3. OSI Model, TCP/IP Model, TCP vs UDP and the 3-Way Handshake
3.4 TCP vs UDP
Aata transport layer che don hero – TCP aani UDP. Class madhe mala nehmi vicharla jata: "Sir, TCP reliable aahe tar sagla TCP var ka nahi?" Karan reliability chi kimmat aahe – handshake, acknowledgement, retransmission. Live video call madhe ek frame gela tar chalel, pan wait kelela chalnar nahi.
| Feature | TCP | UDP |
|---|---|---|
| Connection | Connection-oriented (3-way handshake SYN, SYN-ACK, ACK) | Connectionless |
| Reliability | Guaranteed delivery, ordering, retransmission | Best effort; may lose packets |
| Speed / overhead | Slower, 20-byte header | Faster, 8-byte header |
| Uses | Web (HTTP/1.1, HTTP/2), SSH, e-mail, databases | DNS, DHCP, VoIP, streaming, gaming, HTTP/3 (QUIC) |
| The difference is visible in the headers themselves – TCP carries much more control information: |
| Header field | TCP | UDP |
|---|---|---|
| Source / destination port | Yes | Yes |
| Sequence and acknowledgement numbers | Yes | No |
| Flags (SYN, ACK, FIN, RST, PSH, URG) | Yes | No |
| Window size (flow control) | Yes | No |
| Checksum | Yes | Yes (optional in IPv4) |
sudo ss -tn # established TCP connections
sudo ss -un # UDP sockets
dig example.com # DNS query – normally over UDP 53
Why this matters for security
TCP's handshake is abused in SYN flood attacks (half-open connections exhaust the server). UDP has no handshake, so the source IP is easy to spoof – this enables amplification DDoS through open DNS, NTP or memcached servers. Scanning is different too: TCP ports answer clearly, UDP scanning (nmap -sU) is slow and ambiguous, so admins often forget UDP services that are quietly open.
Ravindra Bagale's Tip
Many students remember only that "DNS runs over UDP". But a large response or a zone transfer (AXFR) goes over TCP 53. Don't forget this when writing a firewall rule or reading Nmap results – DNS needs both UDP and TCP 53.
Ravindra Bagale's Tip – मराठी
"DNS UDP वर चालतो" एवढंच बरेच students लक्षात ठेवतात. पण मोठा response किंवा zone transfer (AXFR) TCP 53 वर जातो. Firewall rule लिहिताना किंवा Nmap result वाचताना हे विसरू नका – DNS ला UDP आणि TCP दोन्ही 53 लागतात.
Ravindra Bagale's Tip – हिंदी
बहुत से students बस इतना याद रखते हैं कि "DNS UDP पर चलता है". पर बड़ा response या zone transfer (AXFR) TCP 53 पर जाता है. Firewall rule लिखते समय या Nmap result पढ़ते समय यह मत भूलना – DNS को UDP और TCP दोनों 53 चाहिए.
Practice task
Make a two-column list of ten services (HTTP, SSH, DNS, DHCP, SNMP, MySQL, RDP, NTP, SMTP, TFTP) and mark each as TCP, UDP or both. Then add a live video call and an online game, and write one reason for your choice for each.