Session Tuple
Definition
The five-element identifier for a network session: source IP, source port, destination IP, destination port, and protocol. The session tuple is the primary anchor for correlating firewall, proxy, and packet-capture records that belong to the same connection.
- Elements
- Source IP, source port, destination IP, destination port, protocol
- Element count
- Five
- Function
- Anchor for correlating logs across sources
- Applies to
- Firewall, proxy, and packet-capture records
Common questions
Why is the full five-tuple needed instead of just the IP addresses?+
Ports and protocol distinguish separate concurrent sessions between the same two IP addresses, such as multiple simultaneous connections from one host, so omitting them would merge unrelated sessions during correlation.
What happens to the tuple if network address translation is involved?+
NAT changes the observed source IP and port between internal and external log sources, so investigators must map translated tuples back to the original internal values before correlating records end to end.
Related terms
- Anchor Event
- A log entry that can be identified with high confidence across two or more log sources, used to verify relative clock offsets...
- Clock Skew
- The difference between a device's local clock and a trusted reference time such as UTC. Skew accumulates due to hardware drift, timezone...
- DHCP Lease Log
- A record maintained by a Dynamic Host Configuration Protocol server that maps each IP address assignment to the requesting device's MAC address,...
- Log Normalisation
- The conversion of log entries from their native format into a common schema, typically a structured record with a corrected UTC timestamp,...
- NAT (Network Address Translation)
- A mechanism by which a router replaces private source IP addresses with a single public IP address before forwarding packets to the...