Skip to content
Back to home
2025-07-16Security Fundamentals5 min read

OSI Model

A layer-by-layer breakdown of the OSI Model's seven layers — what each one does, the protocols that live there, and the common attacks that target them.

OSI model is a set of rules that explains how different computer systems communicate over a network. OSI stands for Open System Interconnection. It provides a clear vision on how data transmitted between nodes.

The OSI model consists of 7 layers. They are (from the top to bottom),

  1. Application layer.
  2. Presentation layer.
  3. Session layer.
  4. Transport layer.
  5. Network layer.
  6. Data Link layer.
  7. Physical layer.

To easily remember this order wise, use

"Anxious Pale Shakespear Treated Nervous Drinks Patiently."

Application Layer (7th layer)

It is the topmost layer. It is where the user interacts with the softwares & websites directly. Kindly note it is not the actual software but an interface. These applications produce the data to be transferred over the network.

Web browsers use Layer 7 application protocols, like HTTP or File Transfer Protocol (FTP). Other internet-connected apps (like Outlook) use protocols such as Simple Mail Transfer Protocol (SMTP).

Presentation Layer (6th layer)

In Presentation layer, the following actions take place....

  • Translation — transfers the data into computer understandable format and vice versa. (ex-ASCII to EBCDIC)
  • Encryption/Decryption — Data encryption translates the data into another form or code. The encrypted data is known as the ciphertext, and the decrypted data is known as plain text. A key value is used for encrypting as well as decrypting data.
  • Compression — Reduces the number of bits that need to be transmitted on the network.

Session Layer (5th layer)

Session layer is responsible for establishment of connections, management of connections and terminations of sessions between two devices.

It also adds checkpoints that are considered synchronization points in the data. These synchronization points help to re-synchronize the data properly and ends of the messages are not cut prematurely and data loss is avoided.

The session layer enables communication between 2 systems either in half-duplex or full duplex.

Transport Layer (4th layer)

Transport layer plays a crucial part in networking. It is responsible for transferring data between two systems via two main protocols:

  • Transmission Control Protocol (TCP) — connection-oriented service.

The sender and the receiver stay connected until the transmission process is fully completed and also ensures that the data reaches its destination. If any data is lost, then the receiver asks the sender to re-transmit it. This uses a 3-way handshake method.

  • User Datagram Protocol (UDP) — connection-less service.

This protocol does not establish any connection before transferring data. It just sends data that's why UDP is known as connectionless.

This layer accepts the message from the session layer and breaks the message into smaller units. The transport layer at the destination station reassembles the message.

Network Layer (3rd layer)

The network layer works to transmit the data from one host to the other located in different networks. It is responsible for selecting the shortest path to transmit the packet from the number of routes available which is known as packet routing.

The sender and receiver's IP addresses are placed in the header by the network layer. Segment is referred to as Packet.

Data Link Layer (2nd layer)

The main function of this layer is to make sure data transfer is error-free from one node to another.

Framing is a responsibility of the data link layer which provides a way for a sender to transmit a set of bits that are meaningful to the receiver. This can be accomplished by attaching special bit patterns to the beginning and end of the frame.

The data link layer adds physical addresses (MAC address) of the sender or receiver in the header of each frame and controls the flow of data on both sender and receiver to avoid data corruption.

Physical Layer (1st layer)

It is responsible for the actual physical connection between the devices. The physical layer contains information in the form of bits. It works on bit synchronization, bit rate control, transmission mode and topologies.

OSI Model: Protocols & Attacks

LayerProtocolsAttacks
ApplicationSMTP, IMAP, HTTP, FTPExploitation, Phishing
PresentationSSL, TLSSSL/TLS downgrading
SessionNetBios, RPCHijacking
TransportTCP, UDPDoS/DDoS
NetworkIP, ICMPMITM (Man-in-the-Middle)
Data LinkARP, EthernetARP Spoofing
PhysicalPhysical components such as cables, wires, etcSniffing