Network Protocol Analysis Guide

Comprehensive Reference for Network Engineers & Security Analysts


Document Information

PropertyValue
Version1.0
CreatedJanuary 2026
AuthorTowfiq Omar Rakin
Total Sections10
Estimated Reading2-3 hours

Table of Contents

Part 1: Fundamentals

FileSectionDescription
01_Introduction_OSI_ModelIntroduction & OSI ModelVisual layer breakdown, encapsulation
02_Layer2_Data_LinkLayer 2 ProtocolsEthernet, ARP, MAC addressing, STP
03_Layer3_NetworkLayer 3 ProtocolsIPv4/IPv6, ICMP, subnetting

Part 2: Transport Layer Deep Dive

FileSectionDescription
04_Layer4_TCP_Deep_DiveTCP Protocol3-way handshake, flags, flow control
05_Layer4_UDP_and_PortsUDP & Port NumbersUDP structure, port reference

Part 3: Application Layer Deep Dive

FileSectionDescription
06_Layer7_DNSDNS ProtocolQuery types, records, resolution
07_Layer7_HTTP_HTTPSHTTP/HTTPS & TLSMethods, status codes, TLS handshake
08_Layer7_Other_ProtocolsDHCP, FTP, SSH, SMTPOther application protocols

Part 4: VoIP & Practical Analysis

FileSectionDescription
09_VoIP_ProtocolsVoIP ProtocolsSIP, RTP, RTCP, SDP
10_Wireshark_CheatsheetWireshark ReferenceFilters, tips, analysis

Quick Navigation

FUNDAMENTALS                    DEEP DIVES                      PRACTICAL
============                    ==========                      =========
01 - OSI Model          --->    04 - TCP Deep Dive      --->    09 - VoIP
02 - Layer 2 (ARP)      --->    05 - UDP & Ports        --->    10 - Wireshark
03 - Layer 3 (IP)       --->    06 - DNS Deep Dive
                                07 - HTTP/HTTPS
                                08 - Other L7 Protocols

How to Use This Guide

  1. Beginners: Start with Section 01 (OSI Model) and proceed sequentially
  2. Intermediate: Jump to specific protocol sections as needed
  3. Advanced: Use Section 10 (Wireshark Cheatsheet) as quick reference
  4. VoIP Analysis: Focus on Section 09 for SIP/RTP analysis

Protocols Covered

Layer 7 (Application)
├── DNS, HTTP, HTTPS, DHCP
├── FTP, SSH, SMTP, POP3, IMAP
└── SIP, SDP (VoIP Signaling)

Layer 6 (Presentation)
└── TLS/SSL Encryption

Layer 5 (Session)
└── Session Management

Layer 4 (Transport)
├── TCP (Transmission Control Protocol)
└── UDP (User Datagram Protocol)
├── RTP, RTCP (VoIP Media)

Layer 3 (Network)
├── IPv4, IPv6
├── ICMP
└── IGMP

Layer 2 (Data Link)
├── Ethernet (802.3)
├── ARP
├── STP
└── VLANs (802.1Q)

Layer 1 (Physical)
└── Electrical/Optical Signals

  • PCAP Analysis: Based on capture.pcapng VoIP call capture
  • Audio Extraction: See Section 10 for RTP audio extraction guide

Continue to: 01_Introduction_OSI_Model