A network socket is a software structure within a
network node of a
computer network that serves as an endpoint for sending and receiving data across the network. The structure and properties of a socket are defined by an
application programming interface
An application programming interface (API) is a way for two or more computer programs to communicate with each other. It is a type of software interface, offering a service to other pieces of software. A document or standard that describes how t ...
(API) for the networking architecture. Sockets are created only during the lifetime of a
process of an application running in the node.
Because of the
standardization
Standardization or standardisation is the process of implementing and developing technical standards based on the consensus of different parties that include firms, users, interest groups, standards organizations and governments. Standardization ...
of the
TCP/IP protocols in the development of the
Internet, the term ''network socket'' is most commonly used in the context of the Internet protocol suite, and is therefore often also referred to as Internet socket. In this context, a socket is externally identified to other hosts by its socket address, which is the triad of
transport protocol,
IP address, and
port number.
The term ''socket'' is also used for the software endpoint of node-internal
inter-process communication
In computer science, inter-process communication or interprocess communication (IPC) refers specifically to the mechanisms an operating system provides to allow the processes to manage shared data. Typically, applications can use IPC, categori ...
(IPC), which often uses the same API as a network socket.
Use
The use of the term ''socket'' in software is analogous to the function of an electrical
female connector
In electrical and mechanical trades and manufacturing, each half of a pair of mating connectors or fasteners is conventionally assigned the designation male or female. The female connector is generally a receptacle that receives and holds the ...
, a device in hardware for communication between nodes interconnected with an
electrical cable. Similarly, the term ''
port'' is used for external physical endpoints at a node or device.
The application programming interface (API) for the network protocol stack creates a
handle for each socket created by an application, commonly referred to as a ''socket descriptor''. In
Unix-like operating systems, this descriptor is a type of
file descriptor
In Unix and Unix-like computer operating systems, a file descriptor (FD, less frequently fildes) is a process-unique identifier (handle) for a file or other input/output resource, such as a pipe or network socket.
File descriptors typically have ...
. It is stored by the application process for use with every read and write operation on the communication channel.
At the time of creation with the API, a network socket is bound to the combination of a type of network protocol to be used for transmissions, a network address of the host, and a
port number. Ports are numbered resources that represent another type of software structure of the node. They are used as service types, and, once created by a process, serve as an externally (from the network) addressable location component, so that other hosts may establish connections.
Network sockets may be dedicated for persistent connections for communication between two nodes, or they may participate in
connectionless
Connectionless communication, often referred to as CL-mode communication,Information Processing Systems - Open Systems Interconnection, "Transport Service Definition - Addendum 1: Connectionless-mode Transmission", International Organization for ...
and
multicast communications.
In practice, due to the proliferation of the TCP/IP protocols in use on the Internet, the term ''network socket'' usually refers to use with the
Internet Protocol (IP). It is therefore often also called Internet socket.
Socket addresses
An application can communicate with a remote process by exchanging data with TCP/IP by knowing the combination of protocol type, IP address, and port number. This combination is often known as a ''socket address''. It is the network-facing access handle to the network socket. The remote process establishes a network socket in its own instance of the protocol stack, and uses the networking API to connect to the application, presenting its own socket address for use by the application.
Implementation
A
protocol stack, usually provided by the
operating system (rather than as a separate library, for instance), is a set of services that allow processes to communicate over a network using the protocols that the stack implements. The operating system forwards the payload of incoming IP packets to the corresponding application by extracting the socket address information from the IP and transport protocol headers and stripping the headers from the application data.
The application programming interface (API) that programs use to communicate with the protocol stack, using network sockets, is called a socket API. Development of application programs that utilize this API is called ''socket programming'' or ''
network programming''. Internet socket APIs are usually based on the
Berkeley sockets standard. In the Berkeley sockets standard, sockets are a form of
file descriptor
In Unix and Unix-like computer operating systems, a file descriptor (FD, less frequently fildes) is a process-unique identifier (handle) for a file or other input/output resource, such as a pipe or network socket.
File descriptors typically have ...
, due to the
Unix philosophy that "everything is a file", and the analogies between sockets and files. Both have functions to read, write, open, and close. In practice the differences strain the analogy, and different interfaces (send and receive) are used on a socket. In
inter-process communication
In computer science, inter-process communication or interprocess communication (IPC) refers specifically to the mechanisms an operating system provides to allow the processes to manage shared data. Typically, applications can use IPC, categori ...
, each end generally has its own socket.
In the standard Internet protocols TCP and UDP, a socket address is the combination of an
IP address and a
port number, much like one end of a telephone connection is the combination of a
phone number and a particular
extension
Extension, extend or extended may refer to:
Mathematics
Logic or set theory
* Axiom of extensionality
* Extensible cardinal
* Extension (model theory)
* Extension (predicate logic), the set of tuples of values that satisfy the predicate
* E ...
. Sockets need not have a source address, for example, for only sending data, but if a program ''binds'' a socket to a source address, the socket can be used to receive data sent to that address. Based on this address, Internet sockets deliver incoming
data packets to the appropriate application
process.
''Socket'' often refers specifically to an internet socket or TCP socket. An internet socket is minimally characterized by the following:
* local socket address, consisting of the local IP address and (for TCP and UDP, but not IP) a port number
* protocol: A transport protocol, e.g., TCP, UDP, raw IP. This means that (local or remote) endpoints with TCP port 53 and UDP port 53 are distinct sockets, while IP does not have ports.
* A socket that has been connected to another socket, e.g., during the establishment of a TCP connection, also has a remote socket address.
Definition
The distinctions between a socket (internal representation), socket descriptor (abstract identifier), and socket address (public address) are subtle, and these are not always distinguished in everyday usage. Further, specific definitions of a ''socket'' differ between authors. In
IETF Request for Comments,
Internet Standards, in many textbooks, as well as in this article, the term ''socket'' refers to an entity that is uniquely identified by the socket number. In other textbooks, the term ''socket'' refers to a local socket address, i.e. a "combination of an IP address and a port number". In the original definition of ''socket'' given in RFC 147, as it was related to the
ARPA network in 1971, ''"the socket is specified as a 32 bit number with even sockets identifying receiving sockets and odd sockets identifying sending sockets."'' Today, however, socket communications are bidirectional.
Within the operating system and the application that created a socket, a socket is referred to by a unique integer value called a ''socket descriptor''.
Tools
On Unix-like operating systems and
Microsoft Windows
Windows is a group of several proprietary graphical operating system families developed and marketed by Microsoft. Each family caters to a certain sector of the computing industry. For example, Windows NT for consumers, Windows Server for serv ...
, the command-line tools
netstat or
ss'' are used to list established sockets and related information.
Example
This example, modeled according to the Berkeley socket interface, sends the string "Hello, world!" via
TCP
TCP may refer to:
Science and technology
* Transformer coupled plasma
* Tool Center Point, see Robot end effector
Computing
* Transmission Control Protocol, a fundamental Internet standard
* Telephony control protocol, a Bluetooth communication s ...
to port 80 of the host with address 1.2.3.4. It illustrates the creation of a socket (getSocket), connecting it to the remote host, sending the string, and finally closing the socket:
Socket mysocket = getSocket(type = "TCP")
connect(mysocket, address = "1.2.3.4", port = "80")
send(mysocket, "Hello, world!")
close(mysocket)
Types
Several types of Internet socket are available:
;Datagram sockets
:
Connectionless
Connectionless communication, often referred to as CL-mode communication,Information Processing Systems - Open Systems Interconnection, "Transport Service Definition - Addendum 1: Connectionless-mode Transmission", International Organization for ...
sockets, which use
User Datagram Protocol (UDP). Each packet sent or received on a datagram socket is individually addressed and routed. Order and reliability are not guaranteed with datagram sockets, so multiple packets sent from one machine or process to another may arrive in any order or might not arrive at all. Special configuration may be required to send
broadcasts on a datagram socket. In order to receive broadcast packets, a datagram socket should not be bound to a specific address, though in some implementations, broadcast packets may also be received when a datagram socket is bound to a specific address.
;Stream sockets
:
Connection-oriented
Connection-oriented communication is a network communication mode in telecommunications and computer networking, where a communication session or a semi-permanent connection is established before any useful data can be transferred. The establish ...
sockets, which use
Transmission Control Protocol (TCP),
Stream Control Transmission Protocol
The Stream Control Transmission Protocol (SCTP) is a computer networking communications protocol in the transport layer of the Internet protocol suite. Originally intended for Signaling System 7 (SS7) message transport in telecommunication, the p ...
(SCTP) or
Datagram Congestion Control Protocol
In computer networking, the Datagram Congestion Control Protocol (DCCP) is a message-oriented transport layer protocol. DCCP implements reliable connection setup, teardown, Explicit Congestion Notification (ECN), congestion control, and feature ne ...
(DCCP). A stream socket provides a
sequenced and unique flow of error-free data without record boundaries, with well-defined mechanisms for creating and destroying connections and reporting errors. A stream socket transmits data
reliably, in order, and with
out-of-band
Out-of-band activity is activity outside a defined telecommunications frequency band, or, metaphorically, outside of any primary communication channel. Protection from falsing is among its purposes.
Examples General usage
* Out-of-band agreement ...
capabilities. On the Internet, stream sockets are typically implemented using TCP so that applications can run across any networks using TCP/IP protocol.
;Raw sockets
:Allow direct sending and receiving of IP packets without any protocol-specific transport layer formatting. With other types of sockets, the
payload
Payload is the object or the entity which is being carried by an aircraft or launch vehicle. Sometimes payload also refers to the carrying capacity of an aircraft or launch vehicle, usually measured in terms of weight. Depending on the nature of ...
is automatically
encapsulated according to the chosen transport layer protocol (e.g. TCP, UDP), and the socket user is unaware of the existence of protocol
headers that are broadcast with the payload. When reading from a raw socket, the headers are usually included. When transmitting packets from a raw socket, the automatic addition of a header is optional.
:Most socket
application programming interface
An application programming interface (API) is a way for two or more computer programs to communicate with each other. It is a type of software interface, offering a service to other pieces of software. A document or standard that describes how t ...
s (APIs), for example, those based on
Berkeley sockets, support raw sockets.
Windows XP was released in 2001 with raw socket support implemented in the
Winsock interface, but three years later, Microsoft limited Winsock's raw socket support because of security concerns.
:Raw sockets are used in security-related applications like
Nmap. One use case for raw sockets is the implementation of new transport-layer protocols in
user space. Raw sockets are typically available in network equipment, and used for
routing protocols such as the
Internet Group Management Protocol (IGMP) and
Open Shortest Path First (OSPF), and in the
Internet Control Message Protocol
The Internet Control Message Protocol (ICMP) is a supporting protocol in the Internet protocol suite. It is used by network devices, including routers, to send error messages and operational information indicating success or failure when communi ...
(ICMP) used, among other things, by the
ping utility.
Other socket types are implemented over other transport protocols, such as
Systems Network Architecture and
Unix domain sockets for internal inter-process communication.
Socket states in the client-server model
Computer processes that provide application services are referred to as
servers, and create sockets on startup that are in the ''listening state''. These sockets are waiting for initiatives from
client programs.
A TCP server may serve several clients concurrently by creating a unique dedicated socket for each client connection in a new child process or processing thread for each client. These are in the ''established state'' when a socket-to-socket
virtual connection
A virtual circuit (VC) is a means of transporting data over a data network, based on packet switching and in which a connection is established within the network between two endpoints. The network, rather than having a fixed data rate reservation ...
or virtual circuit (VC), also known as a TCP
session, is established with the remote socket, providing a duplex
byte stream.
A server may create several concurrently established TCP sockets with the same local port number and local IP address, each mapped to its own server-child process, serving its own client process. They are treated as different sockets by the operating system since the remote socket address (the client IP address or port number) is different; i.e. since they have different
socket pair tuples.
UDP sockets do not have an ''established state'', because the protocol is
connectionless
Connectionless communication, often referred to as CL-mode communication,Information Processing Systems - Open Systems Interconnection, "Transport Service Definition - Addendum 1: Connectionless-mode Transmission", International Organization for ...
. A UDP server process handles incoming datagrams from all remote clients sequentially through the same socket. UDP sockets are not identified by the remote address, but only by the local address, although each message has an associated remote address that can be retrieved from each datagram with the networking application programming interface (API).
Socket pairs
Communicating local and remote sockets are called socket pairs. Each socket pair is described by a unique
4-tuple
In mathematics, a tuple is a finite ordered list (sequence) of elements. An -tuple is a sequence (or ordered list) of elements, where is a non-negative integer. There is only one 0-tuple, referred to as ''the empty tuple''. An -tuple is defi ...
consisting of source and destination IP addresses and port numbers, i.e. of local and remote socket addresses. As discussed above, in the TCP case, a socket pair is associated on each end of the connection with a unique 4-tuple.
History
The term ''socket'' dates to the publication of RFC 147 in 1971, when it was used in the ARPANET. Most modern implementations of sockets are based on
Berkeley sockets (1983), and other stacks such as
Winsock (1991). The Berkeley sockets API in the
Berkeley Software Distribution
The Berkeley Software Distribution or Berkeley Standard Distribution (BSD) is a discontinued operating system based on Research Unix, developed and distributed by the Computer Systems Research Group (CSRG) at the University of California, Berk ...
(BSD), originated with the 4.2BSD
Unix operating system
Unix (; trademarked as UNIX) is a family of multitasking, multiuser computer operating systems that derive from the original AT&T Unix, whose development started in 1969 at the Bell Labs research center by Ken Thompson, Dennis Ritchie, and o ...
as an API. Only in 1989, however, could
UC Berkeley release versions of its operating system and networking library free from the licensing constraints of
AT&T's copyright-protected
Unix.
In c. 1987, AT&T introduced the
STREAMS
A stream is a continuous body of water, body of surface water Current (stream), flowing within the stream bed, bed and bank (geography), banks of a channel (geography), channel. Depending on its location or certain characteristics, a stream ...
-based
Transport Layer Interface
In computer networking, the Transport Layer Interface (TLI) was the networking API provided by AT&T UNIX System V Release 3 (SVR3) in 1987 and continued into Release 4 (SVR4). TLI was the System V counterpart to the BSD sockets programming inter ...
(TLI) in
UNIX System V Release 3 (SVR3). and continued into Release 4 (SVR4).
Other early implementations were written for
TOPS-20,
[historyofcomputercommunications.info - Book: 9.8 TCP/IP and XNS 1981 - 1983](_blank)
/ref> MVS
Multiple Virtual Storage, more commonly called MVS, was the most commonly used operating system on the System/370 and System/390 IBM mainframe computers. IBM developed MVS, along with OS/VS1 and SVS, as a successor to OS/360. It is unrelated ...
, VM, IBM-DOS (PCIP).The Desktop Computer as a Network Participant.pdf
1985
Sockets in network equipment
The socket is primarily a concept used in the
transport layer of the
Internet protocol suite or
session layer of the
OSI model. Networking equipment such as
routers, which operate at the
internet layer, and
switches, which operate at the
link layer, do not require implementations of the transport layer. However, stateful
network firewalls,
network address translators, and proxy servers keep track of active socket pairs. In
multilayer switch
A multilayer switch (MLS) is a computer networking device that switches on Data link layer, OSI layer 2 like an ordinary network switch and provides extra functions on higher OSI model, OSI layers. The MLS was invented by engineers at Digital Eq ...
es and
quality of service (QoS) support in routers,
packet flow
In packet switching networks, traffic flow, packet flow or ''network flow'' is a sequence of packets from a source computer to a destination, which may be another host, a multicast group, or a broadcast domain. RFC 2722 defines traffic flow as " ...
s may be identified by extracting information about the socket pairs.
Raw socket
A network socket is a software structure within a network node of a computer network that serves as an endpoint for sending and receiving data across the network. The structure and properties of a socket are defined by an application programming ...
s are typically available in network equipment and are used for
routing protocols such as
IGRP and
OSPF, and for
Internet Control Message Protocol
The Internet Control Message Protocol (ICMP) is a supporting protocol in the Internet protocol suite. It is used by network devices, including routers, to send error messages and operational information indicating success or failure when communi ...
(ICMP).
See also
*
List of TCP and UDP port numbers
*
Promiscuous traffic In computer networking, promiscuous traffic, or cross-talking, describes situations where a receiver configured to receive a particular data stream receives that data stream and others. Promiscuous traffic should not be confused with the '' promisc ...
*
WebSocket
References
Further reading
*
External links
How sockets work- IBM information center
Server Programming with TCP/IP SocketsBeej's Guide to Network ProgrammingNet::RawIP; module for Perl applications.Created b
Sergey Kolychev
SOCK_RAW Demystified: article describing inner workings of Raw Sockets- David Buchan's C language examples of IPv4 and IPv6 raw sockets for Linux.
{{Inter-process communication