Delhi Police Standardizes Internet Metadata Analysis
New five-step workflow explains how investigators should process internet-session records, identify possible traffic masking and match online activity with phone and subscriber data.
Topics
News
- Temasek, Seraphim Back Pixxel in $100 Million Round
- UN Rights Chief Warns Advanced AI Could Threaten Humanity
- Tata-owned JLR to Cut About 4,000 Bobs Amid Tariff, China Pressure
- Anthropic Walks Away From $6 Billion Decart Deal
- Hyundai India Targets 20% Women in Executive Workforce by 2030
- Security Breach Drains $320 Million in Bitcoin From Liquid Network
Delhi Police has standardized how investigators analyze internet metadata, according to training documents released last week.
The procedures are intended for cybercrime investigations, serious criminal cases and security operations involving major incidents or large gatherings.
The standard operating procedures, released on Saturday, August 8, cover Internet Protocol Detail Records, known as IPDR, and the analysis of bulk datasets commonly called dump data.
IPDR records are generated when a device connects to services over the internet. They do not contain the text of a message, the contents of an email, the audio of a call or the material viewed on a web page. Instead, they contain metadata describing the connection.
That information can include when a session started and ended, the internet addresses involved, the volume of data uploaded or downloaded and the network ports used. An IP address is the numerical address used to route internet traffic, while a port is a numbered connection point that can help indicate the type of network service involved.
A destination IP address may help investigators infer which service or online infrastructure a device contacted. Investigators can match IPDR data with call detail records, subscriber documents and mobile tower information. Subscriber records include the identity and address documents collected when a mobile or internet connection is activated.
Together, the records may help police determine which subscriber was assigned an IP address at a particular time, when a device was active and whether its internet use coincided with calls, messages or movement between mobile towers. They cannot, by themselves, prove who was physically using the device.
“We have laid out guidelines since there’s a spike in IPDR analysis,” a senior Delhi Police officer told Hindustan Times.
The training material sets out a five-stage process covering data preparation, mapping of IP addresses and ports, correlation with other records, behavioral analysis and preparation of evidence.
One part of the guidance focuses on identifying possible use of virtual private networks, proxies and Tor. Investigators are advised to examine indicators such as repeated connections to unusual IP addresses, encrypted traffic through uncommon ports, lengthy sessions involving small amounts of data and unusually high traffic at odd hours.
The SOP also instructs officers to build timelines of user activity and look for deviations or sudden changes in internet behavior that could be relevant to an investigation.
Delhi Police has cyber police stations across its districts as well as specialized cyber units, making uniform analysis increasingly important as digital evidence becomes part of a wider range of cases.
The guidelines also address safeguards around the handling of such data.
Investigators have been told to maintain legal authorization, preserve chain of custody and data integrity, document findings through records such as timelines and screenshots, and account for subscriber privacy.


