This comprehensive study guide for Cyber Forensics Core Paper-II covers fundamental networking models, IP routing protocols, subnetting architectures, virtual LAN management, and application-layer communication protocols essential for forensic network packet analysis, evidence acquisition, and cyber incident investigations.
Unit 1: Networking Models and Encapsulation Architecture
Digital forensics investigators must understand the underlying networking architectures that govern data transmission across local and wide area networks. Communication models establish the standardized layers through which electronic evidence travels from an application payload down to physical electronic pulses:
- The OSI 7-Layer Model: The Open Systems Interconnection reference model partitions network communication into seven discrete layers: Physical (bits and transmission media), Data Link (MAC addressing, frame synchronization, switch operations), Network (logical IP addressing and packet routing), Transport (end-to-end reliability, segmentation, port addressing), Session (dialogue control and session management), Presentation (data encryption, compression, and character syntax translation), and Application (user-facing network services such as HTTP, FTP, and SMTP).
- The TCP/IP 4-Layer Stack: The practical operational model of the Internet integrates OSI layers into four functional tiers: Network Access / Link Layer, Internet Layer, Transport Layer, and Application Layer.
- MAC Addressing and OUI Forensics: A Media Access Control address is a 48-bit physical identifier expressed as six hexadecimal octets (for example, 00:1A:2B:3C:4D:5E). The first 24 bits represent the Organizationally Unique Identifier (OUI) assigned by IEEE to specific hardware manufacturers, enabling investigators to identify hardware vendors during physical device triage. The remaining 24 bits represent the vendor-assigned Network Interface Controller (NIC) serial identifier.
- Internet Protocol (IPv4 vs IPv6): IPv4 utilizes 32-bit addressing with a variable header length (20 to 60 bytes) containing critical forensic fields: Version, Internet Header Length (IHL), Total Length, Identification (for packet reassembly), Flags (Don't Fragment - DF, More Fragments - MF), Fragment Offset, Time to Live (TTL - useful for OS fingerprinting), Protocol identifier (6 for TCP, 17 for UDP, 1 for ICMP), and Header Checksum. IPv6 expands address space to 128 bits with a fixed 40-byte base header and flexible extension headers.
- Transport Protocols and TCP Control Flags: Transmission Control Protocol (TCP) provides connection-oriented, reliable delivery via the classic three-way handshake (SYN, SYN-ACK, ACK) and utilizes control flags (SYN, ACK, FIN, RST, PSH, URG) to manage connection lifecycle. User Datagram Protocol (UDP) provides low-latency, connectionless transmission. Logical port numbers range from 0 to 65535, categorized into Well-Known ports (0 to 1023), Registered ports (1024 to 49151), and Dynamic/Private ephemeral ports (49152 to 65535).
- Encapsulation and Payload Analysis: During encapsulation, each layer prepends a protocol header containing routing and control metadata around the data payload. De-encapsulation reverses this process at the receiving host. Forensics specialists extract reconstructed payloads from PCAP packet captures to identify unauthorized exfiltration, malicious binaries, or protocol anomalies.
Unit 2: Static and Dynamic IP Routing Protocols
Routing protocols determine the path through which data packets traverse interconnected autonomous systems and local networks:
- Static vs Dynamic Routing: Static routing relies on manually configured routing tables suitable for predictable, small-scale network segments. Dynamic routing uses automated routing protocols to discover routes, compute optimal network paths, and adjust to topology changes in real time.
- Interior Gateway Protocols (IGP):
- RIPv1: A classful distance-vector protocol using hop count (maximum 15 hops) as its sole metric, broadcasting entire routing tables periodically without subnet mask support.
- RIPv2: An enhanced classless distance-vector protocol supporting Variable Length Subnet Masking (VLSM), Classless Inter-Domain Routing (CIDR), multicast route updates to 224.0.0.9, and MD5 cryptographic authentication.
- OSPF (Open Shortest Path First): A link-state protocol that constructs a complete topological link-state database (LSDB) using Dijkstra's Shortest Path First algorithm, supporting hierarchical multi-area designs and fast route convergence.
- EIGRP (Enhanced Interior Gateway Routing Protocol): A hybrid distance-vector protocol utilizing the Diffusing Update Algorithm (DUAL) and a composite metric based on bandwidth, delay, reliability, and channel load.
- Network Address Translation (NAT) and IP Spaces: NAT enables private RFC 1918 IPv4 networks (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) to map to public routable IP addresses. Port Address Translation (PAT) maps multiple internal private addresses to a single public IP using ephemeral source port mapping. Special address ranges include loopback addresses (127.0.0.0/8) and Automatic Private IP Addressing (APIPA 169.254.0.0/16), assigned when DHCP servers fail to respond.
- Domain Segmentation: Broadcast domains comprise all network nodes that receive Layer 2 broadcast frames, whereas multicast domains restrict traffic to subscribed group hosts.
Unit 3: Subnetting, Variable-Length Subnet Masks, and WAN Technologies
Subnetting partitions contiguous IP address space into smaller logical subnetworks to optimize routing efficiency and enhance boundary security:
- Subnet Masks and CIDR: A 32-bit subnet mask delineates the network prefix from host bits. Classless Inter-Domain Routing (CIDR) notation (such as /24, /27, or /30) replaces rigid classful boundaries (Classes A, B, C) with flexible bitwise masks.
- Wildcard Masks: Calculated by subtracting the subnet mask from 255.255.255.255, wildcard masks are utilized in router Access Control Lists (ACLs) and OSPF network statements to match specific IP ranges.
- WAN Architectures: Wide Area Network infrastructures connect geographically dispersed sites:
- Frame Relay: A packet-switched technology utilizing Data Link Connection Identifiers (DLCI) to identify Permanent Virtual Circuits (PVCs) with guaranteed Committed Information Rates (CIR).
- MPLS (Multiprotocol Label Switching): An efficient data-forwarding architecture using short numerical path labels rather than complex routing table lookups. Label Edge Routers (LER/Edge Routers) append or strip labels at ingress and egress points, while Provider Edge (PE) and Customer Edge (CE) routers manage customer network boundaries.
- DTE vs DCE: Data Terminal Equipment (DTE, such as customer routers) interfaces with Data Communication Equipment (DCE, such as CSU/DSU modems) which controls clock speed and physical signaling rates.
Unit 4: Virtual LANs, Trunking, and Traffic Segmentation
Virtual LANs (VLANs) segment physical switches into multiple logical broadcast domains, isolating sensitive departmental traffic and preventing network sniffing across broadcast boundaries:
- Access vs Trunk Links: Access ports belong to a single untagged VLAN and connect end-user host machines. Trunk links carry multi-VLAN traffic across interconnected switches by encapsulating Ethernet frames with IEEE 802.1Q four-byte tags containing a 12-bit VLAN Identifier (VID).
- VLAN Trunking Protocol (VTP): Facilitates centralized VLAN configuration across a VTP domain. VTP operates in Server mode (creates/modifies VLANs), Client mode (receives updates without local configuration rights), and Transparent mode (forwards VTP advertisements locally without synchronizing). VTP Configuration Revision numbers must be monitored to prevent unintended VLAN database overwrites.
- Inter-VLAN Routing and Domain Isolation: Communication between isolated VLANs requires Layer 3 routing via external routers or Layer 3 multi-layer switches. VLAN implementation eliminates broadcast storms and creates isolated collision domains on every switchport.
Unit 5: Forensic Analysis of Core Network Communication Protocols
Forensic packet inspection relies on detailed knowledge of application and support protocol mechanics:
- Address Resolution (ARP and RARP): ARP maps Layer 3 IPv4 addresses to Layer 2 MAC addresses through broadcast requests and unicast replies. Forensic analysts scrutinize ARP tables to detect ARP poisoning and man-in-the-middle attacks. RARP (now superseded by DHCP) mapped physical hardware addresses back to IP addresses.
- Internet Control Message Protocol (ICMP): Generates network error messages and operational diagnostics (such as ping echo request/reply and traceroute TTL expiration), frequently analyzed to detect covert tunneling or denial of service activity.
- Application Protocols:
- HTTP / FTP / TFTP: Hypertext Transfer Protocol transfers web traffic; File Transfer Protocol utilizes port 21 for control commands and port 20 for active data transfers (or negotiated ephemeral ports in passive mode); Trivial FTP (TFTP) uses UDP port 69 for lightweight firmware boot operations.
- Mail Protocols: SMTP (port 25/587) handles mail relay between servers; POP3 (port 110/995) downloads mail locally; IMAP (port 143/993) synchronizes email mailboxes across multiple devices.
- Remote Management: Telnet transmits plain-text console data over port 23; SNMP monitors network node health via Management Information Base (MIB) trees and community strings.
- DNS and DHCP: Domain Name System resolves human-readable names to IP addresses across hierarchical servers, utilizing query/response flags (AA, TC, RD, RA); DHCP manages dynamic IP address allocation through the four-step DORA (Discover, Offer, Request, Acknowledge) handshake.
- Forensic Application and Legal Context: Documenting network packet captures, log trails, and protocol headers provides admissible evidence aligned with the cyber legal framework and electronic evidence standards under Section 65B of the Indian Evidence Act. Investigators frequently consult digital forensics and cyber investigation services to maintain chain of custody and validate evidentiary integrity during complex forensic audits.
