try hiccup

Lawful intercept in a VoIP network: where the taps really sit

Short version: in a packet voice network, signalling and media take different paths — so interception has to catch them in different places and then prove they belong together. Signalling is easy: it always crosses the core. Media is the hard part, because it only passes a tappable point if the network makes it do so. That single fact drives most of the engineering.

The two products come from two different places

IRI — the who-called-whom record — falls out of signalling, and every SIP message for a subscriber passes their S-CSCF (or, in a plainer SIP network, the proxy/registrar). So the IRI point of interception is simply the box already reading the signalling, emitting an event per REGISTER, INVITE, answer and release on X2.

Content is different. RTP flows wherever SDP pointed it, and a network that allows direct media — endpoint to endpoint, the ideal for latency — has nothing in the media path to copy packets from. Content interception therefore depends on a media-plane node the call can be held at: the SBC or IMS access gateway at the edge, the transition gateway at an interconnect, or the media gateway at PSTN breakout. For a warranted target the network quietly ensures media anchors at such a node, which then mirrors the streams onto X3. Done correctly this is indistinguishable from ordinary anchoring — operators anchor media all the time for NAT and topology reasons anyway.

What encryption changes — and what it does not

Correlation: proving the streams belong to the warrant

A delivered call is only evidence if the pieces bind together. Each IRI event and each CC stream carries the warrant's LIID plus a correlation identifier generated at interception time; the mediation layer uses them to present "this audio goes with this call record". Inside IMS, the network's own correlation key — the icid-value in P-Charging-Vector — often seeds that binding, which is a nice reminder that LI mostly reuses the machinery the network already has for billing.

Coexisting with SIP without breaking it

The undetectability requirement has a practical engineering translation: the tap must be a copy, never an inline hop. No extra Via, no Record-Route entry, no added latency a target could measure, no different behaviour when the X3 link is down (delivery buffers or fails silently — the call must proceed regardless). The POI mirrors packets and emits events; the call's own state machine never learns about it. In IMS the intercept logic is embedded in nodes that were already in the path, so nothing about the path changes at all.

What this means for the engineer reading traces

hiccup analyses the captures you take on your own network — pairs legs, reads SDP against the media that actually flowed, and finds where the audio went missing. Self-hosted, free for individual users.

upload a trace