Internet Protocol Suite
The Internet Protocol Suite, also known as the TCP/IP protocol suite, is the collection of protocols used to implement networking functions on the Internet and many packet-switched networks. It is built on the same layered principles as the OSI model and is foundational to network communication.
For network forensic investigators, fluency in this suite is essential: nearly every analysis technique—from flow records to packet captures to proxy logs—depends on recognizing these protocols and their header fields.
Core Protocols
IP (Internet Protocol)
- Operates at Layer 3 (Network Layer)
- Handles addressing and routing
- Connectionless and unreliable — no delivery guarantee or sequencing
- No footer; header + payload = IP packet
- Often paired with ICMP for error and status messaging
IPv4
- 32-bit address space
- Written as four decimal octets (e.g.,
10.1.50.150) - ~4.3 billion possible addresses
- Includes a header checksum recalculated at each hop
- Private address ranges reserved by RFC 1918:
10.0.0.0/8172.16.0.0/12192.168.0.0/16
IPv6
- 128-bit address space
- Written in hexadecimal in 8 groups of 16 bits (e.g.,
2001:db8::1:0:0:1) - No header checksum — error detection deferred to higher layers
- Fixed-length header for faster router processing
- Designed to interoperate with IPSEC
TCP (Transmission Control Protocol)
- Operates at Layer 4 (Transport Layer)
- Provides reliable, connection-oriented, sequenced process-to-process communication
- Uses port numbers (0–65,535)
- Establishes connections via the TCP Three-Way Handshake
- Header + payload = TCP segment
UDP (User Datagram Protocol)
- Also at Layer 4
- Minimal protocol providing only process multiplexing via ports
- Unreliable and connectionless
- Port numbers 0–65,535
- Header + payload = UDP datagram
- Useful for real-time traffic (VoIP, streaming, gaming) where retransmission would cause more harm than dropping packets
Historical Note
The suite originated in the 1970s as a single DARPA-funded protocol. In 1977, Jon Postel argued it violated the principle of layering by trying to serve as both an end-to-end protocol and a routing/packaging protocol. This led to the 1981 split into:
- IP (RFC 791) — internetwork routing and addressing
- TCP (RFC 793) — host-to-host reliable transport
Forensic Relevance
Understanding the TCP/IP suite matters because:
- Attackers often abuse protocol semantics (e.g., TCP flags, IP fragmentation, ICMP tunneling)
- Protocol headers contain the evidence artifacts you will later correlate across logs
- Knowing what each layer can and cannot guarantee prevents incorrect assumptions about traffic behavior