Internet Control Message Protocol (ICMP)
The IP suite's error-reporting and diagnostic protocol: it carries messages about delivery problems and network status, works at the Network layer, and uses no port numbers.
The Internet Control Message Protocol reports problems and conditions that arise while IP packets are delivered. Defined for IPv4 in RFC 792, which treats it as an integral part of IP, it carries messages such as destination unreachable, time exceeded, and echo request and reply. ICMPv6, defined in RFC 4443, does the same job for IPv6 and takes on extra duties there, including neighbour discovery. ICMP messages travel inside IP packets but are identified by a type and a code rather than by a port, and the protocol sits at the Network layer of the OSI model alongside the Internet Protocol.
Everyday tools depend on it: ping uses echo messages, and traceroute relies on time exceeded replies to map a path. The same openness makes ICMP useful to attackers for reconnaissance and floods, and for attacks such as the smurf attack and the ping of death. ICMP payloads can also hide a covert channel. Blocking all ICMP is not a clean fix, because path MTU discovery and IPv6 operation rely on some ICMP messages; filtering by message type is the more common approach.
Exam relevance: questions in this area tend to turn on where ICMP sits (layer 3, no ports), which attacks abuse it, and why a blanket block can break legitimate networking.