Networking

Paul Krzyzanowski

November 1, 2010

Everything lives, moves, everything corresponds; the magnetic rays, emanating either from myself or from others, cross the limitless chain of created things unimpeded; it is a transparent network that covers the world, and its slender threads communicate themselves by degrees to the planets and stars. Captive now upon earth, I commune with the chorus of the stars who share in my joys and sorrows.
—Gérard de Nerval, Aurélia, Part 2, chapter 6

Introduction

As we added more processors to a machine, programs and operating systems did not become substantially different. In a symmetric multiprocessor architecture (SMP), each processor has access to all of system memory and they all run under the same operating system. The scheduler gets the additional responsibility of managing multiple processes in the running state and assigning processes to processors. A process can use any existing mechanisms for communicating with other processes, such as shared memory, semaphores, and files.

Once we move beyond standalone systems and look at a collection of independent computers, we can no longer use these local operating system-based communication mechanisms. To work together, they will have to communicate with each other via an inter-machine interconnect: the network.

Modes of connection

Communication over a network can be classified into two types:

circuit-switched
In this network, a dedicated channel exists to the remote machine. An example is that of a telephone network: when you place a call, a dedicated circuit is established for you to the destination. In a circuit-switched network, you are guaranteed to have access to the full bandwidth of the circuit.
packet-switched
Connections are shared in this type of network. Data that is transported across the network is broken up into chunks called packets. Because packets from different sources (and to different destinations) are now intermixed, each packet must contain the address of the destination (in a circuit-switched network, this isn’t needed since the circuit is a dedicated connection). An ethernet network is an example of this type of network. In a packet-switched network, the bandwidth that you see will usually be less than the capacity of the network since you’re sharing the channel with others.

Parlez-vous français? ¡Sí, muy bien!

For computers (or people, for that matter) to be able to communicate, they must speak the same language and follow the same conventions. For humans, this means speaking the same language and knowing how low to bow, which hand gestures not to use, and whether it is acceptable to excrete gas. For computers, this requires knowing how to find out how long a packet is that is coming over a network (so we can get it), knowing where the destination address is stored, and being able to properly interpret all the data within it. The issue is non-trivial because different computers have different concepts of which order to store bytes of a word, how long an integer is, and what character set is being used. The instructions and conventions needed for successful communication is known as a protocol. The instructions and conventions for making sense of data and for computing are known as protocols.

To ease the task of communicating and provide a degree of flexibility, network protocols are generally organized in layers. This allows one to replace a layer of the protocol without having to replace the surrounding layers. It saves higher-level software from having to bother with formatting an ethernet packet. The most popular model of guiding (not specifying) protocol layering is the OSI Reference Model, designed in 1977 and refined somewhat thereafter. It contains seven layers of protocols:

1. Physical
Deals with the specification of the data signals, voltage levels, transmission speed, and connectors. Examples include the RS-232 serial connector or a 1000BASE-T gigabit ethernet connector.
2. Data link
Provides the first level of organization of data – the datalink frame, which includes source address, destination address, content, and some form of checksum for error detection. This layer includes Media Access Control (MAC) and Logical Link Control (LLC). MAC covers rules for accessing the media and dealing with contention. The LLC portion covers frame synchronization, flow control, and error checking. Examples of this layer include Ethernet data (MAC-layer) and PPP (the Point-to-Point Protocol).
3. Network
Relay and route information to the destination. This layer is responsible for managing the journey of packets between local area networks and figuring out intermediate hops (if needed). The network layer gives us the full abstraction of machine-to-machine communication. Examples of this layer include the Internet Protocol (IP) and X.25.
4. Transport
Provides reliable end-to-end communications by providing service-level (transport) addressing, flow control, datagram segmentation, and end-to-end error checking. It can ensure that packets appear to arrive in the correct order and issue retransmission requests to ensure the reliable message delivery. The network layer gives us the abstraction of application-to-application communication. Examples of this layer include TCP/IP and UDP/IP: two transport-layer protocols over the Internet Protocol (IP).
5. Session
Responsible for connection establishment, data transfer, and for connection release. It tracks who initiated a conversation and may manage the re-establishing of a logical communication channel. Examples of this include HTTP 1.1, SSL, ahd NetBIOS.
6. Presentation
Responsible for the selection of an agreed-upon syntax (data representation). This layer may have to convert data between the agreed-upon representation and the machine's native types. Examples of this include MIME, XDR (the eXternal Data Representation used by ONC RPC) and ASN.1 (Abstract Synstax Notation).
7. Application
The protocol of applications using networking, such as file transfer, directory services, distributed processing applications, and many others. Examples of this include email (SMTP, POP, and IMAP protocols), file transfer (FTP), and directory services (LDAP).

Some networking terminology

This section will provide a quick tour of some of the more commonly encountered terms encountered in networking.

A local area network (LAN) is a communication network that covers a small area (a few rooms, a building, or a set of buildings), incorporates a common transmission medium (or media that is bridged at the data link layer; no inter-networking routing is needed), and offers a relatively high data rate (typically 10 Mbps – 1 Gbps) with relatively low latency. The devices on a LAN are peers, so that any device can initiate a data transfer with any other device. Devices (endpoints) connected to a LAN are called nodes. Many nodes on a LAN are workstations. This covers most personal computing devices (PCs, Macs, tablets).

For a node to be connected to the LAN, interface hardware is needed. This is known as an adapter and is a circuit is either built onto the main circuit board or sits on an expansion slot/connector. Networking adapters are referred to as Network Interface Cards, or NICs (even if they are not cards).

Media refers to the wires (or wireless RF) connecting together the devices that make up a LAN. The following types of media are generally encountered:

  • Twisted Pair is the most common wired medium. It typically has eight wires and comes in two flavors: shielded twisted pair (STP) or the more common unshielded twisted pair (UTP). Telephone cable is an example of UTP.
  • Coaxial cable (coax) comes in two flavors as well. Thin coax (similar to TV cable) is by far the more popular of the two. Thick coax is now obsolete. Thin coax is rarely seen in LANs as well but is in widespread use for cable TV/internet service to the home.
  • Fiber
  • Wireless

A hub is a device that acts as a central point for LAN cable. A switch moves data from any input port to a specific destination port, reducing overall congestion. Concentrators or repeaters regenerate data signals when data passes through them, allowing data to pass through longer distances. Bridges connect different LAN segments together (layer 2). Routers determine the next network point to which packets should be forwarded – they connect different types of local and wide area networks (layer 3).

Ethernet

Ethernet is the most common local area networking technology. It was developed in the mid 1970s at Xerox PARC and standardized by the IEEE 802.3 committee. It is a baseband transmission network. This means that all nodes share access to the network media on an equal basis. Data uses the entire bandwidth of the media. This is opposed to broadband transmission, where a given data transmission uses only a segment of the media by dividing the media into channels (e.g., frequency bands). The typical speed of transmission on an Ethernet network using unshielded twisted pair is currently 1 Gbps, with speeds going up to 10 Gbps and higher (40 and 100 Gbps over fiber). Older Ethernet networks generally transmitted at 10 Mbps over coax. Network access on an

Ethernet is a mechanism called Carrier Sense Multiple Access with Collision Detection (CSMA/CD). To send data, a node first listens to the network to see if it is busy (i.e., someone else is sending data). When the network is not busy, the node will send data and then sense to see whether a collision occurred because some other node decided to transmit data concurrently. If a collision was detected, the data is retransmitted. The analogy of CSMA/CD is that of using a telephone on a shared line.

The original Ethernet media was thick coax, which was called 10Base5 because the maximum length of a cable run was 500 meters. Thin coax replaced thick coax, and is called 10Base2 (with a maximum run of 200 meters). Both 10base5 and 10Base2 cables were organized in a bus topology, with any number of nodes plugging into the same cable run. This coax-based bus topology was replaced with unshielded twisted pair wiring in a star topology with a central hub (an Ethernet hub or switch). Each node has a dedicated cable that connects to this central hub (or switch).

Client-Server communication

The most common networking relationship is the client-server model. The model contains three components: a client, a server, and a service. A service is that task that a machine can perform, such as offering files over a network or the ability to execute a command. A server is the machine that performs the task (the machine that offers the service). A client is the machine that is requesting the service. These titles are generally used in the context of a particular service rather than in labeling a machine: one machine’s client may be another machine’s server.

To offer a service, a server must get a transport address for a particular service. This is a well-defined location (similar to a telephone number) that will serve to identify the service. The server associates the service with this address before clients can communicate with it. It is important to distinguish a transport address from a node (or machine) address. A machine address allowes us to send messages to a node but the system will have no clue as to the disposition of the data: which application it is targeted for. A transport address operates at layer four of the OSI stack and allows one to identify a communications endpoint within the node.

The client, wishing to obtain a service from the server, must obtain the server's transport address. There are several ways to do this: it may be hard-coded in an application or it may be found by consulting a database (similar to finding a number in a phone book). The database may be as simple as a single file on a machine (e.g. /etc/services on Unix systems) or as complex as accessing a distributed directory server.

We depend on transport providers to transmit data between machines. A transport provider is a piece of software that accepts a network message and sends it to a remote machine. There are two categories of transport protocols:

connection-oriented protocols

These are analogous to placing a phone call:

  • first, you establish a connection (dial a phone number)
  • possibly negotiate a protocol (decide which language to use)
  • communicate
  • terminate the connection (hang up)

This form of transport is known as virtual circuit service since it provides the illusion of having a dedicated circuit. Messages are guaranteed to arrive in order. A true dedicated circuit (as in a real telephone connection) is not virtual and is known as circuit switched service.

connectionless protocols

These are analogous to sending mail:

  • there is no connection setup
  • data is transmitted when ready (drop a letter in the mailbox)
  • there’s no termination because there was no call setup

This transport is known as datagram service. With this service, the client does not know whether the message arrived at the destination or whether the data arrived in the same order that it was transmitted. Datagram service is less reliable than virtual circuit service but has less overhead.

Ethernet

Ethernet is currently the most common local area network. Ethernet communication represents layers one and two of the OSI model. Layer 1 covers the physical aspects of ethernet connectivity. This includes the 8P8C (RJ45) connector, 1000BASE-T cable, and the voltage levels. Layer 2 covers the Data Link layer and includes error detection, data frame transmission (e.g., implementing the CSMA/CD logic), data frame parsing, and ethernet bridging. Altogether, ethernet offers unreliable connectionless communication over a local area network.

Ethernet has no relationship to IP or, for that matter, other networks. It is a packet-based network that identifies a destination with a 48-bit ethernet address. The packet size is variable-length and is limited (MTU, maximum transfer unit) to 1,518 bytes that consist of an 18-byte header and up to 1500 bytes of data. With the advent of gigabit ethernet, support was added for "jumbo packets", which support a 9,000 byte MTU. Ethernet hardrware on each node is constantly monitoring the network to detect packets where the destination address matches its own address. If a match is found, the packet contents are copied to an internal hardware buffer and an interrupt is generated to inform the operating system that incoming data is ready.

IP: Internet Protocol

By far the most popular network protocol these days is the family of Internet Protocols. The Internet was born in 1969 as a research network of four machines that was funded by the Department of Defense’s Advanced Research Projects Agency (ARPA). The goal was to build an efficient, decentralized, fault-tolerant network that could connect heterogeneous machines and link together separately connected networks. The network protocol is called the Internet Protocol, or IP. It is a connectionless protocol that is designed to handle the interconnection of a large number of local and wide area networks that comprise the Internet.

IP may route a packet from one physical network to another. Every machine on an IP network is assigned a unique 32-bit IP address. When an application sends data to a machine, it must address it with the IP address of that machine. The IP address is not the same as the machine address (e.g. the ethernet address) but is strictly a logical address. There is no relationship between the logical IP address and the hardware address on the underlying physical network. If a machine is connected to several physical networks, it will have several IP addresses, one for each network.

IP addressing

A 32-bit address can potentially support 232, or 4,294,967,296 addresses. However, if every machine on an IP network would receive an arbitrary IP address, then routers would need to keep a table of over four billion entries to know how to direct traffic throughout the Internet! To deal with this more sensibly, routing tables were designed so that one entry can match multiple addresses. To do this, a hierarchy of addressing was created so that machines that are physically close together (say, in the same organization) would share a common prefix of bits in the address. For instance, consider the two machines:

name address hex address
cs.rutgers.edu 128.6.4.2 80 06 04 02
remus.rutgers.edu 128.6.13.3 80 06 0d 03

The first sixteen bits identify the entire set of machines within Rutgers University. Systems outside of Rutgers that encounter any destination IP address that begins with 0x8006 have only to know how to route those packets to some node (a router) within Rutgers that can take care of routing the exact address to the proper machine. This saves the outside world from keeping track of up to 65,536 (216)machines within Rutgers.

An IP address is segmented into two parts:

  • network number — identifies the network that the machine belongs to
  • host number — identifies a machine on that network.

The network number is used to route the IP packet to the correct local area network. The host number is used to identify a specific machine once in that local area network. If we use a fixed 16-bit partition between network numbers and host numbers, we will be allowed to have a maximum of 65,536 (216) separate networks on the Internet, each with a maximum of 65, 536 hosts. The expectation, however, was that there would be a few big networks and many small ones. To support this, networks are divided into several classes. These classes allow the address space to be partitioned into a few big networks that can support many machines and many smaller networks that can support few machines. The first bits of an IP address identify the class of the network.

class leading bits bits for network number bits for network number
A 0 7 24
B 10 14 16
C 110 21 8

An IP address is usually written as a sequence of four bytes, each byte in decimal, separated by periods. For example, an IP address written as 135.250.68.43 translates into the hexadecimal address 87FA442B (135=0x87, 250=0xfa, etc.). In binary, this address is 1000 0111 1111 1010 0100 0100 0010 1011. The leading bits of this address are 10, which identifies the address as belonging to a class B network. The next 14 bits (00 0111 1111 1010) contain the network number (7FA) and the last 16 bits contain the host number (442B).

To allow organizations to create additional networks without requesting additional (and increasingly scarce) network numbers, some high bits of the host number may be allocated for a network number within a higher-level IP network. These local networks are known as subnets. Routers within an organization can be configured to extract this additional network ID and use it for routing. For example, a standard class B network allows 16 bits for a host number. This host address may be locally broken into 8 bits for a subnet ID followed by 8 bits for a host ID.

Machines in an IP network are named in also in a hierarchical manner, with each naming level separated by a dot. Names to the left are lower in the hierarchy. For example, the name bescot.cl.cam.ac.uk identifies a machine named bescot in England (uk), under the Academia hierarchy (ac), within Cambridge University (cam), within the Computer Laboratory (cl). There is no relationship between the hierarchy of naming machines and the underlying IP addresses. An IP address corresponding to a name can found by looking it up in some database. In the past, that database was a single file (/etc/hosts) that contained the address of every machine. As the Internet grew, that file became difficult to manage. Now, in most cases, you would contact a network-based name service offered by some machine that may in turn contact (or tell you to contact) other name servers until it finds a machine that knows the address for a given name. These name servers are known as Domain Name Servers, or DNS.

Running out of IP addresses

As the Internet expanded in the early 1990s to include more networks and more hosts, the three-layer class hierarchy of IP addresses was getting stressed. More and more organizations wanted to be on the Internet. To be on the Internet, each machine would need an IP address. An organization would request an IP network address for a class that was sufficiently large to accommodate all of its machines (and all of the machines it plans to get in the future).

The problem we were having with class-based Internet addressing was not in running out of IP addresses (exhausting all possible IP addresses) but rather running out of IP network addresses (of which there are only two million available). Many organizations also wanted more than a class C network and there are only a bit over 16,000 class A and B networks available.

While the class-based IP addressing scheme can accommodate close to four million distinct addresses, the problem was that the class-based network granularity was too coarse. For example, a class C network can support up to 254 host numbers. If an organization needed up to 1,000 hosts, it would need to request a far more precious class B network (of which there are only 16,382 such networks available). The class B network will allow it to have up to 65,534 host numbers, meaning that over 64,000 IP addresses, or over 98% of the address space, will go unused.

To combat this problem, a routing structure called Classless Inter-Domain Routing (CIDR) was created. This is a structure that tries to provide a better match between the range of addresses assigned to an organization and the number of addresses the organization really needs.

The practice of identifying a class of network (A, B, or C) by looking at the leading bits of the IP address was abandoned. Instead, an IP network number is defined to be a n arbitrary number of leading bits of an address. Using the earlier example, if an organization needed to support 1,000 hosts, it would request a class B address, wasting over 64,000 addresses. Now it can request a 22-bit network number, which provides it with 10 bits of addressing for hosts, enough for 1,022 machines.

Since we can no longer look at the leading bits of an IP address and know how many of the following bits constitute the network number, each entry in the routing table now has to contain this number explicitly. A CIDR IP address includes the standard 32-bit IP addresses and information on the number of bits for the network prefix (for example, 128.6.13.3/16, where the 16 refers to a sixteen bit network number). The pitfall of CIDR is that one now has to manage the prefixes as well as addresses. When routing tables are distributed, they must include the prefixes for the addresses to make sense from a routing point of view.

CIDR requires router tables contain both an IP address and the number of bits for the network prefix. This structure helps alleviate another problem in IP networking: large global routing tables. With class-based IP addressing, every network had to have a routing entry in global routers on the Internet. This was both an administrative pain and a performance bottleneck. If network addresses can be assigned "sensibly", routing tables can be simplified. If adjacent network addresses are generally routed in the same way (for example, they belong to the same ISP and the routes split up only when they get to that ISP’s network), then the global routing tables do not need to contain all those networks; they can simply specify that less bits are significant for the route (i.e., as far as the router is concerned it is a single route to the network with less bits being used for the network number).

Another innovation in IP addressing also helped alleviate the problem of assigning network addresses to organizations. The idea is that if every machine in an organization does not need to be addressed from the Internet, it need not have a unique IP address. Machines within an organization now can have internal IP addresses that are not unique across the Internet but only unique within the organization. Whenever a machine sends a packet outside the organization, it is routed through a gateway that will translate the address from an internal address to an external address. This will be the address of the gateway system (which must have a true external IP address). In translating the address, the gateway will keep a table of the original address and port number and the outgoing, translated, port number. When a return packet comes for that port number, the gateway identifies it as a response to the original packet and rewrites the destination in the IP header as the internal address and port number of the original sender. This scheme is known as network address translation, or NAT. The biggest benefit of NAT is that large organizations no longer need to request a network that can address thousands or tens of thousands of hosts. They only need to support the number of hosts that need to be visible from the Internet (e.g., those running services) as well as gateways.

IP Routing

How does a packet find its way from here to there? A switching element is used to connect two or more transmission lines (e.g., Ethernet networks). This switching element is known as a router. It can be a dedicated piece of hardware or a general-purpose computer with multiple network interfaces. When it gets packet data, it has to decide to which line the data has to be sent. This job is called routing. When a router receives an IP packet, it checks the destination address. If the destination address matches that of the receiving system, then the packet is delivered locally. Otherwise, router uses the destination address to search a routing table. Each entry in the table has an address, the number of significant bits (usually represented by a bit mast known as a netmask), and an outgoing interface. When an entry is located that matches the IP destination address (not counting the bits outside the netmask), the packet can be sent out on the interface defined on that line. This technique is known as static routing. An alternative to static routing is dynamic routing, which is a class of protocols by which machines can adjust routing tables to benefit from load changes and failures.

Drivers

We will cover the driver and data flow structure in more detail when we look at sockets in the next lecture.

IP driver

IP is a logical network that sits on top of multiple physical networks. Operating systems that support communication over IP have module that is called an IP driver. The IP driver is responsible for implementing the Internet Protocol and performs the following operations:

  • getting operating parameters from the device driver (which controls the network card) such as maximum packet size, functions to initialize the hardware headers, and the length of the hardware header
  • routing packets from one physical network to another
  • fragmenting packets: it might have to send a packet that is too big for the network hardware to handle in which case it has to be split into several packets, each with its own IP header containing destination information
  • performing send operations from higher level software
  • receiving data from the device driver
  • dropping data with bad checksums in the header
  • dropping expired packets

Ethernet driver

A logical network has to communicate with an underlying physical network. That network is typically an ethernet network (or Wi-Fi, which is conceptually very similar). The ethernet driver is responsible for interfacing to the NIC. It has to:

  • Process interrupts from the network interface, receive packets, and send them up to the higher levels (the IP driver if the data is an IP packet).
  • Get packets from the higher levels (e.g., the IP driver) and send them to the hardware, ensuring that the packet goes out without a collision.

Before an IP packet is sent on an ethernet network, it has to be encapsulated, or enveloped, for the physical (ethernet) network. Encapsulation means that the entire IP packet is simply treated as data as far as the ethernet network is concerned. The IP packet is placed within an ethernet packet, that must have a valid ethernet address in it.

To get a valid ethernet destination address for an IP address, the IP address is first looked up in the routing table to see if it gets routed to a specific IP address within the LAN. If so, that address will be used as the destination address. The IP address is then converted to its corresponding ethernet address via the Address Resolution Protocol (ARP). ARP finds the corresponding ethernet address via the following steps:

  1. check the local ARP cache
  2. send a broadcast ethernet packet requesting the ethernet address of a machine with a certain IP address
  3. wait for a response (with a time out period)

Protocols over IP

IP supports two transport layer protocols: TCP and UDP. There are also special protocols for sending control messages to guide routing decsions that are not used for application-level communication. These include ICMP (Internet Control Message Protocol) and RIP (Router Information Protocol) as well as others, such as OSPF, IGRP, EIGRP, IS-IS, and BGP.

The two transport layer protocols over IP are:

TCP — Transport Control Protocol
  • virtual circuit service (connection-oriented)
  • sends acknowledgment for each packet received
  • checksum to validate data contents
  • data may be transmitted simultaneously in both directions over a circuit
  • no record markers (one write may have to be read with multiple reads) but data arrives in sequence
UDP — User Datagram Protocol
  • datagram service (connectionless)
  • data sent may be lost
  • data may arrive out of sequence
  • recipient’s address must be specified in each request
Applications may use either of these protocols to send data over the network.

References