-
Duties, Protocols of Each Layer
Layer-2: hub router switch bridge, Ping from Host-1 to Host-2
Layer-2.5: MPLS
Layer-3
Protocols: IP, iptables
Security:
Integrity, Hashing (SHA256, MD5, Argon2), MAC, HMAC, Digital Signatures(RSA, DSA, ECDSA)
Encryption: Symmetric vs Asymetric Key, Symmetric Key Algos (AES, DES), Asymmetric Key Algos(DH, RSA, EC(ECDH, secp256k1))
Build Libraries: Botan, Openssl(build on x86, Cross Compile on ARM)
Threat Modelling: STRIDE framework
DevSecOps STRIDE framework
VPN: What, VPN Tunnel: IKEv1, IKEv2, IPSec(Modes(tunnel, transport), Headers(AH, ESP)), Terms( DPD(Dead Peer Detection), Nonce, PFS(Perfact Forward Secrecy), SA(Security Association), SA, SAD, SPI), Packet Flow(Inbound, Outbound), VPN NAT Traversal
Layer-6(Presentation)
SSL/TLS:
SSL vs TLS, NSS, mkcert, Terms(SNI), Let's Encrypt Root CA
TLS Client Server Certification Exchange
Layer-7(Application)
DNS: Introduction(Name resolution, Forward, Reverse lookup, Terms), DNS Records(A, AAAA, Alias, CAA, CNAME, MX, PTR, RR, SOA, SPF, TXT)
gRPC: Introduction(gRPC, gRPC vs REST), Code(golang gRPC server & client)
Authentication Procotols: Kerberos, OAuth, OIDC(OpenID Connect), SAML
MCP(Model Context Protocol)
REST API
WebServers: Apache, Ngnix
Load testing Tools
RBI(Remote Browser Isolation)
HTTP:
Introduction( Methods(GET,POST,PUT,DELETE)), Headers, Cookies(Session, Domain, Stolen Cookie, Cookie Surrogate)
Authentication: Authenticate by IDP:Get session cookie, Cookies(Session, Domain, Global, Stolen), JWT Token, Refresh Token, HTTP Connect