What is an IP address?¶
An IP address is simply addressing information used to move data across an IP network. It helps networks deliver data to the right connection and send a response back. For an investigator, a recorded IP address can identify a network connection or the next organisation to ask - but it is not a person's, or even a device's, permanent digital name.
What is an IP address?
This version retains the calibration script and Hazel placeholder narration while testing the corrected shared visual system. Its creative treatment remains unreviewed.
Open or download the corrected benchmark MP4 if inline playback does not work. Open the preserved original pilot.
Start with the investigation record¶
In the online-fraud walkthrough, a retailer supplies an activity record associated with a completed checkout:
14:36:42.318 UTC198.51.100.27The retailer's system associated this checkout with a particular account, request, time, source IP address and source port. Those details allow the event to be checked against other records rather than treated as an isolated address.
The record does not by itself identify the person who acted, the physical device used or who was responsible for the fraud. This is because several people or devices may share an address, an address may change, and an intermediary may be what the retailer actually saw.
An IP address has its main investigative use as part of a recorded event. Copied out on its own - as just a bunch of numbers with dots or colons between them - it loses the time, system and activity that give it meaning.
How an IP address helps move data¶
Information travelling across an IP network is divided into small units called IP packets. Each packet combines addressing information with a portion of the data being carried so that networks can move it towards its destination.
- The destination IP address tells routers where the packet is intended to go, so they can move it towards the receiving network.
- The source IP address is the source presented in that packet, so responses can be directed back towards it.
- The payload carries the relevant data, such as part of a webpage, message, image or other content.
Routers can therefore forward a packet without needing to understand its payload. The source address eventually recorded by an online service may still be changed or presented by translation or an intermediary elsewhere in the route, which is why the observation point matters to an investigation.
Prefer an analogy?
IPv4 and IPv6 are two address formats¶
The internet currently uses two versions of IP. They perform the same broad addressing job but write their addresses differently, so investigators need to recognise both when checking and comparing records.
198.51.100.27Four decimal numbers separated by dots.
2001:db8:4::27A longer address using hexadecimal characters and colons.
The retailer's value is therefore an IPv4 address. Recognising the format helps validate and research the value, but the format does not reveal who used it.
A device or service may use IPv4, IPv6 or both. Two different-looking addresses do not automatically mean two different devices or people were involved, because one connection can use both address formats.
Go deeper into address formats
Public and private addresses answer different questions¶
A device inside a home or workplace commonly uses a private IP address. The same private ranges can be reused in millions of unrelated local networks, so a value such as 192.168.1.24 cannot normally identify an internet subscriber on its own. In theory, a device in every house on a street could use that same address without any conflict, because each use is contained inside its own local network.
When the device communicates with an internet service, its router normally uses Network Address Translation (NAT) to represent that local traffic using a public IP address. The private address stays meaningful only inside the home or workplace network; the public address is the one normally presented to the internet service. This is why a retailer's address may identify the household or organisation's internet connection without identifying the particular device inside it.
192.168.1.24198.51.100.27Why one address does not mean one device - or one person¶
Several phones, computers and other devices can use one public address through the same router. The address alone cannot select the device or person involved.
Carrier-Grade NAT can place several customers behind one public IPv4 address. An IP address and time may therefore be insufficient to select one customer.
A provider may reallocate an address, and a phone may change address between Wi-Fi and mobile data. The holder now may not be the holder at the event time.
A VPN, proxy or Tor exit can become the source visible to the destination service. The address may lead to that intermediary rather than the user's ordinary connection.
In a shared-address system, the public IP address and timestamp may not be enough to distinguish one customer's connection. The source port and protocol should also be preserved whenever the recording system has them, because the provider may need those fields to separate simultaneous users of the same address. Whether an address is static or dynamic matters for the same reason: it affects what the provider must match at the event time.
The practical consequence
One public IP address can represent several devices - and sometimes several customers. One device can also use several IP addresses over time. This is why an IP match is a connection lead, not proof of a person or device.
The observation point controls what is visible¶
A system records the address visible from its own position in the connection path. That address might be associated with:
- home or business broadband;
- a mobile network;
- workplace, hotel or public Wi-Fi;
- a server or hosting service;
- shared provider infrastructure; or
- an intermediary such as a VPN, proxy or Tor exit.
These possibilities matter because the same user's activity can produce different visible addresses at different points in the route, and the final service may see an intermediary rather than the user's earlier connection.
If traffic passes through a VPN, the online service normally sees the VPN exit address because the VPN makes the onward connection. If a retailer receives traffic through a reverse proxy, its records must preserve the correct original source field because the immediate network connection may otherwise appear to come from the proxy. The recorded address remains potentially useful, but it may identify a point in the route rather than the user's ordinary connection.
Choose the explanation that matches the record
What an IP address can contribute¶
- identify the likely network or record holder;
- match an address to a subscriber connection at a relevant time;
- connect or distinguish recorded events;
- identify records requiring preservation; and
- test an account of how a device connected.
Each use advances the enquiry by identifying a record to obtain, a comparison to make or an explanation to test.
- the identity of the user;
- a unique physical device;
- an exact physical location; or
- responsibility for the recorded activity.
Those conclusions need other records because an IP address describes a network connection, not the person or device behind every event using it.
The result should therefore be framed as narrowly as the evidence allows: an IP address may direct the next enquiry, while subscriber, account, device and other evidence test who or what was actually involved.
Read the address as part of the event¶
- Preserve
Keep the complete event, including any recorded source port and protocol, because separating the address from its account, request and activity removes the relationships that can be checked.
- Fix the time
Retain the full timestamp, time zone and every precision the system records - milliseconds or microseconds where available - because shared addresses can be reassigned or used by different connections within the same second.
- Understand the field
Establish what the recording system meant by source, client or remote address, because differently named fields may describe different points in the connection.
- Find the observation point
Identify any translation, proxy, VPN or other intermediary, because it may be the source the recording system saw.
- Identify the next holder
Start with an [IP registration lookup](../ip-034/) - for example through RIPE, ARIN or a WHOIS service - to identify the organisation responsible for the address block and frame the next proportionate enquiry. This identifies a likely record holder or route to the holder; it does not identify the subscriber or user.
- Keep the conclusion narrow
Say what the resulting record establishes - and what remains unresolved - because a connection match does not by itself identify the user or prove responsibility.
The point to remember¶
Continue from another perspective
Follow the investigation
Follow a separate offender-perspective case
Go deeper