Academic Domain: Computer Networks & Cyber Security
Nervous System of Civilization
How Systems Connect, Communicate, and Defend
The Architecture of Connection & Defense
A single computer is an isolated brain. A network gives machines a way to speak, creating a planetary-scale hive mind. But connection breeds vulnerability. This realm teaches how data is routed across the world, and how cryptography and cybersecurity establish boundaries to protect that conversation.
CONNECT →
ADDRESS →
FRAME →
ROUTE →
TRANSPORT →
SERVE →
AUTHENTICATE →
ENCRYPT →
DETECT →
RESPOND →
RECOVER
The 20 Network Realms
Networking & Cyber Security Architecture
REALM 01
The Network Universe
- LAN, MAN, WAN Concepts
- Network Topologies (Star, Mesh)
- Client-Server vs P2P
- Circuit vs Packet Switching
The Layers
APP
PRE
SES
TRN
NET
DL
PHY
- OSI Reference Model
- TCP/IP Protocol Stack
- Encapsulation & Decapsulation
- Peer-to-Peer Communication
Physical & Data Link
- Ethernet & CSMA/CD
- MAC Addressing & Switching
- Framing & Error Control (CRC)
- VLANs & Medium Access
The Address
192.168.1.100
- IPv4 & IPv6 Structures
- Subnetting & CIDR
- Public vs Private IP
- Network Address Translation (NAT)
The Router
R1
R2
R3
- Routing Tables & Next Hop
- Distance Vector (RIP)
- Link State (OSPF)
- Path Vector (BGP) & Autonomous Systems
The Transport
- Ports & Multiplexing
- TCP (3-Way Handshake)
- UDP (Connectionless)
- Congestion & Flow Control
The Internet
- Internet Architecture & ISPs
- DNS (Domain Name System)
- DHCP (Dynamic Addressing)
- ICMP (Ping & Traceroute)
Application Networking
- HTTP & HTTPS Protocols
- Email (SMTP, POP3, IMAP)
- File Transfer (FTP, SFTP)
- Remote Access (SSH)
Network Performance
- Bandwidth & Throughput
- Latency & Jitter
- Packet Loss & Congestion
- Quality of Service (QoS)
Security Fundamentals
C
I
A
- CIA Triad (Conf, Int, Avail)
- Threats, Vulnerabilities, Risks
- Defense in Depth
- Zero Trust Principles
Authentication & Access
🔑
- Multi-Factor Authentication
- Identity Management (SSO)
- Role-Based Access Control (RBAC)
- Privilege & Authorization
Cryptography
DATA
🔒
X#9A
- Symmetric Encryption (AES)
- Asymmetric Encryption (RSA)
- Hashing (SHA) & Signatures
- Public Key Infrastructure (PKI)
Network Security
- Firewalls (Stateful/NGFW)
- Intrusion Detection/Prevention (IDS/IPS)
- VPN (IPsec, TLS)
- Network Segmentation (DMZ)
Malware & Attacks
🐛
- Viruses, Trojans & Ransomware
- Phishing & Social Engineering
- Denial of Service (DDoS)
- Sniffing, Spoofing & MITM
Securing Applications
- Secure Coding Practices
- SQL Injection & XSS
- API Security & Tokens
- Web Vulnerabilities (OWASP)
Cloud & Endpoint Security
🔒
- Cloud Shared Responsibility
- Container & VM Security
- Endpoint Protection (EDR)
- OS & Device Hardening
Security Operations (SOC)
- Security Monitoring & SIEM
- Incident Detection & Triage
- Incident Response Lifecycle
- Digital Forensics Fundamentals
Governance & Risk
- Vulnerability Management
- Penetration Testing Concepts
- Risk Assessment & Treatment
- Security Policies & Awareness
19 — The Cyber Security Laboratory
user@soc:~$ tcpdump -i eth0 port 443
[ALERT] Anomalous Traffic Detected: Drop
user@soc:~$ iptables -A INPUT -s 10.x.x.x -j DROP
[1] PACKET ANALYSIS [2] FIREWALL CONFIG [3] VULNERABILITY SCAN [4] SECURE DESIGN [5] INCIDENT TRIAGE [6] MITRE ATT&CK
The convergence of networking and defense. Analyzing live traffic, configuring stateful rules, deploying cryptographic tunnels, and responding to simulated breaches in a controlled DMZ environment.