Skip to content

Reading a Packet: TCP/IP Without the Jargon

What is actually in a packet, why layering matters, and how to reason about traffic you have never seen before.

Beginner 8 min read Networking

What you will learn

  • What each layer of the stack contributes
  • How to read a packet capture without memorising fields
  • Why ports are a convention, not a rule
  • Where encryption starts and stops

Introduction

Network diagrams hide more than they show. A packet capture does not. If you can read a capture you can answer questions no diagram will settle, and the skill takes an afternoon to start and a career to finish.

How it works

Each layer wraps the one above it. Ethernet carries IP, IP carries TCP or UDP, and TCP carries whatever the application speaks. Reading a packet is peeling that wrapping in order and asking, at each layer, who is talking to whom and about what.

Ports are convention. Nothing forces a web server onto 443, and attackers rely on people assuming otherwise. What identifies a protocol is the shape of the traffic, not the number it arrived on.

Common risks

Assuming a port implies a protocol misses tunnelled traffic entirely. Assuming TLS means safe misses everything happening inside a legitimately encrypted channel to a malicious destination.

How to detect it

Baseline what normal looks like on your network before you need to spot abnormal. Watch for protocol on unusual ports, long-lived connections to unfamiliar destinations, and DNS queries with unusual entropy.

How to defend

Segment so that a compromised host cannot reach everything. Log DNS. Terminate and inspect TLS where law and policy allow. Alert on new outbound destinations from server subnets rather than trying to enumerate bad ones.

Security checklist

  • Baseline normal traffic first
  • Log and retain DNS queries
  • Segment server networks
  • Alert on new outbound destinations
  • Do not trust port numbers
Authorised lab

The Network Reconnaissance range gives you a network to map from a single foothold. Never apply these techniques to a system you do not own or have written permission to test.