Unit 4 Protocols and Security Frameworks Vocabulary

Unit Testing Objectives and Assessment Criteria

Unit testing objective

The primary focus of this unit is evaluating the ability to recognize technical concepts embedded within real-world scenarios, select appropriate defensive controls or explanations, and defend why a chosen control or explanation fits better than nearby alternatives. Mastery is demonstrated when core terms can be defined, confusion pairs distinguished, scenarios answered accurately without reference materials, and defensive decisions justified using a four-part structure: what was chosen, why it fits, operational or CIA impact, and why alternative options were rejected.

Required preparatory readings include Tolboom Chapter 4 (pages 39–54), Chapter 3 (pages 36–37), and Chapter 9 (pages 109–112) for attack frameworks. Core areas requiring intensive study include protocol layers and functions, transport protocol differences, bidirectional core ports, secure and insecure protocol pairs, and distinctions among cybersecurity frameworks such as NIST CSF, Cyber Killchain, and MITRE ATT&CK.

Core Networking Protocols and Technical Vocabulary

Address Resolution Protocol (ARP) maps a local IPv4 address to a Media Access Control (MAC) address. For example, a host on a local network uses ARP to query which MAC address owns the default gateway IP address. ARP poisoning occurs when forged ARP messages are broadcast, causing victim hosts to associate the default gateway IP address with an attacker's MAC address, thereby redirecting local network traffic through the attacker.

Dynamic ARP Inspection (DAI) serves as a defensive control on network switches by validating incoming ARP messages against trusted IP-to-MAC binding databases. When DAI detects a forged ARP mapping, the switch drops the invalid packet before it can corrupt local host ARP caches.

Internet Protocol (IP) provides logical addressing and routing of packets across interconnected networks. IPv4 utilizes 32-bit32\text{-bit} addresses, whereas IPv6 utilizes 128-bit128\text{-bit} addresses. Network communications require securing both IP versions during transitional dual-stack deployments.

Internet Control Message Protocol (ICMP) carries network diagnostic and control messages across IP networks. A common application of ICMP is the ping utility, which transmits ICMP Echo Request messages to evaluate target host reachability and round-trip delay.

Network Address Translation (NAT) translates logical addresses between distinct network domains. A typical deployment involves a consumer or enterprise router mapping multiple private internal IP addresses to a single public IP address. NAT provides address translation but does not offer cryptographic confidentiality.

IP Security (IPsec) is a suite of protocols operating at the IP layer (OSI Layer 3) to protect network traffic. IPsec is frequently deployed to establish secure site-to-site virtual private networks (VPNs). Within IPsec, Encapsulating Security Payload (ESP) uses IP protocol number 5050 to provide packet encryption, integrity protection, and data origin authentication across network tunnels. Authentication Header (AH) uses IP protocol number 5151 to offer data integrity and authentication without encrypting packet payloads, allowing detection of unauthorized modifications without concealing content.

Transmission Control Protocol (TCP) is a connection-oriented transport layer protocol that guarantees reliable, ordered packet delivery through connection establishment and retransmission of lost segments. File downloads, web browsing, and administrative sessions rely on TCP. User Datagram Protocol (UDP) is a connectionless transport protocol designed for low overhead and minimal latency, offering no delivery guarantees or packet ordering. Real-time applications, such as live voice traffic or video streams, favor UDP because late retransmitted packets are less useful than dropped packets.

Ports are numerical identifiers ranging from 00 to 6553565535 that specify individual service endpoints on a network host. For instance, Secure HTTP (HTTPS) by default listens for incoming client connections on TCP port 443443.

Domain Name System Security Extensions (DNSSEC) adds cryptographic signatures to DNS records to authenticate data origin and verify message integrity. DNSSEC enables resolvers to confirm that a DNS response has not been forged or tampered with, though it does not encrypt DNS queries or conceal domain destinations.

Nmap is a network discovery and port scanning utility utilized to identify reachable network hosts, listening services, and port states. An open port state indicates that an application is actively accepting connections on that endpoint (e.g., TCP port 443443 accepting HTTPS connections). A closed port state indicates that the target host is reachable and responded to probes, but no application is actively listening on that port (e.g., a host responding with a TCP RST on port 2323). A filtered port state occurs when firewalls, network access controls, or intermediate devices drop or block scan probes, preventing scanner software from definitively confirming whether the port is open or closed.

Simple Mail Transfer Protocol (SMTP) operates at the application layer to transfer and relay electronic mail messages between mail servers. File Transfer Protocol (FTP) facilitates client-server file transfers but transmits commands and data in unencrypted cleartext by default. SSH File Transfer Protocol (SFTP) replaces unencrypted file transfer workflows by running over Secure Shell (SSH), encrypting both commands and file payloads in transit.

Hypertext Transfer Protocol (HTTP) is an application layer protocol used by web browsers and servers to request and deliver web content in cleartext without built-in confidentiality. Secure Hypertext Transfer Protocol (HTTPS) wraps HTTP within Transport Layer Security (TLS), providing transport encryption, server identity authentication, and data integrity protection.

Telnet is a legacy remote terminal login protocol that transmits all credentials and session commands in cleartext, rendering it insecure across modern networks. Secure Shell (SSH) is a secure remote administration protocol that encrypts sessions and authenticates servers and users, providing a safe alternative to Telnet.

A network protocol is a standardized set of formatting, processing, and transmission rules that enable interoperable communication between diverse computing systems. Systems achieve interoperability by sharing common protocol definitions across various layers.

The OSI Reference Model and Layered Defense

The Open Systems Interconnection (OSI) model is a seven-layer conceptual framework designed to standardise networking functions and assist in troubleshooting. It serves as an explanatory model rather than a strict implementation requirement.

Layer 1, the Physical Layer, encompasses physical media, cabling, connectors, radio frequency transmissions, network interface cards (NICs), and bit-level electrical or optical signals. Physical damage to media at Layer 1 disables all higher-layer services across that link.

Layer 2, the Data Link Layer, manages local link delivery, framing, hardware MAC addressing, media access control, and link-level error detection. Switches forward Layer 2 frames within local area networks using MAC address tables.

Layer 3, the Network Layer, handles logical IP addressing, subnet masking, and packet routing across interconnected networks. Routers operate at Layer 3 to determine optimal communication paths.

Layer 4, the Transport Layer, provides end-to-end communication management, segmentation, port addressing, flow control, and delivery reliability tradeoffs. Transport protocols split large application payloads into TCP segments or UDP datagrams.

Layer 5, the Session Layer, establishes, manages, synchronizes, and terminates application communication sessions between hosts.

Layer 6, the Presentation Layer, formats, translates, serializes, and encrypts data to ensure that application content from one system can be parsed by another.

Layer 7, the Application Layer, exposes network services directly to software applications, defining protocols such as HTTP, DNS, SMTP, FTP, and SSH.

Abstraction hides lower-level mechanics while presenting a functional interface to upper layers. Encapsulation wraps application data in headers and trailers as it travels down the protocol stack (producing segments/datagrams at Layer 4, packets at Layer 3, frames at Layer 2, and bits at Layer 1). Decapsulation reverses this process at the receiving host.

Attacks can be mapped to specific layers to understand their security impact. A Layer 2 MAC flooding attack overflows a switch's MAC address table with synthetic addresses, causing the switch to flood incoming traffic out of all ports or degrade network performance. This degrades availability and increases exposure to traffic sniffing. Man-in-the-Middle (MITM) attacks alter traffic flow across physical or logical paths (such as Layer 2 ARP poisoning or Layer 3 route manipulation). If higher-layer protection such as validated TLS is active, an attacker on the path may inspect traffic metadata or disrupt availability, but cannot inspect or modify encrypted application content.

High-Frequency Network Ports and Secure Alternatives

High frequency ports list

Network administrators and analysts must memorize core high-frequency service ports and their corresponding protocol functions:

  • File Transfer Protocol (FTP): TCP ports 2020 (Data) and 2121 (Control)

  • Secure Shell (SSH): TCP port 2222

  • Telnet: TCP port 2323

  • Simple Mail Transfer Protocol (SMTP): TCP port 2525

  • Domain Name System (DNS): UDP/TCP port 5353

  • Dynamic Host Configuration Protocol (DHCP): UDP ports 6767 (Server) and 6868 (Client)

  • Trivial File Transfer Protocol (TFTP): UDP port 6969

  • Hypertext Transfer Protocol (HTTP): TCP port 8080

  • Post Office Protocol v3 (POP3): TCP port 110110

  • Network Time Protocol (NTP): UDP port 123123

  • Internet Message Access Protocol (IMAP): TCP port 143143

  • Simple Network Management Protocol (SNMP): UDP ports 161161 (Queries) and 162162 (Traps)

  • Lightweight Directory Access Protocol (LDAP): TCP/UDP port 389389

  • Hypertext Transfer Protocol Secure (HTTPS): TCP port 443443

  • SMTP Mail Submission with STARTTLS: TCP port 587587

  • Lightweight Directory Access Protocol Secure (LDAPS): TCP/UDP port 636636

  • Internet Message Access Protocol Secure (IMAPS): TCP port 993993

  • Post Office Protocol v3 Secure (POP3S): TCP port 995995

  • Remote Desktop Protocol (RDP): TCP/UDP port 33893389

Security posture is strengthened by replacing legacy, cleartext protocols with secure alternatives that provide transport encryption, data integrity, and mutual authentication:

  • Replace Telnet (TCP 2323) with SSH (TCP 2222)

  • Replace HTTP (TCP 8080) with HTTPS (TCP 443443)

  • Replace LDAP (TCP 389389) with LDAPS (TCP 636636)

  • Replace POP3 (TCP 110110) with POP3S (TCP 995995)

  • Replace IMAP (TCP 143143) with IMAPS (TCP 993993)

  • Replace cleartext FTP (TCP 20/2120/21) with SFTP (running over SSH on TCP 2222)

Security Frameworks, Standards, and Governance

Confusion pairs table

Cybersecurity frameworks organize defensive measures, attack stages, and compliance controls:

  • NIST Cybersecurity Framework (CSF): NIST CSF 2.0 organizes cybersecurity outcomes into six key Functions: Govern, Identify, Protect, Detect, Respond, and Recover. Version 2.0 added the Govern function to the original five functions from CSF 1.1.

  • Cyber Killchain: Developed by Lockheed Martin, this staged model traces attack progression through distinct phases: Reconnaissance, Weaponization, Delivery, Exploitation, Installation, Command & Control (C2), and Actions on Objectives.

  • MITRE ATT&CK: A detailed knowledge base of observed adversary tactics, techniques, and procedures (TTPs) based on real-world threat intelligence, used for threat modeling and mapping defensive capabilities.

  • ISO/IEC 27001:2022: An international standard specifying requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS).

ISO/IEC 27001 follows a structured implementation and auditing process outlined in Clauses 4 through 10:

  • Clauses 4–10 Structure: Defines organizational context, leadership, planning, support, operations, performance evaluation, and continual improvement.

  • Clause 6.1.2 (Risk Assessment): Defines risk criteria and identifies risks to the confidentiality, integrity, and availability (CIA) of assets within the ISMS scope.

  • Clause 6.1.3 (Risk Treatment & Statement of Applicability): Selection of appropriate controls to treat identified risks. Chosen controls are cross-referenced against the 93 reference controls in Annex A (categorized into Organizational, People, Physical, and Technological groups). The organization documents all selected controls, implementation status, and justifications for any excluded Annex A controls in a formal Statement of Applicability (SoA).

  • Risk Owner Responsibility: Assigned individuals or roles evaluate treatment options, approve risk treatment plans, and formally accept residual risk.

  • Performance Evaluation & Continual Improvement: Clause 9.2 requires planned internal audits, and Clause 9.3 requires management reviews. Clause 10.2 mandates formal root cause analysis, corrective action, and effectiveness checks following security nonconformities.

Other notable governance frameworks and regulatory obligations include:

  • COBIT: Governance and management framework developed by ISACA to align IT operations with enterprise business goals.

  • CIS Controls: A prioritized list of practical, actionable cybersecurity safeguards.

  • Regulatory Obligations: Enforceable legal requirements such as HIPAA (protecting healthcare information) and GDPR (regulating personal data privacy and processing).

  • CMMC & PCI DSS: Formal cybersecurity assessment and compliance standards tailored for U.S. defense contractors and credit card processing environments, respectively.

Hardware Infrastructure and Data States

Information security controls must protect data across all three potential data states:

  • Data at Rest (Storage): Information stored in non-volatile storage media, such as databases, solid-state drives (SSDs), or tape archives. Compromises at this state directly impact confidentiality and integrity.

  • Data in Use (Memory and Compute): Active data loaded into volatile central processing unit (CPU) registers, caches, or system RAM during processing. Malicious code running in memory can inspect or tamper with unencrypted system parameters and operational credentials.

  • Data in Transit (Transmission): Data traveling across communication media via network interfaces, cabling, wireless radios, switches, and routers. Transit controls focus on maintaining confidentiality and integrity using encryption protocols (e.g., TLS, IPsec) and ensuring network availability.

Hardware availability is impacted by environmental factor failures, including power outages, cooling loss, or component damage. System outages can degrade availability across all data states and lead to insecure operational recovery decisions.

Application and Review Scenario Checks

  1. Select TCP or UDP for a software installer download versus a live voice packet transmission:

    • TCP is required for downloading software installers because every byte must be received in exact sequential order without corruption. UDP is suitable for live voice transmissions because lower latency is prioritized over complete reliability; retransmitting missing voice packets causes disruptive delay.

  2. Identify the service names corresponding to port numbers 22, 53, 80, 443, 389, 636, and 3389:

    • Port 22: SSH

    • Port 53: DNS

    • Port 80: HTTP

    • Port 443: HTTPS

    • Port 389: LDAP

    • Port 636: LDAPS

    • Port 3389: RDP

  3. Assess whether a host failing to respond to ping while successfully loading a web page over TCP port 443 represents contradictory behavior:

    • This behavior is not contradictory. Network firewalls or host policies may filter ICMP Echo requests used by ping, while allowing inbound TCP traffic on port 443.

  4. Determine which security framework evaluates weaponization activities occurring prior to delivery:

    • The Cyber Killchain framework explicitly models weaponization as a pre-delivery attack stage.

  5. Explain why DNSSEC fails to conceal domain browsing destinations from network observers:

    • DNSSEC adds digital signatures to authenticate DNS records and confirm data integrity. It does not encrypt DNS lookup traffic, leaving query names visible in plain text.

  6. Evaluate whether an organization implementing ISO/IEC 27001 is restricted strictly to controls listed in Annex A:

    • Organizations are not restricted to Annex A. Clause 6.1.3 permits selecting controls from any framework or source. Organizations must compare their chosen controls against Annex A to ensure no necessary controls were omitted, documenting inclusions and exclusions in the Statement of Applicability (SoA).

  7. Identify missing ISMS elements when an organization holds an ISO/IEC 27001 certificate but lacks internal audit and management review records:

    • The organization lacks evidence of mandatory performance evaluation required under Clause 9.2 (Internal Audit) and Clause 9.3 (Management Review).

  8. Determine who must authorize residual risk when encryption is applied to address disclosure risk but account takeover exposure remains:

    • The designated Risk Owner must approve the risk treatment plan and formally accept the remaining residual risk under Clause 6.1.3.

  9. Distinguish between regulatory obligations and ISMS standards when generic course terminology groups HIPAA, GDPR, and ISO/IEC 27001 together as frameworks:

    • HIPAA and GDPR represent statutory regulatory obligations imposed by legal jurisdictions. ISO/IEC 27001 is an auditable standard detailing formal requirements for building an ISMS.

  10. Identify the framework version when a model specifies Govern, Identify, Protect, Detect, Respond, and Recover:

    • This represents NIST CSF 2.0, which added Govern as its sixth core Function.

  11. Explain how an organization can exclude specific Annex A controls without failing an ISO/IEC 27001 audit:

    • Controls must align with assessed organizational risks. An organization can exclude irrelevant Annex A controls if the exclusion is formally justified and documented within the Statement of Applicability (SoA).

  12. Interpret Nmap scan results showing TCP port 443 open, TCP port 23 closed, and TCP port 445 filtered:

    • Port 443 open indicates an active service accepting HTTPS connections. Port 23 closed indicates the target host is online, but no Telnet daemon is listening on that port. Port 445 filtered indicates a firewall or access control list dropped scan probes, preventing state determination.

  13. Select between HTTP and HTTPS for authenticating users on a login page:

    • HTTPS must be selected. TLS encrypts login credentials in transit, authenticates the server domain, and ensures message integrity. Transport encryption does not resolve application code vulnerabilities or weak user passwords.

  14. Identify the secure replacement for legacy Telnet remote administration:

    • SSH must replace Telnet. SSH encrypts administrative sessions and supports strong mutual authentication.

  15. Explain why SFTP is preferred over standard cleartext FTP for transferring sensitive files:

    • SFTP runs over an encrypted SSH connection, preserving the confidentiality and integrity of credentials and file contents during transfer.

  16. Differentiate a communication protocol from a cybersecurity framework:

    • A protocol provides structural rules enabling technical communications between computer systems. A framework provides an organizational structure for managing operational risk, controls, or attack methodologies.

  17. Justify using the OSI model despite modern network protocols spanning multiple layers:

    • The OSI model provides a structured reference language to isolate network faults and place security controls, even when modern protocols overlap individual layers.

  18. Trace a web request down the protocol stack and identify data unit labels at three stages:

    • An application generates an HTTP request payload. The transport layer packages it into a TCP segment. The network layer encapsulates it into an IP packet. The data link layer formats it into an Ethernet frame, which the physical layer transmits as raw bits.

  19. Determine the primary OSI layer and security impact when a switch MAC address table is overwhelmed:

    • This is a Layer 2 attack (MAC flooding). The primary operational impact is degraded network availability. If the switch falls back to fail-open unicast flooding, confidentiality and data integrity can also be compromised.

  20. Evaluate security protections and residual risks when a user connects via an untrusted Wi-Fi access point to a validated HTTPS destination:

    • Validated TLS encrypts application content and confirms authentic server identity, protecting session confidentiality and integrity. Exposed elements include network traffic metadata (SNI/IP addresses), potential access point availability disruption, and local endpoint client compromises.

  21. Categorize a database file on an SSD, a password held in active memory, and an Ethernet frame on a network cable into data states:

    • Database file on SSD: Data at Rest (Storage).

    • Password in memory: Data in Use (Memory/Compute).

    • Ethernet frame on cable: Data in Transit (Transmission).

  22. Identify flaws in claiming that adopting HTTPS resolves web application vulnerability risks:

    • HTTPS only protects transport data in transit. It does not mitigate application vulnerabilities such as SQL injection, broken access controls, malicious input execution, or compromised backend storage.

  23. Explain the application and limits of using Java interface abstractions as an analogy for network layering:

    • Java interfaces hide internal method implementations behind defined method calls, mirroring how lower network layers expose interfaces to upper layers. The analogy illustrates functional abstraction, but does not model actual low-level packet encapsulation, headers, or hardware communications.

  24. Determine if implementing controls outside Annex A invalidates ISO/IEC 27001 compliance:

    • It does not invalidate compliance. Clause 6.1.3 allows security controls to be selected from any external or internal source, provided they are mapped and cross-referenced against Annex A in the Statement of Applicability (SoA).

  25. Identify the missing ISMS phase when security controls are chosen and approved by a risk owner but no post-implementation evaluation evidence exists:

    • The organization fails Clause 9 (Performance Evaluation) requirements, which demand monitoring, internal audits, and management reviews to confirm control effectiveness.

  26. Evaluate whether excluding an Annex A control purely due to financial implementation cost is acceptable under ISO/IEC 27001:

    • Cost alone is an insufficient justification. Exclusions must be justified by formal risk assessments, context evaluation, and documented rationale within the Statement of Applicability (SoA).

Defense Justification and Mastery Framework

When defending security decisions in technical evaluations, responses should follow a four-part drill:

  1. Selection: Identify the exact concept, protocol, or control chosen.

  2. Alignment: Explain why the choice addresses the specific asset, threat, vulnerability, or operational context.

  3. Impact: Detail the specific improvement, prevention, detection, or recovery capability, directly referencing Confidentiality, Integrity, Availability, or operational goals.

  4. Alternative Justification: Identify alternative options, explain why they were rejected for this scenario, and state the specific conditions under which those alternatives would be preferred.

Self-assessment criteria require verifying that core terms can be defined, confusion pairs distinguished in real-world scenarios, decisions justified using the four-part drill, and governance framework boundaries accurately identified across industry standards.