Internet Protocol Suite

The Internet Protocol Suite, also known as the TCP/IP protocol suite, is the collection of protocols used to implement networking functions on the Internet and many packet-switched networks. It is built on the same layered principles as the OSI model and is foundational to network communication.

For network forensic investigators, fluency in this suite is essential: nearly every analysis technique—from flow records to packet captures to proxy logs—depends on recognizing these protocols and their header fields.

Core Protocols

IP (Internet Protocol)

  • Operates at Layer 3 (Network Layer)
  • Handles addressing and routing
  • Connectionless and unreliable — no delivery guarantee or sequencing
  • No footer; header + payload = IP packet
  • Often paired with ICMP for error and status messaging

IPv4

  • 32-bit address space
  • Written as four decimal octets (e.g., 10.1.50.150)
  • ~4.3 billion possible addresses
  • Includes a header checksum recalculated at each hop
  • Private address ranges reserved by RFC 1918:
  • 10.0.0.0/8
  • 172.16.0.0/12
  • 192.168.0.0/16

IPv6

  • 128-bit address space
  • Written in hexadecimal in 8 groups of 16 bits (e.g., 2001:db8::1:0:0:1)
  • No header checksum — error detection deferred to higher layers
  • Fixed-length header for faster router processing
  • Designed to interoperate with IPSEC

TCP (Transmission Control Protocol)

  • Operates at Layer 4 (Transport Layer)
  • Provides reliable, connection-oriented, sequenced process-to-process communication
  • Uses port numbers (0–65,535)
  • Establishes connections via the TCP Three-Way Handshake
  • Header + payload = TCP segment

UDP (User Datagram Protocol)

  • Also at Layer 4
  • Minimal protocol providing only process multiplexing via ports
  • Unreliable and connectionless
  • Port numbers 0–65,535
  • Header + payload = UDP datagram
  • Useful for real-time traffic (VoIP, streaming, gaming) where retransmission would cause more harm than dropping packets

Historical Note

The suite originated in the 1970s as a single DARPA-funded protocol. In 1977, Jon Postel argued it violated the principle of layering by trying to serve as both an end-to-end protocol and a routing/packaging protocol. This led to the 1981 split into:
- IP (RFC 791) — internetwork routing and addressing
- TCP (RFC 793) — host-to-host reliable transport

Forensic Relevance

Understanding the TCP/IP suite matters because:
- Attackers often abuse protocol semantics (e.g., TCP flags, IP fragmentation, ICMP tunneling)
- Protocol headers contain the evidence artifacts you will later correlate across logs
- Knowing what each layer can and cannot guarantee prevents incorrect assumptions about traffic behavior