Skip to content
AI-grafen
EUniversityComputer science· about 60 min· evolving, reviewed regularly· verified 2026-09-20· EN

Networking — the basics

Be able to explain IP, DNS, TLS and latency — and why a lab container with no network is safe.

Prerequisites

Intuition

What happens during an API call:

  1. DNS: api.example.com → 93.184.216.34. One lookup, often cached.
  2. TCP: a three-way handshake with the server (1 round trip).
  3. TLS: the certificate is verified and keys are exchanged (1–2 round trips). Now the traffic is encrypted.
  4. HTTP: the request goes out, the response comes back.

Latency = the sum of the round trips plus the server's own time. A round trip Stockholm–Frankfurt is ~25 ms; Stockholm–California ~150 ms. A new connection costs 3–4 round trips — which is why you reuse connections (a long-lived httpx.AsyncClient, keep-alive). It is often the single biggest latency win in a client.

Bandwidth ≠ latency. More bandwidth helps with big files; latency is set by distance and the speed of light.

Formal

Network isolation as a security measure. AI-grafen's lab containers run with --network none. What that means in practice:

With no network the code cannotConsequence
resolve DNSno contact with named services
open TCP/UDP connectionsno exfiltration of data
reach metadata services (169.254.169.254)no cloud keys can be stolen
reach other containersno lateral movement
fetch packagesnothing can be installed at run time

It is the single strongest measure against malicious code in a sandbox, because almost all damage requires either that something leaves the machine or that something extra is fetched in.

The other layers in the platform (ADR-003): a read-only root filesystem, tmpfs for what must be writable, uid 65534, cap-drop ALL, no-new-privileges, CPU, memory and pid ceilings, and a timeout. Network isolation is the one that tools/isolation_check.py verifies on every CI run — precisely because it is so central.

Code

import socket, time, httpx

print(socket.gethostbyname("example.com"))          # a DNS lookup

# Reuse the connection: measure the difference
with httpx.Client() as c:
    for i in range(3):
        t = time.perf_counter(); c.get("https://example.com"); print(i, round((time.perf_counter()-t)*1000))
# 0 210   ← DNS + TCP + TLS
# 1  35   ← the connection is reused
# 2  34
# Verify the isolation in a sandbox
docker run --rm --network none python:3.12-slim \
  python -c "import socket; socket.create_connection(('1.1.1.1', 443), timeout=3)"
# OSError: [Errno 101] Network is unreachable      ← exactly what should happen

Mastery means

  • Explains IP, DNS, TLS and latency
  • Justifies why a lab container with no network is safe

Sign in to do the exercises and build your mastery up.

Sources

All the sources and licences