu
hi
bbt>lbVlEl-rtlll:ltl,:::ff\l~~ uuunu
bb~:.;1~vN:i:iEllf'l"i
Ut>ll1Lb'Ud ii:IJlll~tlj:.;a\lrl~mh\l 1
t>lElnT';itlljl'V anu bb~:::i:JtJ\lFl'U ~\I:Ij fllj'l11lJ 1'U'l:.;&i'u r:i14i:i:Jl'11 j:';vll fll,&i'\lmhl n ., 'V:.;rilVl'U~dJ'U-1JEl'l11lJ l'U'U 1EJlJ1EJI"l11lJtlmJVlJlEJ1~w 1o}i\llU Vllnl1fllj(;ldl'V'V'I1Jn'Vdlfll,~\l1
bml:.;iiElJ.Jiilal:!J1'l:lf.1n&i'nell'Ubb~:';biil
"
.,
"
1"11JI ath \I
bU(;Ibr.JEJVIllliiEllJfil~l"lll:IJlilr1rum 'lJ
n V'l1d"l:::
rllll.Ja:::1'11n~lEJ
3 4
mnilrrrs
l'ii~E1ffr]dr]dlru11lJnull1iiElEJ~~1'1 'I'Ilflt.hmbtl~EJ'Unu
il'V~uu
Switch) :Ij'lll"lllJ.J~\I:lJln .,
jj'j"'j"l.J(;11) ~m"ii\ll'Ull~
"
'<i):::'lilEJfil;1V'llllJ L~EJ\I'lIEI\lfl1jf.1n#fnell'Uiill:IJfil1J1:IJln (
.,,,
"
m n al:lJl,fJ Hi\ll'U
.,
.,
1'11b-iJ'l1"11(lltI'1EJ~lEJ
'I'Iln:ljmj~€lal.onflJ.Jfilmv .,
1'WEl\lrlml(;1m.h'UEl'Ubtll1l1bilti1
"
Network Analyzer
m'lVi&(j'V'hvJB{fl"l~l'lrl(i)niiBlJiil~~'VIl-JflViiJo~1JULi1~
bl{n1~ 'Vll1Vi
SMTP,
L alm1tl1111iEll-J~ lil~miTll,ll'''llm11h::;mflNfllll"l'l1::;'I11'l 11
"
L'liU HTIP,
'V:::yh1Viffll,11'lrl l1iill~l~'1
"
""
1UlJl~I'1~\ln11'V11fflbVl~fl11j.J~Iil1.ln~'lJ0~bbO'l"l'l"lmll'1'l1U~l\1'1
" 9
uut tllil ll1n'il:::th!'l1 Vin11l lI'111:::'11biil::: 'lJ1JqJ'VIlffl~11r1~1 LilUn111~£J ~1~11 (;11111G'l::: b ufi1 ~
(;11\l~£J1JqJ'VI11fil-.J1n.:gu(;1!'I1Q'I"l1::mruViiim11-11 11'l1miJ 01m:::(i)u bi1(;11linm 1~!'IliiEl~ 1 : 1'li'WiJn1jd~ojj£JlJm-h'W1~f1ElG'l~bL~lii1Jq,J'VI1 Vl1£Jn11'VHi1ff£JlJ CL A
'IlE1~
L Ll'lil1 dJu~u ,1
61'111:::'11(;1
1bfll 01'V'V:::~fl\l1oJl1fllU1Uj.Jlnnl1Vi'il:::
b1n1tJ1JqJ'VI11fi
Packet Monitoring
n11~nl!llWll'1ilfl'1JEI~ 11J11(;1I'lElfl1'Wj::;lillJl{j(;111{n41l1h..!AEI~11U l
iim.JI;'lVi~mn1nu
"
bl'l~£J\liJElVi1.hbWmn(i1l-Jl blff(;1\11 i0id1'111'1131.l11UU(1]l\1'11~ Iillil~l\1b'lh.l blwmn(i1Vi1lff(i1\1 V 1'II'V1'1J..l b~l,Id.fi\l us Iil \11VibiT'llL t'lfl 'Yll'1ill'l l1& Lbn'll~l\1'1'1Jil\lusn n IlljYlI\I 1'W'lIE1~ Vl mnl'l~E1ih(IJEl1~\I Vlln'llllill1Jjbln1~1Jj::; u 1oE1um,FinMlhhl()ll'lm>l1fi~
in D{~lULb~h
b1~1~m,{ln
1:::uum1'V~lJfl111..Jn1nMl~u.:!1'11m'il1nn11(i)nrilu
'lJ "l
n1n b'ihnlJIll1Iilmh'l!'irilj.J~lJU
'i 'fJ
UDn'illnd~ilvJb'V>lD{if\lff1m1r1'l1111.ltJ1:::~nfltoJ11.l1'11\1IU1nl!ll
A11 j.J1.I D (;1ntJil£11\1 11-.:I'1I 1\1 b'li'W ~ n 1 l~DlJ'WVin~E1\11E1 tJ'lJil\lLl!'Jmnil{ ~lJ(i11l!Fll1 1oJ\ll'11 V1'wmm~iJI'1111.nil ~ qJ. V1lilffElUl'111l,1 u "j..j'1JEI~1 bb1J...1 'V>I11Diil b1J'W~'W ~
••
'~1~~1J1J
TCP/IP
nl'j"1nl!llI'111).J1..l
utii-k"n-k,nXtJnl'i'i.11:J.J1'i'1.l'l11l-J1
"
b'ii1 hu 'fl::':~lm'i'1.l1bl'1'i'I::-'I1ii
"
'"
"
" " uil ~"ii£l).J ~Vi1~v 1 nauw b'V>l£J~ bfll?ltl'i'::': 1'J"llUJu ii~'U £J~ fllJ'VInl!l::-uae 1'111:J..1 Vi 1 all-J1'i'1.l'1l£J" Nt iib£J\l " " "
n1'i' 1~1U~tl"
Il-J~ l& 1'1'11 1'U~ mi1'Uii fl"
£I:I.Ji'l'1l£J"~UWbwB~JU
";11 nl'i'& a al 'i'1J1..1 b~{;I,11nYi{;l1 ul ~1'11 B"J..JUl!I6loJ t'il:J..11'i'1.l:J..IfJ" ,tl'W1~J'W:lJ1~ii 1'111).JtI~ B{;Illl'JfJ~1"Yi , fi{;l n1'i'Yi"iim.mmJ1 'U'i'tJbl1J1J'1I£J"~b~n'Vl'i'fJil,I'1~BW'l::.:'lill'J 111iiI'111:J.m::.:vnna::':1J11'1 1'Wn1'i'1ii"IU a n~l'Wl1l1" n1'i'Vi1oJ al:J..11'i'1.l).Jfl" btl'U1WiJ'Uvh 111l'J1n tii £In1'i'ilfl" flU 1nl!l1ii fJ:J..I rl":lEJ ~111 "11nn1'i'~l"~::': b:IJ{;I'lI ~a'U 1Wi l~'i'I::': nl'i'n'i'::':Vl1 fJ"
(1(" n ~11n
"
""
"
~ UP!
"
::':'i'fJ{;IYJ'W
1 1 1'111:I.Jl~I'J"bbi'l::':f.oJ~m::':'Vl1J1PI£JN1iinii:J.J1n~'U
"
9:
IPi'mi"'luim;!<uii""JtJ
Packet Sniffer
.1
___
)&.1UlllUnlnn
lEI:
lEI:
hhund:J.JVivllmllVi
"
Lb~(iI\l,r'Wn1~1l1
rfl:J.Jldbl1l1:J.J1L~ml(i11~()11:J.J b~a'Wl'1J!'il\l'lVim-ilfl"'W
""
h1~
"
11 Ut'l:::
"
1 urrrs
b~al 'I1~1:J.Jldbl'l'ilAl1:J.JLil
hfi\lifJ:J.J~Vi1l1
[.,sIn·Daa TCPIIP
Timestamp Source Host.Port > Destination .Port Flags Beginning Sq:Ending Sq Bytes Options
1~
't.nVi :
ifl~~ViiJ':iln~'V:::iJ':i:::nfl1J~ltJ~t'l~fi1\ld Timestamp: bW~hHl~T~ilM1JuVlmn()1d 1'W1l1. LfI'loJ'1Jfl\l1'W1Vi Source Host: Ufl"?l\l IP Address ~'W'VI1\l'lJfl\lLLVlmni'l fl"l:J.JTlmbfl"t'1\ll~biJ'W 2 U1J1J~fl IP Address ll'1tJl9ld\l b'li'Wl'W~lflrJl\l~fl 'Vl1nfl"l:J.JldbILLUf'l\l IP LiJ'W~flleJ~~~n'J::: WllflrJl\lmdVlt'1~ 2
~f)
bb~~hHiJ'W'YI't.btJ il1:J.J\l :
10.15.14.1 'I1~a
1!'!fl"~M'W'VI1\l~D hacker.com
Port :
LU'llihW!).J1EJbiil'IJ'lJEl" TCP V>l0{tll~U'Vll,,'hihJV>lEl{tl1'YlmEJbfl'lJ 1l'1 ~lmlmL~tl1..jl~ 1J~n11).Jl()ld:ilU 2 U1J1J~0 'Ylm!JLfl'lJV>l0{tlldlV1-r1JV>l0{tlliil •.J1'li LLG'l::.fimJ0\11J~md'YllnmnEJLi;'l'lJV>lflf()ltTwuu HTTP, SMTP, ECHO,
tlfll!JVll\1 Flags: Lb~l'I" TCP Flag ~mV>l~m,Jn1Jbbwmn()ld tl11;.,JTCP Flag ~iimj~B ~..jfllmdmb~WI,,('1l1~
"
FIN, P
Push, U
Urgent, R
Reset
'YlmmG'l'lJ Initial Sequence Number (ISN) ~..j TCP 1'il'hmTl Y'l11Jf1;.,Jn11~D~1'J~..j 1u"J:;'Yl'h" , ~lm"JfI Ending Sequence Number: 'I1m!JLt'l'lJ ISN 1l1nn1J'lIU11'l'lJeJ"-i1D;.,Jt'l~a,,
'U
b.fiD).J~eJ
1~ use bb~1
b~J.Ja"o}jfl;.,Jt'l
"
bV;mu'Wn1"J1JeJn1~11
"
3-ways
Option:
bUUl'll TCP Option vn1'l~~~U'Vll"~B·.ml11Jan 'VlnWi'10~l\1'V:;bU'Wn11bbfll'l\lL~D windows size b'vlln1J 512 l1J~
1,m~tJfll!J'Vl1\1
[dsfoolla UDP
Timestamp Source Host.Port > Destination .Port
••
'</I~:J.JjJ
tcr/u:
Timestamp:
Source Host:
bbff!il-J IP Address tIlUl'11-J'IlENbbWmnlil Sll:J,Jl'HHb'ffIil-J1~bUU 2 bb1J1J~fJ IP Address 1~W(;)1-J b'liu1utilJilE.il\1~fJ Vllm'l1:lJ11ClbbU1;il-J IP bUU~fJlel'Sl~(llii'V:; tilJilE.il\11Jdlvr!il~ 2 ~il1tm<lluvn\l~fJ 10.15.14.1 VI~il
Port :
bW!il-JVI:w1 mfl'II'II fJ\I U DP 'V'lil{liltllUVl1\111 bUm'Jil{lilVl:J,J1 mfl'1J1!il ffl:J,Jl1Clbbff!il\l1t1l 2 bb1J1J~fJ VI:w1mfl'Il'V'lfJ{!ilci'1V1~1J'I'w{lilVil~1'li 1J1nT;J:J,J1!il'l:i,lU bbfl:::~fJ'Ilil\l1J1n1'lVllnVl:J,J1 EJbfl'Il'V'lfJ{!illlU bUU 'V'lfJ{(;)'1JfJ\l1J11l11:!-11!il1:i,lUb'liU ECHO, DNS bUUtIlU
Destination Host. Port : b'liub~iI:.nn1J Source Host, Port bU~tJU'llntllUVl1\1bUU UflltJVl1\1 Bytes:
Timestamp
109:35:16:37528°11
Source Host:
bbQ!!il\l IP Address ,!iUVll\1'1Jil\lbbWmn(;) G'n:J,Jl1mwlil\ll[iiLuu bb1J1J~il IP Address l!iltJ(;)1\1 b'liU1utillmh-J~il Vlln'ffl:J,J1"H1bbUfl\l IP bUU~il1~ff~(llnv:;bbff!il\lbUU~fJ tilJilE.il\11JI'lvr!il~ 2 ~fJl~G'!~tliuVl1\1~fJ hacker.com 10.15,14,1 1~ff~ bUUtliU
ci'1'Y1~1J ICMP 1U1J1\1n'Jrubb wmn(il fJl'V'V:; t1nr11b UIil:lJ1'llm 11 b!ilfJ{ 1(ll Vll1 'I111il~fl1u-Wfl~du'nn£)buu'lJfJ\lb 'llb!ilil{U l'1U b'liU1umru
"
'lJil\l ICMP Host Unreachable bUUtIlU Destination Host: lcrnp message : b'liub<Jln1J Source Host bU~tJU'llnalUl'11\1bUUUfllEJl'11\1 icmp bbWmn!ild ~\l1Ulbbm3-J icmp llilml!illu~~
TCPDUMP 1(llVll1l11bb'lJliI:w1vln!ill11\1'1JfJ\I
10: "llh:i''lJbbrimnl'l
.11
"l't~~:
.. '
j.',,~~;
-
--
---
~)P~:~.
-
,
-
'
---
.
--
--
bVim'hn1"i'·tlJbb-Wmn~
use
1oii\ll'U1lJPI:;~lmTn
Linux use Windows iiEJPIb'l1€J~ih.lb(;lf){b 'l'JPI.yj1oii\l1'W~lEJ!.'l'1:J.J1"irl'lhm1oi1t1'l:;n8tJfllJ ~'W1'l111~!.'l'~mnn';h fl'W 1t1Ul\l 11h:bn"i:J,J TCPDUMP srm
"
"
bbiil~~\l bbihtJbblJlJ'lIf)\l-ilf)m'l'vil~Jt!'OJ:;
bb~l llJ"h-il8:J.Jf'l';)::1~:J.J1'OJ1nPluy.Jby.Jf)fl~n
"
"
"
••
&~1:?::lJll
tcr/u:
Stimulus
'VIl-J1tln-Jn1,)fl'l:::$f'U 1'U~.Q'Vtl-J1tl1i-Jn1')fl>J1im.m'Vt1€J«runJ1ruVlm~
"I 'iJ
'l~
b'li'U fl.,j ICMP Echo, TCP SYN dJ'U~u Response mn U1:1>J 'lM 8U'lUM D'lJ€J:J..j~'VI' & ru m In.! 111 n i1!>J m D n b'lJll-J1 :J..JCiI'Vtl-J1U "I
'l!.I .... ""' 'iJ 'I 'I.i .,...
'IL'
,o::j
"
lwlu"j 1MI98t'l'Vt18m~'il:::
bbMn(9)1-JnU(9I1:iJU(9)iil:'::
"
"
Wlb rill~l'lm.JVll 1
bM8{b ')1 (9) 8 ~n1J bi1(j\b"HntT'Ubl9~8>J a oS\Inl"j Wi::: $f'UUt'l:::M€JU1'1J1(;1 UWll , 2 mh>J:i11911:iJtill'1qJ
"
lYubB>JtTUii1[i1ria 1vibnt'l1'l11:J..Jb~m'l1ubb~mh..J
1W11U'Vll..Jmt1Jn'!.Jnl"jn"j:.::v\'l~.,j
W11flth>Jb'liu nl,Vl b'llM0..JnT'iM"jl~rwUi1!m'U:::'lI8>Jbl9~i1-Jl'lm ~(9)flDV1J'UilubI'l0{b ~ Reply n5u:J..Jl'Vt181lJ Ul'ltX'W lE~lU~i1!WlAtl 11il'lli..J 9 m:::1Jl'WnT'i~l'hi-J
-
ping lUU>J198:iJVllbI'lD{bl'l~8-JtT'Ubbliill>rhjJrm ~
"
ICMP
1 2
B n1')m:::v\'l#i'\lddJunTlm:::tii'Wb'l'\l'l:'::biPI~€J\I ,
b~miPI~D>Jflfl:J..j'l'ilb(ilai b~i11tH1J
B lfi-ru
"
,',
-
'iJ
''''
~.
-
---
bd~I"l~l-J'i'llb(ll~fbl"1~~oJ
A 1tiitlJ
bl"1~~\lI"l~l-J'i'llb(ll~f B
EJoJvlloJl'U~ £Jbbfl:::~ll-Jl"if1~f) ~1"i~1'Ub U(ll blfn 1~ (lllaJun&l -u 'Yl~~£in~l~£Jl\l'YltioJ ~floJnJ:;vll~f) Connection n"iru~ b"il"1:::vlln1"iNoJ-i!~l-Jfl Establishment
'iJ
1 2
"
"I:::vllnl1'I1il~il&1"i~lEJ bl'1~~oJl'1~l-JWlb<'liJf B bdfl1M1JA'ruqJlru (ll1:J.J-i!flrll'Yl'U(ll1u1th1rJl'1flfl -i!~rll'YlU(ll TCP Maw\l SYN "Ilml'1~~\ll'1flaJ'lIllb(llflf A n"l:::ti1il\l(iHl1J1lJ
8 ElUbbfl1
'iJ
rn l&il
~u 1tl it\lmI'lEJm1l'l~1J
"
"
"
"
"Ilm'h~£J1oJYi1~mhl1 dlflfil1aJ
i1'W(llEl'Wtli'ul1m1n"i:::tli'Wbbfl:::mll'l~1J~U~\l ,
"" ,
,
"
bflEJ'Yl1EJ dJ'Ub~f)\ltln~'II~oJm:::1J1'Wn1"i$fllin"ioiif)l-Jfl~tl
,
V'll1:J.JUfl~f1ilEJ &1 b'YlM tj floJ"I1nl1m:;1J1'Wn1"inJ::: b i5lJ'WEl1'V'V:; bU~ EJU'ill nmsseu 11b~aJfl fifJ ~Yivl1nl"i
Cl1l-J u:J.J1 n fllEJ bU'U'lif)\l'Vl1\l'Il~\l rm 1 'ill-J~1~ ~ oJ~ b'l ti1 1 il\l~\ll::: NTW 1 'Ylq!fJ1I'lEJ'lifJoJl1oJ bbfl:::ii au n'Vd~\l'II ~\l"i:::1J1J ~nffl
gn
1"1 l-J~'!U
u 1{
Dlonalnd,un),u~aaOn8
~1'Yl11J TCP/IP bb1ill'Yl1n:ijn1"im:::Ji'W~f1n
, 'iJ
MfJ\lMl:J.J1u"i1MI'l€lfl bblih'i':::Jifl.J(llil1J1lJ
b~:J.Jil
"
1u"i1Ml'lflfl'V:::rh'Yl'W(ll11'l1~H"I'Wl1'V11n:ijm"i b~EJoJf1nti1iJ\l(;lll-J
'iJ
tl1mru:J.J1mn'W
1tJ'Yl1~
hi,
"
bbfl:;m"i~f1m"in1Jm"iCl1l-JYiNliltln~
1ail1Nff\lii~'VlTIL~ 1tl~hEJ
1m11l'lElU'Yl1€11.lJ'Yl1fl~N\lCl1aJ.J1'1n'Umn
• ''Oj1~:'1111
repliP
~\ni"w'n::;nt'lln
1U~lUnl'i-rm~11"l1l:J.J
"
~ mll;u::;a'V:::
~ "" 'il
l>il..] ti1J1'W,:::1J1Jtl~i1~nl"m~:::
bbf)'I'\I'I'l bl"li'W~1-.l 1v1iJ nt'll n r!1l'Wl"lll:wtl t'l€lWiilt! ~ lrii bbl'i('l1l1J1Wiv1 1m:::&i'uv1~p~'W b'iiU llJ1lf
TCP/IP TCP/IP
~"
TCP/IP
lbt'l:::mI'TV
TCP/IP
1Unl,~f)~11on€l:W1ll
"
'l1€l..]',h>l
"
1rii lm;H;]'JWJ\lI"l-Jl'lfl1J11J~f1m'nJ:::~uUUU~1-J11u,:::(ilu ,
"
riil~
b1Jwiiu 'li-J
nlSOilUSUI ~U~i)nCllU1SnR10HU1H 10
u 'WUElUv1~lill1n1'i91ilUfU'ii':::riiil\l , b1Ju&\lv1t'l1:lJl1nl"llW1'14mtJ 1rii b'l'\l,1:::nl'li91ilU1U 1l'11'V::: rii€l\ldJulI11l-lonml1'14'W('I1W ' 1tl11l'1l"lilt'l'li-Jl~tJ bb'l'\l~bbri~lf11"HU'If'Wil~bbfil 'l41nm1i91ilUt'l'Wil-Jl"lllil'l4:w1tJ 1:J.J1riim"jWilt'l11Sfil\l'VI1\lfi'ii':::1:J.JbnWl~'WbI'l11:::1"lV11UJ~b~€I-J unn bnil1~-.l::;il1A~m,1 ' h \l1ilU-rlJ'lIil-.lbUTVi:J.J1V lWiilm'Wm"WJl'il\lj:w1 1oE1lfb1J'Wtl1::: 18'lJ'w
"
"
b\'1,1::;~n11
t1\luiJNv1'V:::141tl1:::1EJ'If11'Vlnn11l'1f1U1U 1w1m~ru:::ulfi$f€l-JiJI"l11:J.J bonlh1'W 11 (;1 I"lilt'lb1J'W 1tl €I~1\l~ bblll:::ri€luoJ11\l1ll::: EJWIb'l'\l11:::riiEl-Jml1Jl1n11n1:::riiuUflt'l:::'lJ'Ulil'V::: b~ , dhl1l..n EJil~h\ll ,ill\l nl,l'IilUfu usn in fI{~\l'l4~l EJ 'Wnl11lflrii:J.Jl'li\lonmJ 1 l1J'W'iiil-J'Vl1\lVi1:J.J:i1 n1,1mI1I"l11:J.J1.J 'WVlJ'Wl hJmn
i.I . .... . . .. _.
"
:i1Nv.J~l'I1tldbbnll-l~'1h'Vl'Wl~m::riiubblll:::1LA'1:::~buTI'\mEJ
"
u 'I'\I~l1~lt!iJ!.ili'l hJ "lilt!
"
'"I::; bbt'llil-J~lil!.il\ln111bA1l:::~'Vlnm1m:::~'Wbblll:::~1(>lmlruv.J1Il1'1€lU1U
1'W lrii
mrul'il\l'1v1'1::: 1rii",llmUlm.nEJ
'li\!~lm1mhwl'IlV1EJ~1Il1lfd'i(iltl,:::
l1.JV-.lbU1'14mEJb'WU-Jbb Vlnbfil'lb~EJ1LvhJ'Wfilll'lm1t1mllJ'.1iil~t'l'1lil\ldJl'l4:J.J1EJ
"
"f
---
n1'391£11Jofui'i
fl1l"frh~:::l~iu
~-l TCP SVN 'I'lf)'f(;J 80 TCP SYN, ACK 2.1!n;j~dh'VIl..n8:OlleJ'I'lw~lrliul'111JinT~t(;J81oE'V'l1){(;J lil1)-l"lln:OnT~(;J1)1J11J"inn'V'lf)1(i)80 3 ~'Wih~!1'l.rilt!'lfl'~dh'l'lm8vil-l1\.!Lih...ll11Jl'iHvlnfJ{ (lileJ.J"Ilmi1Jl-BivlblfJftllW1)1(;J RST 1. l!'191~d:hmJ1uvil-ll'Wmj 801Un111'111Jin11) 80
"
"
n,soausuri,HuCl151unsaunaunmSau ••
'1If)-ln1"J~fJ9Il'
q .... 'l.J
10
1'l11~mn~1)-l 1'l11j.J:iJw~!J1m'l'lbb~:;lh:;~'VlTImw
c1ilVblh'VImu'lJEhllu"Jl(i)l'lfJ~l'WdJf)\I(ih...l~il
"
I"lfJlJ~ll(i)fl·rVyj 2 ~-l'ij::;~il\lfl'1'U1I'JmllJ
'I'Ilni:Jn11~E1al,~1:JJbln~il\l(i)llJ
rll''r1'Wlil 'U~(i)Vishl'lbJJ utyjnV\lI'l-lb'Vi~flb~fl'U 111 1'lJ~'U'1~nlJlnm8ffitl11(i)l"lfJ~ TCP rll'VI'Ulilll1t'i\l SYN l'Wlililu Connection Establishment
"
1"l' ilTv'V:;i:J
llJ1~b:;~:iJC;)lfl~1\1 b'Ii'W
bbf'l::;t'i.J FIN
Iuasu
Connection
use
"
--
u oJ 'UfJ'U11 n11t'i \I~qj qjl nJ'VI~il'i1fl~ f'l1(i)1ViN(i)'ilil nl'ViU(i)1Uttl "i lill'l1)~~'Uil ffllJl"Jbl m::;'l'11 ' l 1J11'Unl1vil.Jl'Utln~ b'J3'W'Vilnl'lnJ'V::;id\l-nfJlJiijV·h'U , " bbl'imh~lJ11 TCP I'lnJfll'V'ij:;b~!.Jn , API (Application
'II
Program Interface) 'Vi~El Socket l-JlvhI11'Ubbf'l:;~b'Vi~fJ API b'I'I~l,l'l.!mtl~(i)nl"i-nm.Jfll'U'::;c;)lJ ~l\1bf)-l 111bln~fl\l(;llj,J ltl"il(i)l'lil~ API 'Vi~fl Socket b'Vi~l,l'l.!rhiJ'Ultl1bbmlJ'lJU(i)'Vi,j\l l81)1~1\1 b'vh,l'l.! mnuen '11c1i1(i) 1.](i)"i\l b'Iiun'l.! bnfl-fmtl'lumj,JVivl1
"
~'V11'1'1'Wl~~lil'l::;lii81J':iJ'm.jf'l b~lfl\lltlil\lfltlmru1'Wb~ L
'"
'V!ih~~\ln~ll
nffllJl1r1g\l-nilj.J~
'II
ltlil,mtlmruliil.J
,
ii..1 bl:Wm'ij~:::(if1)\liiI'l11j.J11'l.!
b"l'li'11lJl1blci\l-nfllJf'lltlil\l ltl11(ilI'l1)lilb'l'l:iJfl'U~ Socket
Ul'iilliJ'l.!~\lVivil1(ii
uae dlfl
V11 ojjfllJflill'V~:;iib~eJ'l.! l'lJ'Vi~fl flag ViutlflnU"J::;'Viflll11bblil:; :JJfflj.Jl'lbl~(iln1'j'c1i181tl"J l(i)l'leJlilv(1'11tl 1 n bUU1(ii bb~:;'V(i)dbfl\l~'I'h 111-nfJlJlilVigl11tliI-lUlill tJ'Vl\11J 1\I1"l{\IVIInll,jil~l Ub~eJ'U l ' l'lJun~Vi'j':;lJ 1 i1 u
q 'IJ 'iJ "l
"
bu'Uojj1)lJ~Viblnrll'Viu(il11bl~11u
"
"
"
"
1tl'l1(ill'liJ~
HlJ-nfl j.Jf'lfl1"J'V:;llJi'lllJl"i
11 'lJ
II·
L~1:-1::1J1J
repliP
Il'SllhqlJ,ftuWi,UDil
'I'll
"
b'l'jdl:::
dJu
b'VIqJ
'VI1n l~J.JEl\li:i\l
dJUl.ld::: lu'/lu
'3.J
bWU\lbbl1l
b'ii\llU'lJEl\le:11'ii·:hv::-111
J.Ju11.lbo1Jnw 11.lbUill"T'Vll\1b~
b'liu'lNElf(llNbbnU bill'lbiimmnu
~Elmd~\liffq)q)lrull.l
TCP
SYN 11.liJ..J
El\lbbl11~:::'I'j l1(11'i1::'1'11bViiffut1'B!llUl~1111'1111tli" E :
ICMP Echo
b'Ubu(iib11mTubb~:::f\EltImd(llEl'U
'u
n~'U:J..JT'V1llbbl1li:'!:::IP
'Ubilfilbi1n1Jl\1 l~lldJ'U
tI:::In
wd\l htJ1~qj'1 dJ'U LiiEl\ll11fild1'1'ffEl'Uffi1'1111tli"J'U""J~\I b 'li'U'VIlnLilEl\ln1d'VIdlU1111'!N tli"lllilltJ'VI1\1vh.nu '1 l.ln&1'V1~i11~rlil1'i1'i1:::H11.J1 bbn1:J..J PING bvlEl'VIt'lNEl'lJ1?lVI~f1vl1nLiiil\lnl1'V111'Ul1b:J..J~ bMwb lfl1LiJI?l lVi'U~mli1tJVI~Ell~rl'VI1?l1llD'U 11?ltlnT1 Nm'w:::v1dJ'W'iI,\l1 'U'lJru::.:J'W ifim,bb§l::': bl'1~fl\liJiI b'VIt'h,j,,:::111l111ft ~'UilE.inlJN1 ii Vllnm,dl'·T'VJ'U
TELNET
"
"
"
" 11'1NWI'lI EJ\IN~Url'il::: bV'Wn1'J§l::: bjjf?l~V1B'1:JB\I N~U 'VI n b1.l1EJlJ1[1111W1 1 dJ'Wll1u bbG~i1rl'V::: bNiiEJUU1Uv1 dJu " " 1~ii{11i1'U'lIflu1i1?l 'Ur1f1§lfl1 UU fl nv1 N1U11.lm ~ll.11'bliiifl\)n li' fl\l b-Elm ~,1, ssu1'WU1U1M u 'VI'U'VIn
'1lElnvm:J..J:J..J lV1t1~b..ijl'l1B\lUl'Wfl1'i1'::: ldJ~(ih bbi;'l:::ii\lul1':::~1'l11V1~iii1'W 1'V1ninEJ1nv191:::'VI~m~tJ\llM
'I 'I 'lJ '9..J ....
"
bv'UnTm"i:::vhvifllviilWifilub1NrldJ'W~\ItJ
n1'J'lIlf?ln§llnM1UI'111:J..Jll§lilVlJ111v1m rl(llll.11Liivllm,dl"i1'l
f;j
u,:;-~'lJ 111'J1t91r1i1§l bUUn11bUt'l1fln1111 1ViN~UVI~B 11"l1'1 b1ll1 '1'111 Viriml§l::: dJI?l~'VIfi'1I€I\I~~u 1'WbU(IIb i{nLiil!'Jn11
d:Jl'V1mtl(fjl\1'1flVl\1
"
unu 1f?ltIhi1Mu fl'Will~1I?lbnf?l~'W lu VI§llm:::~lJ u UUilU l1n1'J1II bbnujj1~'Vhf1uI?l11u , Ni:'!m :::'VIlJ l?l'1l'imiJl'V1;j.jltJ 1'WYluYi bbvi.V,J~ 5YilJi'illn rrnsunu bUU~\I~5'W~111 tI~\lnl1 b ~~ ~\lv1f11"jfill:::'VIlTnM€I
D 'WT!'JYin'B:::r111:J..JiU i
"
us :::a\l
u [1n in fl1ti a 1.1 ,1 tilT nv1,::.: 1II1:J..J1 b"'ill:;-N1'Wseu Ufn'BlI'111:J..Jll iililt'l J1t1'l1iI\l bVIdill iKtl?lU sn ldJ:lJii fl:J..J Gil'1lfl\l
,-:r
b'VIdEllmJu'iI :::W1fl\l
1.1
"
"
.;r\lJum
:::lJ1Un111 Vil~:J..J1~\lii Ell-Jlil'l':::b1Jum :::lJ1U n1d Wiu'1'11 \I1'111:J..J~til 111:1.11 nl"i b'ill::: EJ U d'.11'V1m U~htllTI11l1\11t!'WbEl-.:l m1iJ€l\lnU~n m[1111~'1IEl\lb"il1111mlbl Qnabbn'W lLii
11 : Stimulus & Response _.
. "i:-:'U'UrlRfln11dl11'V
~"
-~
---
---
--
---
--
~ il
1l"l:::~Vlfj[11'woii\l"l:::'li';JU lyb:::~lJ,"m:lJ~ln
"
bb1il:::1il~l"lll:lJ b~~\11Yi-wmJ1il\11~
1'W mi"l::: bU'W \1~'ll\il b"IU 'll El\lnl1Ul 'il ~ msri Elmu n1':lYll\l 1'W'llfl\1dhVl:lJl~ 1'WLi'i(;lb l{n
m:::m'Wn11i1l111
:::'1'111 m!lfl(P]
~ fl\1li1fllJ~UnlJmlm:::~'WbblJlJ{9]1\l1
'ilm.J1illYibbrluen bnfl'h~ElCinflbbnUbb~l
"
"
~'VhLVibb~d\lnll'!'W1ifiEll!lflMtaJilVl1\1
bViElll1lCilJ':i:::fI\1 ~El:::
~
b~Eln~"I:::1aJ\9lfllJ~lJ
11 bb~::::lJl"11nYil'VI'W
1udJfl\l'VI~.,j ui'll"1 :::~El\11-E
bii El\1 "I1nnTJI'lEllJ~lJ bu'Wm:::u':m nll'Y1ii\l'lJEl\l n11~El fll':l'il fll;j1il WI\1'!Ub~Ell!JfI #ll~~U n11 m:::MU l:JJil"l::: , bU'Wuuu 1l1l n11"1::: g\1trru~onru V1ElU~Un~u l11l~'!u ~
:lJln b~ElbYi~lJnU'VI~"foI~lnl,;r\1'VI:lJl1l~:i:l bb1il:::~'Ull~:lJlruVl~"foI~Jlm bYl~\1 b~nu8u~nn -u l-ii111'Vll1 Yi1 U flJl11:::11 n Wi bi'llNL-ii1:JJ'VI11lJbb1il::: b 1:JJ1~~u N1ilnl::: VlU"I 1 nm:::munl1.a
bi'W bbM'YIln~El.,j'Vllnl1
512 llJ~Uml~\1trtl)q)lru
ACK b~fl\9lfllJ~u111
"
rc=
SYN 1 bb-wmnVl
rcr-
SYN bbwmnVl
111mru:lJ'VI1Al1il boihm bbf'l::: l!'1f1~bfl\lri1aJfll:lJl1n'VllEl::: 1'j1~~hJnilml"fo1tJ1m:lJ\9l8U1m'Wfi\1~1i!l'1 bYil~Vl1'VHJ 1 n'J'il :::flll-l1'j n1"li1111~ "'1l n~'8 ~l\1-iil\l WlU 'VI1 nl!lfl(p]WI\1n~l'd 1cHlJ
rep
SYN
Iu
"
1~
• •
•• L1ll1:';l:IJ1l
"
"
icr/»
1~fl'~iil\1~lJLtif)1Mum"Jn"J:::~'U~\lniill1 ,
nij~m'Viv1~rJ\lv11\11'UrJ~l\1'V1tTnLLPI:::v1l\1l'U~'U1~ f)~ LLPI::: lllnf) v1'U1:'Tl11w«i'l4'u~m"J 1~'71dJ1~ \Jv1fl'~ o;u 'iJ I It 11uiJ\I dJl'V1:!J1V,r'U
0111 PI\lmnl'V'Wii\loff'Uv1<]~~l
n~'lJf)\I'Vlf'Vi tnn"J~ij
Flooding fif)'V:::1'l~11JnUn1"Jv1l1'14'buAbl~n,rmil:!JYl'U
\i
t1i'U PI::: 1I"(llf)U1U b 11'W 'W ff1 'VIit\l'lJEl\lml"~ Elfl'l "Jii f):!J~ 'i\l ,11'W ~ €l\l tn n~'V::: b ,u n ~ bt:j'WjjLL{i]n!iil\1
OJ
:::'1'11 1Vib"Jlffl:!Jl1"lliJ€l\ln'Ut111
"
~1'U l~ih\lv1
~l bU'U~D\ll ii~\lriD vi] fl\ln'UA1:!J1'111:!Jb'VI:!Jl::: t'l'l-J b'Vi"Jl:::nl"JiJ fl\l nuv1:.nn bllUlU'VI~fl'lJ1~1'111:!Jb iill 'I b V\I'ViElEll"J<iJ:::v11l Vi Vi".i:::uUfl1'V'V::: lJfl'1).J1"J1l~f)~1"J'VI~D1'14'u~n1"J1Willll:!JUn~mWi 1
rep stimulus
DElnhl
- Response
"
n1".in"J:::~'Udl'Vlfu
TCP J'WiHi€l:j.mdl~ru~~fl\l"J:::ul'Un1"Jn"J:::Jfu~fl
'iJ....
"I
'I
IP Address
LbPl:::
'VIl-JlVL~'lJ'Vifl~AtJ~l V'Vll\1 1'W &[111 :::tJn~ b1flU 1'111 'Wn1"JAfl1J1U 1 U bb!ii~::: smu m".im:::t1iufflm"Jf:I'Vh1~{i]V~lVbYiV\lLbI'i1ii~1«\I ,
bb\ll~:::
nsn1if 1
1umrudL
fiJifdlfhnu181iJallfusnlsuuwasnns:q
"Jl&1:!Jl"J1lI'1l{i]'VImVn1"JlllElU1lHln
'il
boi!{y,jb1Elfl~
'lJ
Stimuli Response
client.com 2774653900
: 25001 > server. com. tel net S 2774653900 (0) win 8760 <MSS1460> (OF) S 2500700000 client.com.25001
server.com.telnet>
,..
"
U~n1"J~Wf)~!ill{i]Ul\1 vW{\lI1Viu~m"Ja~
l\l1EJ'v11n1dm:::t1iti{i]l:!J~".i:::u , iiil\1M'U 1 ,
'VIlni'Jn1"JAflU~Ubbt'l'{i]\l11:ijn11"bU~
11 :
~.~~. ,&_:}-' • ~ ~
-~~~-~.~
.,i' . .;+;;~
,
,:"L:~ •"
0; ','
--,~ i~~.'~::~::'_:'7?~<:
,~
fIo.""",", ...:_
",J
.:m:-~'~
~Itr:~
, ,
" ~~
. .'
~~------
nsrun 2
Stimuli Response
fi1i1tilli'JIfU1Sll.iliJalliusnlsuuWiJsans:q
client.com : 25001 > server.com.telnet client.com.25001 :S R 0:0 (0) Ack 2759957870 : 2759957870 (0) WIN 8760 <MSS1460> (DF) server.com.telnet> 2759957871 WIN 0
Host
tJ~lU'VI1\1vl1\l1'W€i~bb~1l.JHibtl[1l1Yi1J~m1"1J'W'jIIjfl{M~~mWlJml-J
b{hmu.,j'l'lJfl~MVillJdJ(iJ1'11u~n1J~EJ b~ilb'i11cii-run1'i(?Jil1Jniff1J~il
"
Host
'V:::vhn1J(?JEJ1Jntr1J111u.,j~~ n'V:::ml1J1ciiVi'WVil1
"Host
"
$hUn1'i~.,j
Reset Flag
ntru111bVifl~Mn11"M(iJMmr'WVi b~flll~bmli~~MMMflb-ihmii1Yi:i:l
Reset Flag
m'iM(iJMm1i1j.Jl~'l'IJil'mi
nsrun 3
Stimul i Response
fi1i1tillalSnli)ltiiJa8uUliimJsn
client.com.25001> 2759957870 router.com> unreachable server.com.telnet : S 2759957870 (0) WIN 8760 <MSS 1460> client.com: ICMP : host server.com
..
3 blJ'Wn"iru~1eJmMll ~18'Vll\1 hJiimjumil(i1 bi{n EJ1"1'V::: lJ'Wb'l'lJ'il:.:tI(iJ brl~fl.,jfl ~ b ~ ~ 1aJ1lilMElb1ilnu bil(F]bi~n l'l~ilciilml'l(?J ,1(iJ1lbb~1 bb(i11!JtilM~\lnj;hJ1aJtill'-Jl,lJ~mn'inlJlil(i1b lin 1cii ~ltJ
TCP
nlru~
'V:::b'l1'Wl1n1'iMflU-ru<,;':M1.,jnu1'timru~
ICMP Unreadable (ICMP Type IP
2 mrii'dffqJqnruVilcii1lJMfluniffu'V:::1l-J1'1i 3
Code 1)
TCP
bbM'V:::dJu b~btJfl1'1Jfl.,j
~~l~\ll1.JbbPl:~~\I
IP
ICMP
Ylih~(i11'-J~nl'''1'W(i1111'ti
111U\l
server.com
~~EJ
I'lflunfful-JliJ-JJi'W'VI1.,j 1Yl'Vl,lU
nsrun 4
Control List)
fi1i1tiLla18n1i)l1nUaanlJ1oslslloas
<u
mruii~fl1!Jf'lMilil~'V~\l 111,.n!Jf'I;tv!
Admin
ACL (Access
, 1Yin1';i~flm1"i
~1'ti
client.com.25001> 2759957870
2759957870 :
ffqJqJ1ru~(F]fl1J-rlJni!hJd..nn-HiHi<,;':::dJ'ti
(ICMP Type 3 Code 10)
ICMP
5nL'1i'Wn'Wbb~
Message
1'W
ICMP 'iJ:::
••
'1iI1:t';1:IJlJ
rep/IP
nsciifl 5
"Ilf1nJruii
~\lI'h11tl~1..]1
faadllif18nliJgnuaanaJ8lS1/DaSlla:lsltnas1ulliiJnau
4 J\.!Niivllf1l"j'INmm~'Vl!n~EJ1J 1 m.HU1(ii1milb£)!nb~'iflU§l:::VW{(iitl::: ,
"
11 1~1il"] (il"]~ubvltliJtl..]nuil1'11ojjf)l'Il1:!.rvi(iiil1J
..jf1'lruvi'Vllm'i1J~f)n
TCP Segment 11bb§l:::
"I::;1Vilb~..]1iElI'l11J.Jn51J1tJir..]$1U'Vll~'VI1tl1:!J mrudbih 1:!Ju~..]1im'nlJ.J 11'l'I n5lJ 1tJEJ..]$1u'Vll..] Stimuli Response 1un'lruii f11'i~..]1im.m~h14 client.com.25001> nothing
server.com.telnet.S
2759957870 ..
5 iinl'l(iif)1J1'm:::1:!Jb1'Ju1tJ(iil~1imhvI'IJ(i\~..]114
IP use
'VI1f1 1:!Jl1m'll'lEl1J1'1J
"
IP 1:!J1T"l:::bnl'lf):::hffun(;11J.J'i':':~f)\lilm1u~..]n5lJmEJ-:I~U'Yl1-:11liHJ
1(ii'l1Vifl'14'I1H::i1141~1111§llV'Vll..]il~tJn'lru1m::flI'111~tJm)(i\.nVf)y bbvlm'lVil:!Jilm'l(iiEllJ11J
fll'i''i'::: b1JU
rll'V114(>l1'111~tJ~EJ(j].nVf)~1-:11'l 1:!JG'l'1l-J1'lbl'Vl'lI1J1~-hvinnlJ~ilnJu~\I
'VI1EJbil'V'l1:::'lNrJ{!Ilii-:l"l:::'Vl11Yi~iNbaVb1L'n1tJi.'4114'VId-:lbvlmhm'll'l'l1v@1JtJmV'Yll..]Ji1vlTI~uEln
"
~\I~14EJ~n1J -u
'Yl(>lG'l'EJ1Jn1Jlbtl'IN'V'I~bl'1i14vibtJ(>l1i\lI141JU UDP EJyriEJ DNS Stimuli Response 1UM1D~I..]d client.com.2540 > server.com.domain : 43005 + (31) DF
"
rlT1114l'llEl-:l iElfl-:lbn(;1rimh'VI1lJ
UDP bb~lvrlnilnTm'l:':~14U~JaiEl"]f11'J'Vl'illJl1bb~~:':'lNEI{(ii'V:':
(ilD1J~14D"]£)~l\11 'l n$1£)..]ffm::fl1mlV~:::bElV(il"1JEl"] bb~f!l:::bbil'V'l'IN~bfli14 EJ~l..]1 'lnl'lll-J'VIlnMEJ"]f11'l 1t1 m:::M14lWt!..] bvl£) '11mllJl1:!Jb1f)'IN'IN~LIi'l05uLi'J(>l1'I11J~f111ii'INf){(fl~u'VI~a 1lJ~14 €mv:.:1lJ'Il1 b1JU~EI-:I 1 , 'Vl".ll1JmJi"lJEl1 ilW us lbvll-n{W bJ El11'1E1lJn 1Jmn bwV"]'V'I£)iiv~vh 1Yi'Yl'l11J Ji Y 5 1
nslfifl 2
Stimuli Response
client.com.25040> server.com>
client.cm
f11'l(ii£)1JNUD..]1umrudv~~I..]nlJ
'iJ
1[91V114
TCP ~14mruYillJ:!Jf11'llJ~f11Jii'V'lil{(ilJ14
ni!l1J'V:::~lvln
b~mtJ~V1JbViV1Jf11'l{ilil1Jn51J'i:::'VIil"]
11 : Stimulus & Response _ •