Five-Tuple
Definition
The five fields that uniquely identify a network flow: source IP address, source port, destination IP address, destination port, and transport protocol (TCP or UDP). Every firewall log entry records at least the five-tuple plus the action taken.
- Fields
- Source IP, source port, destination IP, destination port, protocol
- Protocol values
- TCP or UDP
- Use
- Uniquely identifies a network flow
- Logged by
- Firewalls, at minimum, alongside the action taken
Common questions
Why is the five-tuple the baseline unit for firewall log analysis?+
Because it is the minimum set of fields that distinguishes one conversation between hosts from another, an analyst can group, filter, and correlate log entries by five-tuple to reconstruct which flows occurred, even before inspecting packet payloads.
Can two different connections share the same five-tuple?+
Not while both are active on the same network segment; a five-tuple in use is exclusive to one flow. Once that flow closes, the same combination of addresses, ports, and protocol can be reused by a later, unrelated connection, so timestamps matter for correctly attributing log entries.
Related terms
- Anomaly-Based IDS
- An intrusion detection system that models normal traffic behaviour and alerts when observed traffic deviates significantly from that baseline. Detects novel attacks...
- Lateral Movement
- Attacker activity after initial compromise in which the threat actor traverses from one internal system to another, typically to escalate privileges, access...
- Proxy Log
- A record generated by a forward proxy server for each HTTP or HTTPS request made by an internal client. Contains the URL,...
- Signature-Based IDS
- An intrusion detection system that compares network traffic against a database of known attack patterns (signatures). Snort and Suricata are the dominant...
- True Positive / False Positive
- A true positive is an alert that correctly identifies malicious activity. A false positive is an alert that fires on legitimate traffic....