Transmission Control Protocol (TCP)

Connection-oriented transport protocol that opens sessions with a handshake and uses sequence numbers, acknowledgements and retransmission to deliver data reliably and in order.

Transmission Control Protocol is the connection-oriented protocol at the transport layer of the internet protocol suite (OSI layer 4), first specified in RFC 793 in 1981 and now defined by RFC 9293. Before any data moves, the two ends open a connection with the three-way handshake. Every byte then carries a sequence number, the receiver acknowledges what arrives, and anything unacknowledged is sent again, so the application receives a complete stream in the right order. Flow control stops a fast sender overrunning a slow receiver, and congestion control slows senders on a busy network. Services are reached through port numbers.

The trade-off against UDP is reliability against overhead: TCP’s guarantees cost extra round trips, so time-sensitive traffic such as live voice often uses UDP instead. TCP’s own machinery is also an attack surface. A SYN flood exhausts the state a server keeps for half-open connections, forged reset segments can tear down sessions, and session hijacking can exploit predictable sequence numbers. TCP itself gives no confidentiality; that comes from TLS above it or IPsec below it.

Exam relevance: a scenario is likely to ask which transport suits an application that needs guaranteed delivery, or which layer a TCP attack targets. Candidates are expected to link TCP with reliability, ordering and connection state, and UDP with speed and no delivery guarantee.