Skip to content
Skip to main content
IP Addresses & Networks Technical Explainer

What does a connection or session record actually prove?

Different systems use connection and session to mean different things. First establish what event makes that particular system create the record.

A connection may begin at different points

A system might create a connection record when:

  • it sees the first packet;
  • a TCP handshake completes;
  • a firewall allows traffic;
  • an application accepts a request; or
  • a service groups related traffic together.

Check the event type, status and system documentation before deciding how far the communication progressed.

TCP connections

TCP normally starts with a three-way handshake. The two systems exchange messages before the connection is established.

This creates a useful distinction:

  • an initial request shows a connection attempt; and
  • a completed handshake shows that the systems could exchange traffic along that network path.

Application records are then needed to show what happened within the connection, such as a login, file transfer or message.

UDP “connections”

UDP does not use the same setup process. A firewall or monitoring system may still group UDP packets by their addresses, ports and timing and call the result a connection or session.

Treat that as the system’s way of organising traffic, then inspect the packets, event count and application records to see what took place.

Application and account sessions

A platform may use a cookie or token to group a series of requests. A VPN may create a session when a device or account connects to its gateway.

Session records may contain:

  • start and end times;
  • account and device details;
  • source and assigned IP addresses;
  • a session identifier;
  • authentication information; and
  • data volumes.

Use those fields to find the actions that occurred during the session. An end time may represent a logout, disconnection or automatic timeout, so check how the service records it.

Read the record in stages

Ask:

  1. What caused the record to be created?
  2. Did the connection or authentication complete?
  3. Which traffic or actions are grouped into it?
  4. What other logs share the same session or event identifier?

Operational takeaway

Find out what the system means by connection or session, identify how far it progressed, then use the shared identifiers to locate the activity within it.

Explore related guidance
Reference: IP-024IP Addresses & Networks