Back to Delhi

Delhi Police Issue 5-Step Guidelines for IPDR and VPN Data Analysis

Delhi Police Issue 5-Step Guidelines for IPDR and VPN Data Analysis

Delhi Police released standardised guidelines and training materials on Saturday to streamline Internet Protocol Detail Records (IPDR) and dump-data analysis for criminal investigations across the national capital, including past landmark security sites like Red Fort. The new Standard Operating Procedures (SOPs) aim to guide officers handling digital activity mapping amid a spike in demand for internet data during major incidents and mass gatherings.

With separate cyber police stations established in each district alongside specialised units in the Crime Branch and Special Cell, the guidelines establish a uniform procedure for investigators. Police stated that dump-data and IPDR analysis are routinely required during investigations into heinous crimes, large-scale planned processions, and major security cases.

According to training documents prepared by a Delhi Police sub-inspector, IPDR contains metadata regarding a user's internet activity. It helps investigators establish data volume and service access by tracking timestamps, source and destination IP addresses, source and destination ports, uploaded and downloaded bytes, session durations, and subscriber identifiers. Officers correlate this information with Call Detail Records (CDRs), customer Know Your Customer (KYC) forms, and mobile tower data to trace physical locations and establish user activity.

The guidelines also provide specific instructions on identifying VPN and proxy services used to conceal online activity. Officers are instructed to monitor connections to high-risk IP addresses, traffic moving through uncommon ports, long-duration sessions involving low data volumes, encrypted traffic on non-standard ports, repeated connections to identical remote IPs, and unusually high data transfers during odd hours.

The training material outlines a structured five-step workflow for analysing IPDR: data ingestion and normalisation, IP and port mapping, correlation, behavioural profiling, and reporting and evidence. Under behavioural profiling, investigators create user timelines to detect anomalies, dark web usage, and connections to malicious infrastructure. The protocol instructs officers to maintain legal authorisation, chain of custody, subscriber privacy, and data integrity by documenting findings through screenshots and timelines.

Share

Related Stories