> For the complete documentation index, see [llms.txt](https://security.navidnaf.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://security.navidnaf.com/potions/computer-networking/osi-layer.md).

# OSI Layer

The **OSI (Open Systems Interconnection) Model** is a conceptual framework developed by the ISO to standardize the functions of telecommunication and computing systems. It ensures communication between different systems and devices, promoting interoperability across a wide range of networking technologies. The OSI model divides network communication into seven abstraction layers, each representing a specific functionality.

The seven layers are:

* **Physical Layer**: Deals with the transmission of raw bit streams over a physical medium (e.g., cables, WiFi).
* **Data Link Layer**: Ensures error-free data transfer between adjacent network nodes by managing frames.
* **Network Layer**: Handles routing and forwarding of data packets across different networks (e.g., IP).
* **Transport Layer**: Ensures reliable data transfer between hosts, handling error correction and flow control (e.g., TCP/UDP).
* **Session Layer**: Manages sessions or connections between applications.
* **Presentation Layer**: Translates data formats between applications and the network (e.g., encryption, data compression).
* **Application Layer**: Provides network services directly to end-user applications (e.g., HTTP, SMTP).

Each layer performs a unique role and communicates with the layers directly above and below it, ensuring smooth data exchange across diverse systems.

## Function & Usage

<table><thead><tr><th width="161">Layer</th><th width="377">Function</th><th>Example</th></tr></thead><tbody><tr><td>Application</td><td>Provides services and interfaces for end-user applications to access the network. It handles high-level protocols like file transfers and email.</td><td>HTTP, FTP, SMTP, DNS, Telnet</td></tr><tr><td>Presentation</td><td>Ensures data is in a usable format for the application layer by handling translation, encryption, and compression.</td><td>Encryption (TLS/SSL), JPEG, PNG, ASCII</td></tr><tr><td>Session</td><td>Manages and controls connections between computers, ensuring proper start, maintenance, and termination of sessions.</td><td>Session management, RPC, NetBIOS</td></tr><tr><td>Transport</td><td>Ensures reliable data transfer between hosts, managing error detection, retransmissions, and flow control.</td><td>TCP, UDP, SPX</td></tr><tr><td>Network</td><td>Responsible for routing and forwarding packets between different networks, ensuring they reach their destination.</td><td>IP, ICMP, IPX, Routers</td></tr><tr><td>Data Link</td><td>Handles node-to-node data transfer by framing data, detecting errors, and controlling how devices share the physical medium.</td><td>Ethernet, Wi-Fi (802.11), Switches, MAC, ARP</td></tr><tr><td>Physical</td><td>Transfers raw bits over a physical medium (cables, wireless), ensuring electrical or optical signals are transmitted correctly.</td><td>Cables (Ethernet, Fiber Optic), Wi-Fi</td></tr></tbody></table>

## Security on Each Layer

<table><thead><tr><th width="147">Layer</th><th width="342">Security Defenses</th><th>Common Attacks</th></tr></thead><tbody><tr><td>Application</td><td><ul><li>Web Application Firewalls (WAF)</li><li>Secure Socket Layer (SSL)/Transport Layer Security (TLS)</li><li>Regular software updates and patch management</li><li>Input validation and sanitization</li></ul></td><td><ul><li>SQL Injection</li><li>Cross-Site Scripting (XSS)</li><li>Cross-Site Request Forgery (CSRF)</li><li>Buffer Overflow</li></ul></td></tr><tr><td>Presentation</td><td><ul><li>Encryption (e.g., AES, RSA)</li><li>Data Integrity Checks (e.g., hashes)</li><li>Secure data format conversions</li></ul></td><td><ul><li>Data Interception (Man-in-the-Middle attacks)</li><li>Data Tampering</li><li>Format String Attacks</li></ul></td></tr><tr><td>Session</td><td><ul><li>Secure Session Management</li><li>Use of Session Tokens</li><li>Regular monitoring and session timeouts</li></ul></td><td><ul><li>Session Hijacking</li><li>Session Fixation</li><li>Man-in-the-Middle Attacks (session interception)</li></ul></td></tr><tr><td>Transport</td><td><ul><li>Transport Layer Security (TLS)</li><li>Secure protocols (e.g., TCP with proper configurations)</li><li>Port filtering and monitoring</li></ul></td><td><ul><li>TCP SYN Flood</li><li>UDP Flood</li><li>Session Hijacking</li><li>Man-in-the-Middle Attacks (e.g., packet sniffing)</li></ul></td></tr><tr><td>Network</td><td><ul><li>IPsec</li><li>Network Firewalls</li><li>Network Segmentation</li><li>Routing Protocol Security (e.g., BGP)</li></ul></td><td><ul><li>IP Spoofing</li><li>Routing Attacks (e.g., BGP Hijacking)</li><li>DDoS Attacks</li><li>Packet Sniffing</li></ul></td></tr><tr><td>Data Link</td><td><ul><li>MAC Address Filtering</li><li>VLANs (Virtual Local Area Networks)</li><li>Network Access Control (NAC)</li><li>Frame Relay Security</li></ul></td><td><ul><li>MAC Spoofing</li><li>ARP Spoofing</li><li>VLAN Hopping</li><li>Frame Injection</li></ul></td></tr><tr><td>Physical</td><td><ul><li>Physical Security Measures (e.g., secure access to facilities)</li><li>Network Segregation</li><li>Monitoring and Surveillance</li></ul></td><td><ul><li>Cable Tapping</li><li>Physical Theft of Equipment</li><li>Signal Interception</li><li>Electromagnetic Interference (EMI)</li></ul></td></tr></tbody></table>

The OSI model serves as a guideline for developing and understanding network protocols by organizing the complex task of network communication into manageable and structured layers. It is a conceptual model that helps in breaking down network functions into seven distinct layers, each responsible for specific aspects of communication.

While the OSI model provides a framework for understanding and designing network architectures, it is not a strict blueprint for every networking system. Instead, it acts as a reference model that guides the development and implementation of network protocols and systems, promoting a standardized approach to network communication.
