Home
Cybersecurity & AI Security / Part 4 — Networking Deeper: Services, Protocols, and the Attack Surface

Networking Deeper: Services, Protocols, and the Attack Surface

CAP, ACID vs BASE, latency numbers, back-of-envelope estimation, single points of failure — the vocabulary every system designer thinks in.


Core Philosophy: A computer connected to a network is not one target — it is a collection of doors, each one a service listening on a port. Both attacking and defending begin with the same question: “What doors exist, and which are open?” The sum of all those doors is called the attack surface. Security, in large part, is the discipline of knowing your attack surface and keeping it as small as possible.

Part 1: The Problem

In section 0.1 you learned that a port identifies a program on a machine. Now we make that operational. Before anyone can attack a system — and before anyone can defend it — they need a map: which services are running, on which ports, speaking which protocols, exposed to whom.

A defender who doesn’t know their own attack surface cannot protect it. An attacker who maps it well is halfway to a breach. This section is about seeing the surface.

Part 2: The Concept — Services Listen on Ports

A service is a program that sits running, waiting for network connections on a particular port. It “listens.”

text
        ONE SERVER
   ┌─────────────────────────┐
   │  Web service   → port 80, 443
   │  SSH service   → port 22
   │  Database      → port 3306
   │  Mail service  → port 25
   └─────────────────────────┘
        Each is a separate "door."

Each listening service is an independent way in. If the web service is flawless but the database is exposed with a default password, the attacker simply uses the database door. A system is only as secure as its weakest service.

Part 3: Common Services You’ll Meet Constantly

Port Service What it is Why an attacker cares
22SSHEncrypted remote loginFull control of the box if cracked
80 / 443HTTP / HTTPSWeb serversThe huge web-app attack surface
21FTPOld file transferOften allows anonymous access
25 / 587SMTPSending mailSpam relay, info leaks
53DNSName resolutionSpoofing, info gathering
3306MySQLDatabaseDirect access to all the data
3389RDPWindows remote desktopFull graphical control of a Windows box
445SMBWindows file sharingHistorically a major breach vector

You don’t memorize this table — you’ll absorb it through use. Keep it on your Tools & Reference Cheatsheet page.

Part 4: Client–Server, and Why “Listening” Matters

Every network interaction has two roles:

Your browser is a client. A web server listens. Your SSH program is a client; an SSH service listens.

The security-relevant insight: only listening services can be attacked over the network. A program that isn’t listening on any port presents no network door. This leads straight to a core defensive move — turn off and remove services you don’t need. Every service you shut down is a door that no longer exists. (You’ll do exactly this in Phase 4’s hardening pages.)

Part 5: Firewalls, NAT, and VPNs — The Gatekeepers

Three pieces of technology sit between services and the open internet. Know what each does.

Firewall — the bouncer. A firewall is a set of rules deciding which connections are allowed. “Allow incoming on 443, block everything else incoming.” It doesn’t fix a vulnerable service; it controls who can reach the door at all.

text
   Internet ──►  ┌──────────┐  ──►  Services
                 │ FIREWALL │
                 │  rules   │   blocks anything
                 └──────────┘   not explicitly allowed

NAT — the shared mailbox.Network Address Translation lets many devices on a home or office network share one public IP address. A side effect: devices behind NAT aren’t directly reachable from the internet by default — a small, accidental layer of protection. It’s why your laptop at home isn’t directly exposed, but a cloud server is.

VPN — the private tunnel. A Virtual Private Network creates an encrypted tunnel between you and another network, so you appear to be “inside” it. Security uses VPNs two ways: defensively (employees safely reach internal systems) and, in this curriculum, to legally connect into hacking-practice lab networks — many training platforms require a VPN connection to reach their deliberately vulnerable machines.

Part 6: Attack Surface — The Idea That Ties It Together

Your attack surface is the total set of points where an attacker could try to get in:

Two principles flow from this, and they run through the entire curriculum:

  1. Attackers enumerate the attack surface. “Reconnaissance” (Phase 2.1) and “scanning” (Phase 3.1) are exactly this — mapping every door before trying any.
  2. Defenders minimize the attack surface. “Attack surface reduction” — closing unused ports, removing unused software, disabling unused accounts — is one of the highest-value defensive activities. Fewer doors, fewer ways in. This is the heart of Phase 4’s hardening.
text
   BIG attack surface          SMALL attack surface
   (many doors open)           (only what's needed)
   ┌─┬─┬─┬─┬─┬─┬─┐             ┌─┬───────────┬─┐
   │D│D│D│D│D│D│D│             │D│           │D│
   └─┴─┴─┴─┴─┴─┴─┘             └─┴───────────┴─┘
   easy to attack              hard to attack

📓 Key Terms

Term Plain meaning
ServiceA program listening on a port for network connections.
ListeningA service actively waiting for connections on a port.
Client / ServerThe side that initiates / the side that listens.
FirewallRules controlling which network connections are allowed.
NATLets many devices share one public IP; incidentally hides them.
VPNAn encrypted tunnel making you appear inside another network.
Attack surfaceThe total set of points an attacker could try to exploit.
Attack surface reductionClosing/removing unneeded services, accounts, software.

🧪 Hands-On Lab

⚠️ Legal note: In this lab you scan only your own machine (localhost / 127.0.0.1). Scanning machines you don’t own can be illegal even if you cause no harm. Section 1.0 covers the rules in full; the habit starts here.

Task 1 — Install Nmap. Nmap is the standard port-scanning tool. Install it (sudo apt install nmap on Ubuntu, or download from nmap.org).

Task 2 — Scan your own machine.

text
nmap localhost

Nmap reports which ports are open on your own computer and guesses the service behind each. This is your machine’s attack surface, made visible.

Task 3 — A more detailed scan.

text
nmap -sV localhost

The -sV flag asks Nmap to identify each service’s version. Versions matter enormously later — a specific version often maps to specific known vulnerabilities.

Task 4 — Reflect on each open door. For every open port, ask: “Do I know what this is? Do I actually need it running?” That single question, asked about a real server, is attack-surface reduction.

Task 5 — Inspect your firewall.

See which rules currently exist. Don’t change anything yet — just observe what’s already guarding your doors.

⚠️ Common Mistakes

✅ Recap & What’s Next

Next (0.5): You can’t practice attacks on the real internet — that’s illegal. So we build your own private, legal, isolated lab: an attacker machine and a victim machine, safely sealed off from everything else.

⁂ Back to all modules