What is the purpose of the ISO/OSI reference model, and how is it used in cyber security architecture?
It describes network communication in seven layers so that communication across very different technical systems can be described and developed further; in CSA it is used to classify what a security component does and to describe attacks.
The model (Open Systems Interconnection, an ISO standard since 1983) dates from the early days of networking and is still everyday vocabulary. Its seven layers run from the physical layer (cables, hubs) through data link (Ethernet, switches), network (IP, routers), transport (TCP, UDP) up to the application layer.
Two typical uses in CSA:
- Classifying security components. Azure Firewall, for example, advertises stateful filtering of layer 3 and layer 4 protocols; a web application firewall works on layer 7.
- Describing attacks. DDoS attacks are commonly grouped by the layer they target: network (3), transport (4), presentation (6) or application (7). Google reported a record layer-7 DDoS in 2022, with the Mēris botnet sending up to 46 million HTTPS requests per second.
Tip: When a product or an attack report names a layer, you immediately know which components can see it and which can stop it.