Can the IP link this event to earlier intelligence or other cases?¶
title: "Can the IP link this event to earlier intelligence or other cases?" card_id: "IP-107" status: "complete" source_document: "https://docs.google.com/document/d/10kdkqA0v_G8fnXTrdgZ8EtbZAgkONqqbp9D8Bsr_KOU/edit?usp=drivesdk"
Can the IP link this event to earlier intelligence or other cases?¶
IP-107 Can the IP link this event to earlier intelligence or other cases?
An IP address appears in this event and in earlier intelligence or another case. That can be a useful link, but it isn’t automatically a link between offenders.
Start with the exact values. Confirm the complete IP address, the date, time and time zone for every event, and the source of each record. Check for transcription errors and establish what each system actually recorded.
Then examine the address over time. Was it allocated to the same provider, customer connection or hosted resource during all the relevant periods? A dynamic address may pass between subscribers. A cloud address may be reassigned to a new customer. A VPN, proxy, mobile network or public Wi-Fi address may represent many unrelated users even at the same time.
The closer and more distinctive the circumstances, the more useful the comparison may become. Events involving the same account, device identifier, session detail, payment method, communication pattern or unusual behaviour provide a stronger basis for linkage than the address alone.
Look for differences as well as similarities. If one event came through a residential connection and another occurred months later after the address had moved to a hosting provider, the apparent match may be meaningless. If the same shared exit address appears in thousands of unrelated records, its discriminatory value is low.
Record where the earlier information came from. An intelligence entry, provider response, platform log and analyst summary don’t carry the same weight. Avoid circular corroboration where several case records all repeat one original report.
The IP match can justify further comparison, preservation or coordination between enquiries. It may help identify a common service, infrastructure choice, victim system or method. Those can be valuable findings even if a common person can’t be established.
State the result carefully. The events share a recorded IP address, subject to the timing, allocation and source limitations identified. That supports a line of enquiry or possible association. It doesn’t, without independent links, prove that the same device, user or offender was responsible for both.