{"id":2376,"date":"2026-09-20T08:00:00","date_gmt":"2026-09-20T07:00:00","guid":{"rendered":"https:\/\/ic-services.io\/?p=2376"},"modified":"2026-09-17T18:07:45","modified_gmt":"2026-09-17T17:07:45","slug":"provider-side-dpi-enriched-li-handover","status":"publish","type":"post","link":"https:\/\/ic-services.io\/it\/resources\/blog\/provider-side-dpi-enriched-li-handover\/","title":{"rendered":"Ispezione approfondita dei pacchetti presso l\u2019ISP: fornitura di dati LI arricchiti alle forze dell\u2019ordine"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>Deep packet inspection for lawful interception<\/strong> is usually associated with the law enforcement side: the agency receives raw IP packets and analyses them in its monitoring facility. More and more network operators and agencies, however, are asking whether part of this work can be done <strong>at the provider<\/strong>, close to the traffic. In this model, the provider extracts and enriches metadata at the point of interception and hands it over together with the full copy of the communication.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Done right, provider-side DPI speeds up investigations, can reduce data volumes where an order limits the scope, and gives agencies context they could not reconstruct themselves. Done wrong, it breaks evidence rules or exceeds the legal mandate. This article explains the architecture, what can be extracted, how enriched data is delivered, and where the boundaries are.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"key-takeaways\">Key Takeaways<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Provider-side DPI <strong>complements<\/strong> the full copy of the communication. It never replaces it, unless the order and national rules explicitly allow a reduced scope.<\/li>\n\n\n<li>The provider has <strong>context the agency lacks<\/strong>: subscriber and line identity, NAT mappings, cell and location data, device identifiers and precise session timing.<\/li>\n\n\n<li>Typical extracted metadata includes <strong>flow records, DNS, SNI, TLS fingerprints (JA4), application classification, VoIP signalling and activity types<\/strong>.<\/li>\n\n\n<li>Enriched data must be delivered in an <strong>agreed, documented format<\/strong>, for example as additional IRI records where the national specification allows it, or as a clearly labelled analytics stream.<\/li>\n\n\n<li>Everything must be <strong>target-specific, reproducible, documented in the acceptance concept<\/strong> and strictly separated from commercial DPI.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"why-do-deep-packet-inspection-on-the-provider-side\">Why Do Deep Packet Inspection on the Provider Side?<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead>\n<tr>\n<th>Driver<\/th>\n<th>Benefit for the agency<\/th>\n<th>Benefit for the provider<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Bandwidth growth (multi-Gigabit FTTH, 5G)<\/td>\n<td>Metadata is available immediately, even if the full copy takes time to process<\/td>\n<td>Less pressure on handover links where scope limits apply<\/td>\n<\/tr>\n<tr>\n<td>Encrypted traffic<\/td>\n<td>Pre-classified sessions and fingerprints<\/td>\n<td>Reuse of existing DPI expertise<\/td>\n<\/tr>\n<tr>\n<td>Network context<\/td>\n<td>Subscriber, NAT, cell and device data attached to each flow<\/td>\n<td>Fewer follow-up requests for basic context, where the order allows<\/td>\n<\/tr>\n<tr>\n<td>Time-critical cases<\/td>\n<td>Near real-time alerts on activity patterns<\/td>\n<td>Clearly defined, automated process<\/td>\n<\/tr>\n<tr>\n<td>Complex access models<\/td>\n<td>Correct attribution behind CGNAT and in wholesale setups<\/td>\n<td>Fewer disputes about incomplete intercepts<\/td>\n<\/tr>\n<\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"where-the-law-draws-the-line\">Where the Law Draws the Line<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Before designing anything, providers must understand their legal position:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>The full copy comes first.<\/strong> In most European jurisdictions, including Germany, the provider must deliver a <strong>complete, unaltered copy<\/strong> of the target&#8217;s telecommunications. Enrichment is an addition, and filtering is allowed only where the order limits the scope.<\/li>\n\n\n<li><strong>No analysis beyond the order.<\/strong> Provider-side DPI may only process traffic of the <strong>ordered target<\/strong> and only for the purpose of the interception. Bulk or untargeted analysis is not permitted.<\/li>\n\n\n<li><strong>Separation from commercial DPI.<\/strong> The EU Open Internet Regulation (EU) 2015\/2120 restricts DPI for traffic management, but allows measures needed to comply with Union or national law. LI processing must therefore run in a separate, access-controlled environment and must never feed commercial systems.<\/li>\n\n\n<li><strong>Confidentiality.<\/strong> Staff and systems are bound by telecommunications secrecy, and the subscriber must not notice the measure.<\/li>\n\n\n<li><strong>Acceptance.<\/strong> In Germany, anything the provider delivers must be part of the technical concept accepted by the BNetzA. National specifications such as the TR TK\u00dcV define what may be delivered and how.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"reference-architecture\">Reference Architecture<\/h2>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Traffic access via X3<\/strong>: carrier-grade BNG\/BRAS for PPPoE and IPoE access, and PE or core routers for fixed-IP lines, deliver the target&#8217;s traffic natively via X3 (ETSI TS 103 221-2). ICS integrates the LI functions of Huawei, Cisco, Juniper and other leading vendors. Optical TAPs or virtual mirror ports are only a fallback where X3 is not available.<\/li>\n\n\n<li><strong>Target triggering<\/strong>: the LIMS\/ADMF activates the target, and session events from RADIUS\/Diameter, DHCP or the packet gateway tell the DPI node which IP addresses and prefixes currently belong to the target.<\/li>\n\n\n<li><strong>Target-specific deep packet inspection node<\/strong>: the node processes only the X3 stream of the ordered target. Flows are reassembled, protocols identified and metadata extracted, using high-performance packet processing (for example DPDK or FPGA-based NICs) at 10\/40\/100 Gbit\/s.<\/li>\n\n\n<li><strong>Enrichment<\/strong>: each flow is tagged with the LIID, subscriber and line identifiers, the NAT mapping (public IP and port block), cell ID or location, and the IMEI where available.<\/li>\n\n\n<li><strong>Mediation and delivery<\/strong>: the full copy is delivered as CC via HI3, for example according to ETSI TS 102 232-3 or -7, and the enriched metadata is delivered via HI2 or an agreed analytics channel.<\/li>\n\n\n<li><strong>Audit and retention<\/strong>: DPI outputs are kept only as long as delivery requires, and every configuration and signature version is logged.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">See <a href=\"https:\/\/ic-services.io\/resources\/blog\/x1-x2-x3-interfaces-5g-li\/\">X1\/X2\/X3 interfaces<\/a> and <a href=\"https:\/\/ic-services.io\/resources\/blog\/mediation-function-lawful-interception\/\">how a mediation function works<\/a> for the underlying interfaces.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"what-can-be-extracted-and-enriched\">What Can Be Extracted and Enriched?<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead>\n<tr>\n<th>Metadata<\/th>\n<th>Source<\/th>\n<th>Value for the investigation<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Flow records (5-tuple, start\/end, bytes, packets)<\/td>\n<td>Packet headers<\/td>\n<td>Complete activity overview<\/td>\n<\/tr>\n<tr>\n<td>DNS queries and responses<\/td>\n<td>Unencrypted DNS<\/td>\n<td>Services and domains used<\/td>\n<\/tr>\n<tr>\n<td>TLS SNI, ALPN, JA4 \/ JA4S fingerprints (note the FoxIO licence terms for JA4S)<\/td>\n<td>TLS \/ QUIC handshakes<\/td>\n<td>Application and device identification<\/td>\n<\/tr>\n<tr>\n<td>Application classification<\/td>\n<td>DPI signatures and behaviour<\/td>\n<td>Messenger, VoIP, streaming, VPN, Tor<\/td>\n<\/tr>\n<tr>\n<td>Activity type<\/td>\n<td>Packet size and timing patterns<\/td>\n<td>Message vs call vs file transfer<\/td>\n<\/tr>\n<tr>\n<td>VoIP signalling (SIP, RTP parameters)<\/td>\n<td>Unencrypted VoIP<\/td>\n<td>Third-party VoIP calls with participants and duration<\/td>\n<\/tr>\n<tr>\n<td>HTTP host and user agent<\/td>\n<td>Unencrypted HTTP<\/td>\n<td>Services and client software<\/td>\n<\/tr>\n<tr>\n<td>NAT mapping<\/td>\n<td>CGNAT logs<\/td>\n<td>Link between public IP and port and the target<\/td>\n<\/tr>\n<tr>\n<td>Location and device<\/td>\n<td>Cell ID, IMEI, access line<\/td>\n<td>Where and with which device an activity happened<\/td>\n<\/tr>\n<\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The encryption rule applies here as well: the provider removes only the encryption it applied itself. End-to-end encrypted content remains encrypted, and the metadata above is extracted without decrypting it.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"handing-over-enriched-data\">Handing Over Enriched Data<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">There is no single, universal ETSI record type for &#8220;DPI results&#8221;. In practice, three models are used:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Additional IRI records<\/strong>: extracted events (for example a detected VoIP call or an application session) are sent via HI2, using standard fields where possible and national or agreed extensions where necessary.<\/li>\n\n\n<li><strong>A separate analytics stream<\/strong>: structured records (for example IPFIX-like flow records or JSON) are delivered over a secured channel, clearly labelled and correlated with the LIID and the CC.<\/li>\n\n\n<li><strong>Service-level records<\/strong>: in some jurisdictions, and only where explicitly required, the provider delivers events at service level, similar to the service-specific parts of ETSI TS 102 232 that messaging and multimedia providers use for their own services.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Whatever the model, the format must be <strong>documented, versioned and agreed<\/strong> with the receiving agencies and the regulator, and the agency must always be able to verify enriched data against the full copy.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"evidence-quality-make-enrichment-reproducible\">Evidence Quality: Make Enrichment Reproducible<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Record the <strong>DPI engine and signature version<\/strong> used for every result.<\/li>\n\n\n<li>Use <strong>synchronised, high-precision timestamps<\/strong> so that metadata aligns with the CC and HI2 records.<\/li>\n\n\n<li>Provide <strong>confidence indicators<\/strong> for behavioural classifications.<\/li>\n\n\n<li>Keep a <strong>complete audit trail<\/strong> of target activation, configuration changes and deliveries.<\/li>\n\n\n<li>Test regularly with <strong>reference traffic<\/strong> to detect regressions after signature updates.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"implementation-checklist-for-providers\">Implementation Checklist for Providers<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Legal assessment: what the national framework allows, and what the orders typically cover<\/li>\n\n\n<li>Enrichment scope and delivery format agreed with the agencies and included in the acceptance concept<\/li>\n\n\n<li>Target-specific activation only, driven by the LIMS\/ADMF<\/li>\n\n\n<li>Hardware-accelerated DPI sized for peak subscriber rates<\/li>\n\n\n<li>Integration with AAA, DHCP, CGNAT logs, packet core and location data<\/li>\n\n\n<li>Strict separation from commercial DPI and traffic management<\/li>\n\n\n<li>Versioning, reference testing and audit logging<\/li>\n\n\n<li>Resilient delivery with buffering and monitoring<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"how-ics-helps-with-provider-side-deep-packet-inspection\">How ICS Helps with Provider-Side Deep Packet Inspection<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">ICS International Carrier Services has <strong>more than 20 years of experience in telecommunications, lawful interception and compliance<\/strong> and holds <strong>multiple BNetzA acceptances<\/strong>. We integrate network elements via X1\/X2\/X3 and operate mediation for providers today, so we know both the network and the receiving side.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Architecture and legal-technical design<\/strong> of provider-side DPI (see <a href=\"https:\/\/ic-services.io\/solutions\/deep-packet-inspection\/dpi-for-network-operators\/\">DPI for Network Operators<\/a>) that fits your national framework and your acceptance concept.<\/li>\n\n\n<li><strong>Target-triggered DPI and enrichment pipelines<\/strong> integrated with RADIUS\/Diameter, CGNAT logging and packet core events.<\/li>\n\n\n<li><strong>X3 integration<\/strong> with BNG\/BRAS and core routers from Huawei, Cisco, Juniper and other leading vendors, plus passive probes or cloud mirroring where X3 is not available.<\/li>\n\n\n<li><strong>Mediation and ETSI handover<\/strong> through our <a href=\"https:\/\/ic-services.io\/products\/software-solutions\/li-mediation-platform\/\">LI Mediation Platform<\/a> and <a href=\"https:\/\/ic-services.io\/products\/software-solutions\/lawful-interception-management-system\/\">LIMS<\/a>.<\/li>\n\n\n<li><strong>Managed operations<\/strong> around the clock. See <a href=\"https:\/\/ic-services.io\/services\/managed-li-operations\/\">Managed LI Operations<\/a>.<\/li>\n\n\n<li><strong>Custom development<\/strong> of extractors, classifiers and delivery formats. See <a href=\"https:\/\/ic-services.io\/services\/integration-custom-development\/\">Integration &amp; Custom Development<\/a>.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/ic-services.io\/contact\/\">Get in touch with ICS<\/a> to discuss whether provider-side enrichment makes sense for your network.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"frequently-asked-questions\">Frequently Asked Questions<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"is-deep-packet-inspection-allowed-for-lawful-interception\">Is deep packet inspection allowed for lawful interception?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Yes, when it is limited to the traffic of the ordered target, serves the purpose of the interception order and is covered by the national technical specifications and the provider&#8217;s accepted concept. Untargeted or commercial use of LI data is not allowed.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"does-provider-side-dpi-replace-the-full-copy-of-the-communication\">Does provider-side DPI replace the full copy of the communication?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">No. In most jurisdictions the provider must deliver a complete, unaltered copy of the target&#8217;s communication. DPI-based metadata is delivered in addition to it, unless the order explicitly limits the scope.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"can-an-isp-decrypt-a-targets-https-or-messenger-traffic\">Can an ISP decrypt a target&#8217;s HTTPS or messenger traffic?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">No. The provider only removes encryption it applied itself in its own network. End-to-end or application-level encryption remains intact. DPI works on unencrypted headers, handshakes and traffic patterns.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"how-is-dpi-metadata-delivered-to-law-enforcement\">How is DPI metadata delivered to law enforcement?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Typically as additional IRI records via HI2, or as a separate, secured analytics stream correlated with the LIID. The format must be documented and agreed with the agencies and the regulator.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"what-is-the-difference-between-provider-side-and-lea-side-dpi\">What is the difference between provider-side and LEA-side DPI?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">LEA-side DPI analyses the delivered traffic in the monitoring facility. Provider-side DPI runs at the point of interception, where it can add network context such as subscriber identity, NAT mappings and location, and deliver results in near real time.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"related-articles\">Related Articles<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/ic-services.io\/resources\/blog\/mediation-function-lawful-interception\/\">How a Mediation Function Works: The Bridge Between Your Network and Law Enforcement<\/a><\/li>\n\n\n<li><a href=\"https:\/\/ic-services.io\/resources\/blog\/encrypted-dns-doh-dot-li-impact\/\">Encrypted DNS (DoH\/DoT) and Its Impact on Lawful Interception Capabilities<\/a><\/li>\n\n\n<li><a href=\"https:\/\/ic-services.io\/resources\/blog\/network-slicing-5g-lawful-interception\/\">Network Slicing in 5G SA: How It Complicates (and Can Simplify) LI Targeting<\/a><\/li>\n\n\n<li><a href=\"https:\/\/ic-services.io\/resources\/blog\/ai-lawful-interception-automation\/\">AI-Assisted LI: What Automation Means for Operators and Law Enforcement Workflows<\/a><\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"external-resources\">External Resources<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/www.etsi.org\/technologies\/lawful-interception\" rel=\"noopener noreferrer\" target=\"_blank\">ETSI Lawful Interception Standards (TC LI)<\/a><\/li>\n\n\n<li><a href=\"https:\/\/eur-lex.europa.eu\/eli\/reg\/2015\/2120\/oj\" rel=\"noopener noreferrer\" target=\"_blank\">Regulation (EU) 2015\/2120 (Open Internet Access)<\/a><\/li>\n<\/ul>\n\n\n\n<script type=\"application\/ld+json\">{\"@context\": \"https:\/\/schema.org\", \"@type\": \"FAQPage\", \"mainEntity\": [{\"@type\": \"Question\", \"name\": \"Is deep packet inspection allowed for lawful interception?\", \"acceptedAnswer\": {\"@type\": \"Answer\", \"text\": \"Yes, when it is limited to the traffic of the ordered target, serves the purpose of the interception order and is covered by the national technical specifications and the provider's accepted concept. Untargeted or commercial use of LI data is not allowed.\"}}, {\"@type\": \"Question\", \"name\": \"Does provider-side DPI replace the full copy of the communication?\", \"acceptedAnswer\": {\"@type\": \"Answer\", \"text\": \"No. In most jurisdictions the provider must deliver a complete, unaltered copy of the target's communication. DPI-based metadata is delivered in addition to it, unless the order explicitly limits the scope.\"}}, {\"@type\": \"Question\", \"name\": \"Can an ISP decrypt a target's HTTPS or messenger traffic?\", \"acceptedAnswer\": {\"@type\": \"Answer\", \"text\": \"No. The provider only removes encryption it applied itself in its own network. End-to-end or application-level encryption remains intact. DPI works on unencrypted headers, handshakes and traffic patterns.\"}}, {\"@type\": \"Question\", \"name\": \"How is DPI metadata delivered to law enforcement?\", \"acceptedAnswer\": {\"@type\": \"Answer\", \"text\": \"Typically as additional IRI records via HI2, or as a separate, secured analytics stream correlated with the LIID. The format must be documented and agreed with the agencies and the regulator.\"}}, {\"@type\": \"Question\", \"name\": \"What is the difference between provider-side and LEA-side DPI?\", \"acceptedAnswer\": {\"@type\": \"Answer\", \"text\": \"LEA-side DPI analyses the delivered traffic in the monitoring facility. Provider-side DPI runs at the point of interception, where it can add network context such as subscriber identity, NAT mappings and location, and deliver results in near real time.\"}}]}<\/script>\n","protected":false},"excerpt":{"rendered":"<p>L'ispezione approfondita dei pacchetti da parte del provider pu\u00f2 trasformare le intercettazioni IP grezze in metadati arricchiti e pronti per l'analisi a disposizione delle forze dell'ordine. Scopri l'architettura, quali dati \u00e8 possibile estrarre, come vengono trasmessi e quali sono i limiti legali.<\/p>","protected":false},"author":7,"featured_media":2580,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"_uag_custom_page_level_css":"","site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[10],"tags":[17,48,26,51,21,55,50],"class_list":["post-2376","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technical-standards-architecture","tag-compliance","tag-deep-packet-inspection","tag-etsi","tag-isp","tag-lawful-interception","tag-metadata","tag-traffic-analytics"],"uagb_featured_image_src":{"full":["https:\/\/ic-services.io\/wp-content\/uploads\/2026\/09\/provider-side-dpi-x3-enriched-metadata.jpg",1600,900,false],"thumbnail":["https:\/\/ic-services.io\/wp-content\/uploads\/2026\/09\/provider-side-dpi-x3-enriched-metadata-150x150.jpg",150,150,true],"medium":["https:\/\/ic-services.io\/wp-content\/uploads\/2026\/09\/provider-side-dpi-x3-enriched-metadata-300x169.jpg",300,169,true],"medium_large":["https:\/\/ic-services.io\/wp-content\/uploads\/2026\/09\/provider-side-dpi-x3-enriched-metadata-768x432.jpg",768,432,true],"large":["https:\/\/ic-services.io\/wp-content\/uploads\/2026\/09\/provider-side-dpi-x3-enriched-metadata-1024x576.jpg",1024,576,true],"1536x1536":["https:\/\/ic-services.io\/wp-content\/uploads\/2026\/09\/provider-side-dpi-x3-enriched-metadata-1536x864.jpg",1536,864,true],"2048x2048":["https:\/\/ic-services.io\/wp-content\/uploads\/2026\/09\/provider-side-dpi-x3-enriched-metadata.jpg",1600,900,false],"trp-custom-language-flag":["https:\/\/ic-services.io\/wp-content\/uploads\/2026\/09\/provider-side-dpi-x3-enriched-metadata-18x10.jpg",18,10,true]},"uagb_author_info":{"display_name":"David Son","author_link":"https:\/\/ic-services.io\/it\/author\/david\/"},"uagb_comment_info":0,"uagb_excerpt":"Deep packet inspection at the provider can turn raw IP intercepts into enriched, analysis-ready metadata for law enforcement. Learn the architecture, what can be extracted, how it is handed over, and where the legal limits are.","_links":{"self":[{"href":"https:\/\/ic-services.io\/it\/wp-json\/wp\/v2\/posts\/2376","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ic-services.io\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ic-services.io\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ic-services.io\/it\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/ic-services.io\/it\/wp-json\/wp\/v2\/comments?post=2376"}],"version-history":[{"count":3,"href":"https:\/\/ic-services.io\/it\/wp-json\/wp\/v2\/posts\/2376\/revisions"}],"predecessor-version":[{"id":2608,"href":"https:\/\/ic-services.io\/it\/wp-json\/wp\/v2\/posts\/2376\/revisions\/2608"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ic-services.io\/it\/wp-json\/wp\/v2\/media\/2580"}],"wp:attachment":[{"href":"https:\/\/ic-services.io\/it\/wp-json\/wp\/v2\/media?parent=2376"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ic-services.io\/it\/wp-json\/wp\/v2\/categories?post=2376"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ic-services.io\/it\/wp-json\/wp\/v2\/tags?post=2376"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}