Telecom Intelligence Guide

What is IPDR?

IPDR full form, meaning, and how IPDR analysis works — plus IPDR vs CDR analysis, IPDR records, and what an IPDR collector does, explained for investigators and telecom analysts.

See the CDR/IPDR Platform → Request Demo

IPDR full form: Internet Protocol Detail Record. It's a session log generated by an ISP or telecom operator that records the IP address, port, timestamps, and data volume for every internet session a subscriber makes — the internet equivalent of a phone call record.

What is IPDR?

IPDR (Internet Protocol Detail Record) is a log entry that an internet service provider or mobile network operator generates every time a subscriber opens, uses, or closes a data/internet session. Where a phone bill itemizes every call you made, an IPDR itemizes every internet session your device initiated — which IP address you were assigned, how long the session lasted, and how much data you used.

IPDRs exist because most subscribers share a small pool of public IP addresses through Network Address Translation (NAT). Without an IPDR, an investigator seeing "this IP address did X at this timestamp" has no way to trace it back to a real subscriber — the IPDR is the record that maps a public IP + port + timestamp combination back to the individual SIM or broadband connection that was using it.

What's inside an IPDR record

IPDR records vary slightly by operator and by service type (broadband, mobile data, Wi-Fi hotspot), but a standard IPDR contains the following fields:

Subscriber IDMobile number or account ID tied to the session
Public IP addressThe IP assigned to the subscriber for that session
Private IP addressInternal IP behind the operator's NAT gateway
Port number / port rangePorts allocated, since many users share one public IP
Session start / stop timeExact timestamps for the internet session
Data volumeBytes uploaded and downloaded during the session
IMEI / IMSIDevice and SIM identifiers tied to the session
Cell/Tower IDLocation of the tower that served the data session

What is IPDR analysis?

IPDR analysis (also called IPDR analytics) is the process of processing bulk IPDR files to answer investigative questions — who was using a given IP address at a given time, what apps or services a subscriber connected to, and how a suspect's online activity correlates with their physical location or phone calls. In practice, IPDR analysis is used for:

  • IP-to-subscriber attribution — mapping an IP address flagged in a cybercrime complaint back to the exact subscriber who held it at that timestamp.
  • Session pattern analysis — identifying unusual data usage, active hours, or session durations that indicate automated or suspicious activity.
  • VPN/proxy detection — spotting sessions that route through anonymizing services based on data volume and endpoint anomalies.
  • Device fingerprinting — linking IMEI/IMSI values across sessions to detect a suspect switching SIMs on the same device.
  • CDR–IPDR correlation — cross-referencing internet sessions with call records to build a single timeline of a subscriber's activity.

Because raw IPDR exports from telecom operators can run into millions of rows per day, IPDR analytics tools are used to ingest, index, and query this data quickly rather than manually filtering spreadsheets.

What is an IPDR collector?

An IPDR collector is the network-side component — hardware or software — deployed by the ISP or telecom operator that captures IPDR events in real time as subscribers open and close internet sessions, timestamps them, and writes them to storage. The collector typically sits close to the operator's NAT/CGNAT gateway or Deep Packet Inspection (DPI) infrastructure, since that's where session and IP-allocation data is generated.

From the collector, IPDR data is either streamed to a lawful-interception system in near real time, or exported in bulk (daily/hourly files) for law enforcement and internal fraud/compliance teams to analyze. The collector's job ends at capture and storage — the actual investigative work happens in a downstream IPDR analysis platform.

Call data record analysis (CDR analysis)

CDR analysis — short for call data record analysis or call detail record analysis — is the equivalent process for voice and SMS metadata rather than internet sessions. A Call Detail Record logs who called whom, when, for how long, and via which cell tower, for every call and text message on a network.

CDR analysis is used to:

  • Map communication networks between suspects (call link analysis)
  • Reconstruct a timeline of a suspect's calls and messages
  • Track physical movement using cell tower handoff sequences
  • Identify co-location — two numbers repeatedly active on the same tower at the same time
  • Detect burner phones and short-lived, single-use numbers

CDR vs IPDR — what's the difference?

CDRIPDR
Full formCall Detail RecordInternet Protocol Detail Record
CapturesVoice calls and SMS metadataInternet / data session metadata
Key fieldsCaller, receiver, duration, tower IDIP address, port, session time, data volume
Used forCommunication mapping, movement trackingOnline activity attribution, cybercrime tracing
Typical requesterTelecom operator (mobile/landline)ISP or mobile data provider

In most serious investigations, CDR and IPDR are analyzed together — a suspect's call activity from CDR is cross-referenced against their internet sessions from IPDR to build one unified timeline of physical and digital activity. This is exactly what the VedOps CDR/IPDR platform automates for law enforcement and telecom forensics teams.

Frequently Asked Questions

What is IPDR?

IPDR stands for Internet Protocol Detail Record — a log of every internet session a subscriber makes, including IP address, port, timestamps, and data volume, generated by an ISP or telecom operator.

What is the full form of IPDR?

The full form of IPDR is Internet Protocol Detail Record, sometimes also called IP Detail Record.

What is IPDR analysis?

IPDR analysis examines IP Detail Records to map internet sessions back to a subscriber, device, or timestamp — used to attribute online activity, detect VPN/proxy use, and correlate sessions with call records.

What is an IPDR collector?

An IPDR collector is the network element deployed by an ISP or operator that captures, timestamps, and stores IP Detail Records before they're exported for analysis or lawful interception.

What is CDR analysis?

CDR analysis (call data record analysis) examines Call Detail Records — caller, receiver, duration, timestamp, tower ID — to map communication networks and reconstruct timelines.

What's the difference between CDR and IPDR?

CDR captures voice call and SMS metadata; IPDR captures internet/data session metadata such as IP address and data volume. Investigators often correlate both together.

Get Started

See IPDR analysis in action.

Book a demo — we'll process a sample IPDR/CDR file and show you a complete analysis in real time.