By now, you have learned about the main networking protocols in SECFND or other courses. In this chapter, we will learn how to differentiate normal header content from abnormal and rogue content to conduct an initial analysis of network intrusions.
Protocol headers contain a lot of information, so rapid identification of abnormalities is key to avoiding confusion in the workplace and in the exam. A lot of time can be lost on the exam if candidates cannot exclude normal data rapidly.
The following topics will be covered in this chapter:
- Physical and data link layer (Ethernet) frame headers
- Network layer (IPv4, IPv6, and ICMP) packet headers
- Transport layer (TCP and UDP) segment and datagram headers
- Application layer (HTTP) headers