The OSI model (Open Systems Interconnection) is a seven-layer framework developed by ISO for designing and understanding network communications.

Each layer solves a discrete subproblem:
1. Physical — bits on the wire/air/fiber.
2. Data Link — node-to-node delivery, framing, MAC addresses.
3. Network — logical addressing and routing (e.g., IP).
4. Transport — end-to-end reliability, ports (e.g., TCP).
5. Session — session management.
6. Presentation — data translation, encryption.
7. Application — user-facing services (e.g., HTTP, web browsers).

Core ideas:
- Encapsulation: As data moves down the stack, each layer wraps the data from above with its own header/footer. The receiving host then demultiplexes (unwraps) the data as it moves back up.
- Modularity: You can swap protocols within a layer without rewriting the rest of the stack.
- Abstraction: Engineers at one layer do not need to know implementation details of other layers.
- Flexibility: Competing protocols can coexist at the same layer.

A web request example illustrates this: Firefox (Layer 7) sends an HTTP GET, which the OS wraps with a TCP header (Layer 4), then IP addressing (Layer 3), then data-link framing (Layer 2), and finally physical transmission (Layer 1). At the destination, the reverse process occurs.

In forensics, understanding these layers helps you identify where an anomaly occurred and how an attacker might have manipulated protocol behavior.