Network Security Fundamentals Cheat Sheet
Covers core network security concepts including segmentation, defense-in-depth, common attack vectors, and essential hardening practices.
Attacks by OSI Layer
Common attack types mapped to the layer they target.
- Layer 2 (Data Link)- ARP spoofing, MAC flooding, VLAN hopping
- Layer 3 (Network)- IP spoofing, ICMP flood, route poisoning
- Layer 4 (Transport)- SYN flood, port scanning, session hijacking
- Layer 7 (Application)- SQL injection, XSS, HTTP flood, DNS tunneling
- Physical- Cable tapping, rogue device insertion, hardware keyloggers
Core Security Principles
Foundational concepts every network defender should apply.
- Defense in depth- Layer multiple independent controls so no single failure exposes the network
- Least privilege- Grant only the access required to perform a task, nothing more
- Network segmentation- Split networks into zones (VLANs/subnets) to contain breaches
- CIA triad- Confidentiality, Integrity, Availability — the three pillars of security
- Zero trust- Never trust, always verify, regardless of network location
- Attack surface reduction- Disable unused services, ports, and protocols
Basic Linux Network Hardening
Quick commands to inspect and reduce exposure on a Linux host.
# List listening ports and owning processesss -tulnp# Show active connectionsss -tan state established# Disable IP forwarding (unless acting as a router)sysctl -w net.ipv4.ip_forward=0# Enable SYN cookies to mitigate SYN flood attackssysctl -w net.ipv4.tcp_syncookies=1# Check open ports from outside using nmapnmap -sS -p- 192.168.1.10
Key Network Controls
Common technologies used to secure network perimeters and traffic.
- Firewall- Filters traffic by rules (IP, port, protocol, state)
- IDS/IPS- Detects (IDS) or blocks (IPS) malicious traffic patterns
- VPN- Encrypts traffic between endpoints over untrusted networks
- NAC- Network Access Control enforces device compliance before granting access
- DMZ- Isolated segment for public-facing services, separate from internal LAN
Stateful Firewall Rules (nftables)
Modern connection-tracking firewall rules including rate limiting for brute-force mitigation.
# Base chain with default drop policynft add table inet filternft add chain inet filter input { type filter hook input priority 0 \; policy drop \; }# Allow established/related, drop invalidnft add rule inet filter input ct state established,related acceptnft add rule inet filter input ct state invalid drop# Allow loopback and SSH, rate-limited to blunt brute forcenft add rule inet filter input iifname lo acceptnft add rule inet filter input tcp dport 22 ct state new limit rate 5/minute accept# Allow inbound HTTPSnft add rule inet filter input tcp dport 443 acceptnft list ruleset
Mutual TLS Certificate Chain
Generating a CA and client/server certs for mutual TLS authentication.
# Private CAopenssl req -x509 -new -nodes -newkey rsa:4096 \ -keyout ca.key -out ca.crt -days 3650 -subj "/CN=Internal-CA"# Server key + CSR, signed by the CAopenssl req -new -nodes -newkey rsa:2048 -keyout server.key -out server.csr \ -subj "/CN=api.internal"openssl x509 -req -in server.csr -CA ca.crt -CAkey ca.key \ -CAcreateserial -out server.crt -days 365# Client cert for mTLS, same CAopenssl req -new -nodes -newkey rsa:2048 -keyout client.key -out client.csr \ -subj "/CN=service-a"openssl x509 -req -in client.csr -CA ca.crt -CAkey ca.key \ -CAcreateserial -out client.crt -days 365# Verify the chainopenssl verify -CAfile ca.crt server.crt client.crt
Advanced tcpdump Filters
Targeted capture expressions for triaging suspicious traffic.
# Capture only SYN packets (connection attempts) to spot scanstcpdump -i eth0 'tcp[tcpflags] & (tcp-syn) != 0 and tcp[tcpflags] & (tcp-ack) == 0'# Capture traffic to/from a suspicious host, write to file for offline analysistcpdump -i eth0 host 203.0.113.7 -w suspect.pcap# Filter by packet size to spot exfiltration-sized burststcpdump -i eth0 'greater 1400'# DNS queries only (common exfil/C2 channel)tcpdump -i eth0 -n 'udp port 53'# Read back with a display-style filtertcpdump -r suspect.pcap 'tcp port 443 and host 203.0.113.7'
Modern Secure Transport Protocols
Encryption and integrity protocols that underpin current network defenses.
- TLS 1.3- Drops legacy ciphers, cuts the handshake to 1-RTT, and mandates forward secrecy by default
- mTLS- Both client and server present certificates, authenticating each other (not just the server)
- WireGuard- Modern VPN protocol using a minimal, auditable codebase and Curve25519/ChaCha20 crypto
- IPsec (ESP/AH)- Network-layer encryption/integrity, commonly used for site-to-site VPN tunnels
- DNSSEC- Cryptographically signs DNS records to prevent cache poisoning and spoofed responses
- DoH / DoT- DNS over HTTPS/TLS encrypts DNS queries in transit, defeating passive on-path snooping
- Perfect Forward Secrecy- Ephemeral key exchange (ECDHE) ensures a compromised long-term key can't decrypt past sessions
Advanced Threats & Controls
Higher-order concepts beyond basic perimeter defense.
- BGP hijacking- Malicious or misconfigured route announcements redirect internet traffic through an attacker-controlled AS
- 802.1X- Port-based network access control requiring authentication before a device can join a switched network
- Microsegmentation- Enforces per-workload (not just per-subnet) policy, often via identity-aware east-west firewalls in the data center
- EDR/XDR- Endpoint/extended detection and response correlates host and network telemetry to catch what signature-based tools miss
- SIEM correlation- Aggregates logs across firewalls, IDS, endpoints, and auth systems to detect multi-stage attack patterns
- Assume breach- Design controls (segmentation, monitoring, least privilege) assuming an attacker is already inside, not just outside
Segment your network so that a compromised IoT or guest device can never reach management interfaces — put them on isolated VLANs with explicit deny-by-default rules between zones.