How do I move from a connection to a device, user and responsible person?¶
title: "How do I move from a connection to a device, user and responsible person?" card_id: "IP-080" status: "complete" source_document: "https://docs.google.com/document/d/12dhJGOW8GLM1MEjMBSEnBCVMkrWr0BpWMaGy4o3H0eE/edit?usp=drivesdk"
How do I move from a connection to a device, user and responsible person?¶
An IP enquiry may begin with a connection recorded by an online service.
The aim is often to identify the person responsible.
But there are several different steps between those two points.
First, establish the event.
What did the recording system actually observe, and what does the IP address relate to?
Next, identify the connection or infrastructure.
A provider result may associate the public address and time with a household, business, mobile session, VPN account or hosted server.
That doesn't yet identify the device.
For a household or organisation, local network records may help connect the activity with a private address, Wi-Fi association or particular machine.
For a hosted service, provider records may identify a virtual server or customer account.
The next step is control.
Who could use that device, connection or account at the relevant time?
A laptop may be shared. A phone can provide a hotspot. An account may be compromised. A server may be administered remotely by several people.
Then consider the user.
Authentication records, device artefacts, communications, account activity and physical evidence may help show who was actually operating the system.
Finally, responsibility still has to be established.
Proving that somebody used a device or account doesn't automatically prove intent, knowledge or responsibility for every action it generated.
Automated activity, malware, remote access and innocent explanations may need to be considered.
The chain won't always be neat or complete.
Different evidence may support several stages at once, while some stages may remain uncertain.
The important discipline is to state what each result genuinely establishes.
Connection evidence can lead to infrastructure.
Infrastructure records can lead to an account, session or device.
Further evidence can connect that device or account with a user.
Only the combined evidence can support a conclusion about the person responsible.
An IP address begins the attribution chain. It doesn't skip it.