Follow one web page, https://www.example.co.nz/tours/index.html, from the moment its URL is typed to the moment the page is on the screen. Press Play, or Step from one moment to the next: each message travels along the lines as it's sent, and the panel on the right explains it. The waterfall under the picture builds up as it goes, a row for each file, as in a browser's developer tools.
- Full lookup / Cached: the first time the site is visited, or ten minutes later, when the browser already has the addresses in its cache.
- HTTPS / HTTP: with or without the TLS handshake and encryption.
The key ideas
- The URL has a protocol (https://), a domain name (www.example.co.nz) and a path to the file (/tours/index.html). A domain name is read from the right: the top-level domain (.nz), the second-level domain (.co), the name that was registered (example) and a subdomain (www).
- DNS turns the domain name into the server's IP address. The browser's cache and the operating system's are checked first, and so is the operating system's hosts file: a text file on the computer pairing names with IP addresses, typed in by hand, which is used instead of DNS for any name it lists; then the computer asks its resolver (usually the ISP's), which asks a root server, then the top-level domain (TLD) server, then the domain's authoritative name server, which has the answer. Every answer is cached for its time to live (TTL).
- TCP opens a connection with a three-way handshake: SYN, SYN-ACK, ACK. Each end says where its sequence numbers start and acknowledges the other's.
- HTTPS adds a TLS handshake: the server sends its digital certificate, the browser checks it, and both work out a session key. Everything after it is encrypted.
- HTTP: the browser sends a request (GET /tours/index.html) and the web server replies with a status code (200 OK) and the file.
- The browser parses the HTML and requests every file it refers to: a relative path (style.css) is on the same server and can use the same connection; a file on another domain (a CDN, a map server) needs its own DNS lookup, connection and request. Once the CSS has arrived it can lay out and draw (render) the page.
In the TCP/IP model these are layers: HTTP is an application layer protocol; it uses TCP (the transport layer: connections, sequence numbers, acknowledgements), which uses IP (the internet layer: addressing and routing each packet); and the link layer carries the bits across each cable or Wi-Fi hop. DNS is an application-layer protocol too.
The names are made-up examples, and the IP addresses are from the ranges kept for documentation, so none of them is a real site. Simplified: real browsers start fetching before the HTML has finished arriving, open several connections to a server at once (or use HTTP/2 to send many requests down one), and a large file is many packets. The order of the steps is right.
Common exam mistakes
"The DNS stores the web page." DNS only turns the domain name into an IP address. The page comes from the web server.
"The browser asks the root server." The computer asks its resolver; the resolver asks the root, TLD and authoritative servers in turn, and only if it hasn't the answer cached.
"The order is SYN, ACK, SYN-ACK." It's SYN, then SYN-ACK, then ACK: the SYN-ACK both acknowledges the computer's SYN and sends the server's own.
"HTTPS means the website is safe." It means the connection is encrypted and the certificate matches the domain name. A scam site can have a valid certificate for its own domain.
"The internet and the World Wide Web are the same thing." The internet is the network of networks (the hardware and the connections); the web is the collection of web pages and other resources on it, reached with HTTP(S) through a browser.
Exam-style questions and answers
1. Identify the three parts of the URL https://www.example.co.nz/tours/index.html. [3]
Answer. Protocol: https. Domain name: www.example.co.nz. File name (path): /tours/index.html.
2. Explain how a web page is located and displayed when its URL is typed into a browser. [6]
Answer. The browser sends the domain name to a DNS (domain name server); the DNS looks up the matching IP address (asking other DNS servers in turn if it doesn't have it) and returns it to the browser. The browser sends a request to the web server at that IP address, using HTTP or HTTPS. The web server sends back the HTML for the page. The browser interprets (renders) the HTML, requesting any other files it refers to (images, stylesheets, scripts), and displays the page.
3. Describe the three-way handshake used to open a TCP connection. [3]
Answer. The client sends a SYN with its initial sequence number. The server replies with a SYN-ACK, acknowledging the client's number and giving its own. The client replies with an ACK acknowledging the server's number, and the connection is open.
4. The second time the page is loaded it appears faster. Explain why, with reference to DNS. [2]
Answer. The IP address was cached (by the browser, the operating system or the resolver) the first time, for its time to live, so no DNS lookup across the internet is needed, saving several round trips.
5. State two differences between HTTP and HTTPS. [2]
Answer. HTTPS encrypts the data sent (using TLS); HTTP sends it as plain text. HTTPS uses a digital certificate so the browser can check the server is genuine; HTTP doesn't. (HTTPS normally uses port 443, HTTP port 80.)
Objective: explain how a web page is located, retrieved and displayed when a URL is entered: the URL's parts, the DNS (domain name server / service) and IP addresses, HTTP and HTTPS, and the web browser (Cambridge IGCSE Computer Science 0478, 5.1 The internet and the World Wide Web, with 2.1 packets and protocols); the role of DNS, client-server, and the TCP/IP protocols with the three-way handshake (Cambridge AS & A Level Computer Science 9618, AS 2.1 Networks including the internet, and A Level 14.1 Protocols).
Where this fits
- AP: AP Computer Science Principles Goes beyond AP Computer Science Principles: TLS handshakes and the DNS server hierarchy go beyond AP CSP.
- AQA: AQA A Level Computer Science (7517)
- Cambridge: Cambridge IGCSE Computer Science (0478); Cambridge A Level Computer Science (9618); Cambridge AS Level Computer Science (9618); Cambridge A Level Information Technology (9626) Goes beyond Cambridge IGCSE Computer Science (0478): The TCP handshake, DNS root/TLD hierarchy and request waterfall go beyond 0478.
Goes beyond Cambridge AS Level Computer Science (9618): TCP, HTTP and the TCP/IP layers are A Level (14.1) and TLS is 17.1; AS has URLs and DNS.
- IB: IB Computer Science HL; IB Computer Science SL
- NCEA Level 2 Digital Technologies: 91895 Use advanced techniques to develop a network; 91895 Use advanced techniques to develop a network
- NCEA Level 3 Digital Technologies: 91905 Use complex techniques to develop a network; 91905 Use complex techniques to develop a network
- Pearson Edexcel International: Edexcel International GCSE Computer Science (4CP0); Edexcel International A Level Information Technology
- USDP: USDP Computer Science