Computer Networking: A Top-Down Approach - Chapter 1 Complete Study Guide

Introduction to Computer Networking and the Internet

Computer Networking: A Top-Down Approach textbook cover
  • Computer networking provides the foundational infrastructure that powers modern distributed applications and global communication.

  • A central unifying scenario illustrates end-to-end network operation: uploading a single 25MB25\,\text{MB} file from a King Faisal University (KFU) classroom to a remote cloud destination.

  • The journey of data involves passing through campus edge devices, regional and national Internet Service Providers (ISPs), content provider networks, and large-scale data centers.

  • The Internet is fundamentally defined as a "network of networks," operating through interconnected packet switches, communication links, and standardized protocols.

What is the Internet? Nuts-and-Bolts and Service Views

Overview of Internet components including end systems, routers, and links

The "Nuts and Bolts" View

  • Hosts / End Systems: Devices connected to the Internet that host and run network applications. Examples include traditional desktop computers, laptops, enterprise servers, smartphones, and an expanding ecosystem of Internet of Things (IoT) devices.

  • Packet Switches: Specialized devices that forward chunks of data (packets) through the network from source to destination.

    • Routers: Forward packets across network boundaries, typically located in the network core.

    • Link-Layer Switches: Forward packets within localized access networks.

  • Communication Links: Physical media connecting devices and packet switches, including twisted-pair copper wire, coaxial cable, optical fiber, and wireless radio spectrum. Communication performance is governed by transmission rate or bandwidth RR, measured in bits per second (bps\text{bps}).

  • Networks: Collections of interconnected packet switches, communication links, and end systems managed by a single administrative entity (e.g., home networks, enterprise networks, mobile operator networks, regional ISPs, content provider networks).

Examples of IoT devices connected to the Internet
  • Internet-Connected "Things" (IoT Devices):

    • Web-enabled toasters with weather forecasting capability.

    • Wearable fitness trackers (e.g., Fitbit) and Augmented Reality (AR) glasses.

    • Sensorized bed mattresses for monitoring sleep metrics.

    • Smart diapers and baby monitor systems (e.g., Lumi by Pampers).

    • IP-enabled security cameras (e.g., Swann) and Voice over IP (VoIP) phones.

    • Medical devices such as pacemakers and home cardiac monitors (e.g., Biotronik Edora 8 DR-T).

    • Smart energy monitors (e.g., Kill A Watt meter) and IP picture frames.

    • Connected transportation systems including autonomous cars (e.g., Tesla), e-bikes, Lime e-scooters, and smart traffic lights.

The "Services" View

  • The Internet serves as a global computing infrastructure that provides services to distributed network applications such as the World Wide Web, streaming video, email, online gaming, peer-to-peer file sharing, e-commerce, and mobile app services.

  • Application Programming Interface (API): A set of rules and software hooks provided by the network layer that enables software programs running on end systems to request data transmission to specific destination applications.

What is a Protocol?

Human protocol vs network protocol communication sequence
  • Definition of a Protocol: A protocol defines the format, the order of messages sent and received among network entities, and the actions taken on message transmission or receipt.

  • Human Communication Protocols: In human interactions, protocols govern polite conversations. For instance, a person says "Hi", receives a reply "Hi", asks "Got the time?", and receives the answer "2:00". If an unexpected response occurs, the protocol fails.

  • Network Communication Protocols: In network systems, machines execute rigorous protocol exchanges:

    1. The client sends a Transmission Control Protocol (TCP) connection request.

    2. The server responds with a TCP connection response.

    3. The client issues a Hypertext Transfer Protocol (HTTP) request, such as GET http://gaia.cs.umass.edu/kurose_ross.

    4. The server returns the requested web file <file>.

  • Internet Standards: Formal protocol specifications managed by international bodies:

    • IETF (Internet Engineering Task Force): Standardizes core Internet protocols through documents known as RFCs (Request for Comments).

    • Common protocol standards include HTTP, IP, TCP, User Datagram Protocol (UDP), Wi-Fi (IEEE 802.11), and Ethernet (IEEE 802.3).

The Network Edge: Hosts, Access Networks, and Physical Media

Access network technologies connecting end systems to the edge router

Network Edge Overview

  • End Systems (Hosts): Reside at the edge of the Internet. Categorized into:

    • Clients: Consumer devices (laptops, desktops, smartphones, IoT nodes).

    • Servers: High-capacity machines situated in data centers that host web pages, stream video, or process cloud workloads.

  • Access Networks: Physical links that connect an end system to the first router (also called the "edge router") along the path to any other remote host.

Access Network Technologies

Cable access network architecture and frequency division multiplexing
  • Cable Network (Hybrid Fiber-Coaxial / HFC):

    • Uses existing cable television infrastructure made of combined fiber and coaxial cable.

    • Operates using Frequency Division Multiplexing (FDM): Different channels (video, downstream data, upstream data, control) are assigned separate frequency bands over a single physical cable.

    • Connects homes via a cable modem to a Cable Modem Termination System (CMTS) located at the cable headend.

    • Shared Medium: All residences attached to a single cable line share the total bandwidth; concurrent high-volume usage by neighbors can reduce throughput.

  • Digital Subscriber Line (DSL):

    • Reuses existing traditional copper telephone lines to connect to a telephone company Central Office (CO).

    • Voice and high-speed data are transmitted at different frequencies over a dedicated point-to-point line.

    • A splitter separates incoming signals into data signals (directed to the DSL modem) and telephone voice signals (frequencies below 4kHz4\,\text{kHz}).

    • At the Central Office, a DSL Access Multiplexer (DSLAM) combines data signals from multiple subscribers and routes them to the ISP network.

    • Dedicated Access: Subscribers do not share line capacity with neighbors.

  • Fiber to the Home (FTTH):

    • Direct optical fiber connection from the central office to individual residences.

    • Provides ultra-high symmetric or asymmetric bandwidth (gigabit speeds) via Optical Network Terminations (ONT).

  • Enterprise Access Networks (Wired Ethernet & Wi-Fi):

    • Used by universities, corporate offices, and institutions.

    • Hosts connect via wired Ethernet switches using twisted-pair cables at rates of 100Mbps100\,\text{Mbps}, 1Gbps1\,\text{Gbps}, or 10Gbps10\,\text{Gbps}.

    • Hosts connect wirelessly to enterprise Wireless Access Points (APs) connected directly to campus network switches.

  • Wireless Access Networks:

    • Wireless LANs (Wi-Fi / IEEE 802.11): Shared wireless medium operating over short range (10100m10\text{--}100\,\text{m}) to connect end systems within a home or enterprise building.

    • Wide-Area Wireless Networks (Cellular): Provided by cellular mobile operators through base stations (cell towers) over wide coverage areas (10100km10\text{--}100\,\text{km}). Employs technologies like 4G LTE and 5G.

Physical Media

  • Guided Media: Signals propagate within solid physical conduits.

    • Twisted-Pair (TP) Copper Wire: Consists of two insulated copper wires twisted in a spiral pattern to reduce electromagnetic interference. Used in Ethernet (Cat 5e, Cat 6, Cat 7) and DSL.

    • Coaxial Cable: Consists of two concentric copper conductors separated by insulation. Offers high data transmission rates across shared or point-to-point topologies.

    • Fiber-Optic Cable: Thin, flexible glass fibers conducting pulses of light. Offers extremely high-speed transmission (tens to hundreds of gigabits per second), exceptionally low attenuation, and immunity to electromagnetic noise.

  • Unguided Media: Signals propagate freely through atmosphere, water, or outer space.

    • Terrestrial Radio: Signals travel through the electromagnetic spectrum over point-to-point or omnidirectional radio channels (Wi-Fi, cellular networks, microwave links).

    • Satellite Radio: Satellite links relay microwave signals between earth stations. Geostationary satellites (GEO) sit at fixed locations overhead but introduce propagation delays of approximately 280ms280\,\text{ms}. Low Earth Orbit (LEO) satellites orbit closer to Earth, significantly reducing latency.

The Network Core: Packet Switching vs. Circuit Switching

The Network Core

  • The network core consists of a mesh of interconnected routers that route packets through the global Internet.

  • Data sent from a host application is segmented into smaller pieces called packets of length LL bits.

  • Packets travel through communication links at transmission rate RR bits per second (bps\text{bps}).

Packet Switching and Store-and-Forward

  • Store-and-Forward Transmission: A packet switch must receive the entire packet before it can begin transmitting the first bit of that packet onto the outbound link.

  • Transmission Delay Formula: The time required to transmit a packet of length LL bits onto a link with transmission rate RR bps is given by: dtrans=LR\text{d}_{\text{trans}} = \frac{L}{R}

  • Multi-Hop Path Example: For a packet of length LL traveling across QQ hops (links) of uniform rate RR, the total transmission delay without queuing or propagation delay is: Total Transmission Delay=Q×LR\text{Total Transmission Delay} = Q \times \frac{L}{R}

  • Queuing and Loss: Routers maintain output buffers (queues) for each link. If the packet arrival rate exceeds the output link transmission capacity RR, arriving packets enter a queue and experience queuing delay. If the queue buffer becomes completely full, newly arriving packets are dropped, resulting in packet loss.

Circuit Switching

  • In Circuit-Switched Networks, end-to-end network resources (buffers, bandwidth, link transmission rate) are dedicated and reserved exclusively for the duration of a communication session between sender and receiver.

  • Traditional telephone networks use circuit switching.

  • Guaranteed Performance: Since link resources are reserved, transmission rates are constant with zero queuing delay.

  • Inefficiency: Reserved circuits remain idle during silent periods when no data is being actively transmitted, leading to wasted capacity.

  • Multiplexing Methods in Circuit Switching:

    • Frequency Division Multiplexing (FDM): Continuous spectrum is divided into discrete narrow frequency bands; each active connection receives a dedicated band.

    • Time Division Multiplexing (TDM): Transmission time is divided into fixed-duration frames containing a fixed number of time slots; each connection receives a dedicated slot in every frame.

Packet Switching vs. Circuit Switching

  • Packet switching supports significantly greater resource sharing ("statistical multiplexing") than circuit switching.

  • Quantitative Example:

    • A link has a bandwidth of 1Mbps1\,\text{Mbps} (1000kbps1000\,\text{kbps}).

    • Each user requires 100kbps100\,\text{kbps} when active, but is active only 10%10\% (0.100.10) of the time.

    • Circuit Switching Capacity: Can support at most 1010 simultaneous users (10×100kbps=1000kbps10 \times 100\,\text{kbps} = 1000\,\text{kbps}).

    • Packet Switching Capacity: If N=35N = 35 users are connected, the probability that more than 1010 users are active simultaneously is given by the binomial distribution tail: P(more than 10 active users)=k=1135(35k)(0.10)k(0.90)35k<0.0004P(\text{more than } 10 \text{ active users}) = \sum_{k=11}^{35} \binom{35}{k} (0.10)^k (0.90)^{35-k} < 0.0004

    • Packet switching easily supports 35 users with less than a 0.04%0.04\% chance of experiencing link congestion.

  • Summary Comparison:

    • Packet switching is superior for bursty data traffic (great resource utilization, simpler hardware).

    • Circuit switching is preferred when strict bandwidth reservations and real-time audio/video guarantees are required without congestion control.

Internet Structure and Hierarchy: A Network of Networks

Evolution of the Global Internet Architecture

  • End systems connect directly to local Access ISPs.

  • Connecting every access ISP directly to every other access ISP is impossible because it requires O(N2)O(N^2) individual connections, which does not scale.

  • Tiered ISP Structure:

    • Global Transit ISPs: Access ISPs pay global transit ISPs to connect them to all other access points worldwide.

    • Competition and Regional Networks: Multiple competitive global Tier-1 ISPs exist globally.

    • Regional ISPs: Intermediary networks connecting local access ISPs to global Tier-1 networks.

    • Point-of-Presence (PoP): A group of routers in an ISP network where customer ISPs connect to the provider ISP.

    • Peering Links: Direct non-monetary or contractual links established between two competitor ISPs to exchange data traffic directly without paying transit fees to a third party.

    • Internet Exchange Points (IXPs): Third-party physical facilities where multiple national, regional, and access ISPs meet to establish peering links with one another.

    • Content Provider Networks: Private corporate IP networks operated by large content companies (e.g., Google, Microsoft, Akamai). They connect data centers directly to regional access ISPs or IXPs, bypassing the Tier-1 public Internet backbone to lower costs and reduce user latency.

Performance Metrics: Delay, Loss, and Throughput

Four Sources of Nodal Delay

dnodal=dproc+dqueue+dtrans+dprop\text{d}_{\text{nodal}} = \text{d}_{\text{proc}} + \text{d}_{\text{queue}} + \text{d}_{\text{trans}} + \text{d}_{\text{prop}}

  1. Processing Delay (dproc\text{d}_{\text{proc}}):

    • Time required by a router to inspect the packet header, check for bit-level errors, and determine the appropriate outbound interface using its forwarding table.

    • Typically microsecond (μs\mu\text{s}) scale.

  2. Queuing Delay (dqueue\text{d}_{\text{queue}}):

    • Time a packet spends waiting in a router queue buffer to be transmitted onto the link.

    • Depends directly on network traffic intensity and router queue length.

  3. Transmission Delay (dtrans\text{d}_{\text{trans}}):

    • Time required to push all packet bits onto the physical communication link.

    • Formula: dtrans=LR\text{d}_{\text{trans}} = \frac{L}{R}

    • Where LL is the packet length in bits and RR is the link transmission rate (bps\text{bps}).

  4. Propagation Delay (dprop\text{d}_{\text{prop}}):

    • Time required for a single bit to travel from the start of the link to the destination node over the physical medium.

    • Formula: dprop=ds\text{d}_{\text{prop}} = \frac{d}{s}

    • Where dd is the physical length of the link in meters and ss is the signal propagation speed in the medium (2×108m/s\approx 2 \times 10^8\,\text{m/s} in fiber/copper).

Traffic Intensity and Queuing Delay

  • Traffic Intensity Parameter: Defined as LaR\frac{L \cdot a}{R}, where:

    • LL = packet length (bits)

    • aa = average packet arrival rate (packets per second)

    • RR = link transmission rate (bps)

  • Behavior of Traffic Intensity:

    • If LaR0\frac{L \cdot a}{R} \sim 0: Average queuing delay is extremely small, approaching zero.

    • If LaR1\frac{L \cdot a}{R} \rightarrow 1: Queuing delay increases exponentially as arrivals become clustered.

    • If LaR>1\frac{L \cdot a}{R} > 1: Work arrives faster than the router can transmit it; queuing delay becomes infinite and buffer overflow leads to packet loss.

Caravan Analogy for Transmission vs. Propagation Delay

  • Imagine a caravan of 1010 cars (packets) traveling through a tollbooth (router) onto a highway toward a second tollbooth located 100km100\,\text{km} away.

  • Tollbooth processing rate (transmission speed): Services 11 car every 12seconds12\,\text{seconds} (5 cars/minute5\text{ cars/minute}).

  • Car highway speed (propagation speed): 100km/h100\,\text{km/h}.

  • Scenario Analysis:

    • Time to service all 1010 cars at tollbooth 1 (dtrans\text{d}_{\text{trans}}): 10×12seconds=120seconds=2minutes10 \times 12\,\text{seconds} = 120\,\text{seconds} = 2\,\text{minutes}.

    • Time for the last car to travel 100km100\,\text{km} to tollbooth 2 (dprop\text{d}_{\text{prop}}): 1hour=60minutes1\,\text{hour} = 60\,\text{minutes}.

    • Total time for the entire caravan to arrive at tollbooth 2: 62minutes62\,\text{minutes}.

  • Fast Propagation Variant: If cars travel at 1000km/h1000\,\text{km/h} and tollbooth service time is 1minute1\,\text{minute} per car:

    • First car travels 100km100\,\text{km} in 0.1hours=6minutes0.1\,\text{hours} = 6\,\text{minutes}.

    • The first car arrives at tollbooth 2 while remaining cars are still waiting in line at tollbooth 1.

Network Diagnostic Tools: Traceroute

  • Traceroute: A diagnostic program that measures end-to-end packet delay along a path between source and destination.

  • Sends a sequence of probe packets (ICMP or UDP) with time-to-live (TTL) fields set to 1,2,3,,i1, 2, 3, \dots, i.

  • When hop ii receives a packet with TTL=1\text{TTL} = 1, it drops the packet and sends an ICMP "Time Exceeded" message back to the source.

  • The source records the round-trip time (RTT) for three separate probe transmissions to each intermediate hop.

Throughput

  • Throughput: The rate (bits per unit time) at which data bits are successfully delivered from sender to receiver.

    • Instantaneous Throughput: Measured rate at a precise instant in time.

    • Average Throughput: Total data transferred divided by total elapsed delivery duration.

  • Bottleneck Link: The bottleneck link along an end-to-end network path is the specific link that constrains overall end-to-end throughput.

  • For a path with server rate RsR_s, client rate RcR_c, and shared core link capacity RR, throughput is: Throughput=min(Rs,Rc,RN)\text{Throughput} = \min\left(R_s, R_c, \frac{R}{N}\right)

  • The slowest transmission link along the route limits maximum achievable end-to-end performance.

Network Security, Threats, and Lines of Defense

Network Security Realities

  • The original Internet architecture was designed under the assumption of a community of mutually trusting end users and connected institutions.

  • Modern computer networks face aggressive malicious attacks requiring explicit defense mechanisms across all protocol layers.

Common Attack Vectors

  • Packet Sniffing: Passive capture of data frames passing through an unencrypted or promiscuous physical medium (e.g., public Wi-Fi or hub-based Ethernet). Threat actors read payload contents, stealing passwords, personal identification, and confidential tokens.

  • IP Spoofing: Injecting network packets with a forged source IP address to impersonate an authorized user or server.

  • Denial of Service (DoS) / Distributed Denial of Service (DDoS):

    • An attacker overwhelms a target server, service, or network link with bogus traffic.

    • DDoS Execution: Attackers compromise vulnerable Internet devices to construct a controlled botnet, then direct thousands of infected nodes to flood the victim simultaneously, consuming server memory, CPU, or link bandwidth.

Lines of Defense

  • Firewalls: Specialized hardware or software devices that inspect packet headers and filter incoming/outgoing traffic based on security policies.

  • Encryption and Cryptography: Encrypting payloads using TLS/SSL or IPsec to protect confidentiality, integrity, and authenticity.

  • Authentication: Verifying identity using digital certificates, passwords, and multi-factor authentication (MFA).

  • Integrity Checks: Cryptographic hash functions and digital signatures to detect payload tampering.

  • Intrusion Detection Systems (IDS) / Intrusion Prevention Systems (IPS): Deep packet inspection systems that detect and block malicious traffic signatures.

Protocol Layering, Service Models, and Encapsulation

Why Layering?

  • Layering provides a structured modular framework for designing complex networking systems.

  • Advantages:

    • Explicit identification and organization of system components.

    • Simplified system maintenance and software updates: changing the implementation of a single layer does not impact other layers as long as layer service interfaces remain constant.

  • Air Travel Analogy: Air travel uses a layered system structure:

    • Ticket purchase -> Baggage check -> Gate boarding -> Runway takeoff -> Flight routing -> Runway landing -> Gate exit -> Baggage claim -> Ticket refund/processing.

The 5-Layer Internet Protocol Stack

  1. Application Layer: Supports network applications and distributed end-user software processes.

    • Protocols: HTTP, Simple Mail Transfer Protocol (SMTP), File Transfer Protocol (FTP), Domain Name System (DNS), Secure Shell (SSH).

    • Data Unit: Message.

  2. Transport Layer: Provides process-to-process data delivery services between application endpoints.

    • Protocols: TCP (reliable, connection-oriented, flow control, congestion control) and UDP (unreliable, connectionless, lightweight).

    • Data Unit: Segment.

  3. Network Layer: Routes data packets (datagrams) from host to host across multiple interconnected networks.

    • Protocols: IP (IPv4, IPv6), routing protocols (BGP, OSPF, RIP).

    • Data Unit: Datagram.

  4. Link Layer: Transfers data frames between neighboring network nodes over a single communication link.

    • Protocols: Ethernet (IEEE 802.3), Wi-Fi (IEEE 802.11), Point-to-Point Protocol (PPP).

    • Data Unit: Frame.

  5. Physical Layer: Coordinates bit-level signal transmission across physical media (copper, optical fiber, radio frequency waves).

    • Data Unit: Bits.

The ISO/OSI Reference Model

  • The International Organization for Standardization (ISO) proposed the Open Systems Interconnection (OSI) 7-layer reference model, adding two layers between Application and Transport:

    • Presentation Layer: Responsible for data syntax translation, data compression, and encryption/decryption (e.g., string encoding formats).

    • Session Layer: Coordinates session establishment, checkpointing, synchronization, and connection recovery.

  • Internet Architecture Difference: The Internet protocol stack omits distinct session and presentation layers; if an application requires these functions, the application developer implements them directly inside the Application Layer.

Encapsulation and Decapsulation

  • Encapsulation Process at Source Host:

    1. The Application layer generates an application Message M$.\n 2. The Transport layer attaches a Transport Header H_t,creatingaSegment(, creating a **Segment** (H_t + M).\n 3. The Network layer attaches a Network Header H_n,creatingaDatagram(, creating a **Datagram** (H_n + H_t + M).\n 4. The Link layer attaches a Link Header H_l,creatingaFrame(, creating a **Frame** (H_l + H_n + H_t + M).\n 5. The Physical layer transmits raw physical bits over the medium.\n* **Nested Structure Metaphor**: Similar to Matryoshka (Russian nesting) dolls, each layer wraps the payload received from the layer above within its own protocol header.\n* **Decapsulation Process**: Intermediate packet switches and destination hosts perform reverse decapsulation:\n * Link-layer switches inspect and decapsulate up to the Link layer (H_l).\n * Network-layer routers inspect and decapsulate up to the Network layer (H_n).\n * Destination hosts decapsulate up through all layers to extract the original message M$.

  • Wireshark Packet Analyzer: A software tool that captures physical frames from a network interface card (via pcap/npcap drivers) to inspect header fields and payloads layer by layer.

History of Computer Networking

  • 1961–1972: Early Packet-Switching Principles:

    • 1961: Leonard Kleinrock publishes first queuing theory paper demonstrating packet switching efficiency.

    • 1964: Paul Baran investigates packet switching for survivable military communication.

    • 1967: Advanced Research Projects Agency (ARPA) conceives ARPANET.

    • 1969: First operational ARPANET node deployed at UCLA, followed by SRI, UCSB, and Utah. First network message "LO" transmitted.

    • 1972: ARPANET public demonstration; Network Control Protocol (NCP) implemented; Ray Tomlinson writes first email software.

  • 1972–1980: Internetworking and Heterogeneous Networks:

    • 1970: ALOHANET operational in Hawaii (wireless packet network).

    • 1973: Bob Metcalfe conceives Ethernet in PhD thesis.

    • 1974: Vinton Cerf and Robert Kahn outline architecture for interconnecting heterogeneous networks (TCP/IP specification).

    • Late 1970s: Vendor proprietary networks (IBM SNA, DECnet) and X.25 standard.

  • 1980–1990: New Protocols and Network Proliferation:

    • January 1, 1983: Official switchover to TCP/IP on ARPANET ("Flag Day").

    • 1983: Domain Name System (DNS) invented by Paul Mockapetris.

    • 1986: NSFNET created to link supercomputing centers (56kbps56\,\text{kbps} backbone, later upgraded to 1.5Mbps1.5\,\text{Mbps} T1).

    • 1988: Van Jacobson invents TCP congestion control.

  • 1990s–2000s: Commercialization, World Wide Web, and Mass Adoption:

    • Early 1990s: Tim Berners-Lee invents World Wide Web (HTML, HTTP, Web browser, Web server at CERN).

    • 1991: NSF lifts commercial restrictions on NSFNET.

    • Mid-1990s: Commercial ISPs replace NSFNET backbone; browser proliferation (Mosaic, Netscape).

    • Late 1990s–2000s: Growth of e-commerce, Google search engine, peer-to-peer networks (Napster, BitTorrent, Skype), instant messaging.

  • 2005–Present: Scale, SDN, Mobility, and Cloud:

    • Global mobile internet deployment (4G LTE, 5G, ubiquitous Wi-Fi).

    • Hyper-scale data centers and cloud computing infrastructures.

    • Implementation of Software-Defined Networking (SDN) and Network Function Virtualization (NFV).

    • Dominance of private Content Provider Networks (Google, Akamai, Netflix, Microsoft).

Conceptual Summary: Four Lenses of Networking

  • Architecture Lens: End systems (hosts), access networks (DSL, Cable, Fiber, Wi-Fi, Cellular), edge routers, regional/national ISPs, content provider networks, data centers.

  • Performance Lens: Bandwidth (RR), buffers, nodal processing delay (dproc\text{d}_{\text{proc}}), queuing delay (dqueue\text{d}_{\text{queue}}), transmission delay (dtrans=L/R\text{d}_{\text{trans}} = L/R), propagation delay (dprop=d/s\text{d}_{\text{prop}} = d/s), packet loss, throughput limits (bottlenecks).

  • Organization Lens: Standardized protocols (RFCs, IETF), 5-layer Internet protocol stack (Application, Transport, Network, Link, Physical), service models, headers, encapsulation/decapsulation.

  • Risk Lens: Vulnerabilities (packet sniffing, IP spoofing, DoS/DDoS attacks) and multi-layered defenses (firewalls, encryption, authentication, integrity verification, IDS/IPS).