PROTOCOLS-FUN . THE MAP

Network Protocol Headers

the map
L7 . Application L4 . Transport L3 . Internet L2 . Link L0 . Legacy / Other DNS HTTP DHCP SNMP BGP UDP TCP IPv4 ICMP IPv6 ARP Ethernet Wi-Fi PPP IPX POCSAG SITOR IMP-IMP
Application
Transport
Internet
Link
Legacy / Other
protocol index
additional resources
ddos Attack Anatomy: the bytesSYN flood, spoofing, amplification and Rapid Reset, field by field, plus the history → defence Attack & Mitigationhow the stack gets attacked and defended - floods & amplification, HTTP/2 Rapid Reset, bot abuse, JA4 fingerprinting, defense in depth → capture Capture & Filtersee hostile traffic on the wire - BPF vs display filters, tcpdump/tshark/Wireshark, offset matching, and the u32/nftables bridge to dropping it → ipv6 IPv6 & IPv4 Header Anatomythe two headers that open every packet, byte by byte - the ipv6-fun deep dive → path Anatomy of a Web RequestHTTP request lifecycle, caches and CDN edge selection → kernel Linux Network Stackkernel packet path and sysctl reference → ebpf eBPF in the Network Stackread & write the wire in-kernel - the transport fingerprints a socket can't see, and how ja4-loko captures them → ja4+ JA4+ Breakdownthe fingerprint family byte-by-byte - JA4/H/S/T/L/X/SSH/q decoded, why it beats JA3, and why coherence beats any one hash → tls TLS 1.3 Handshakethe handshake byte-by-byte - ClientHello fields, the 1-RTT flow, the key schedule, 0-RTT, and the exact bytes JA4 hashes → quic QUIC & HTTP/3packets, Initial keys, varints & frames, connection IDs, HTTP/3 & QPACK - and the Initial ClientHello that JA4q reads → netfilter Packet Fatethe firewall path - netfilter hooks, conntrack, DROP vs REJECT, and who really sent that "connection reset by peer" (the TTL gives it away) → privacy ECH - Encrypted ClientHellothe countermove to SNI fingerprinting - the HPKE-sealed inner hello, the HTTPS-record key, GREASE, and why ECH hides where you are going, not who you are →