IRI (Intercept Related Information)

Also known as: Intercept-Related Information

Intercept Related Information is the metadata component of a lawful intercept: signalling events such as call setup, release, SMS submission, registration, location updates and session start/stop, together with target and correlation identifiers. IRI is delivered over the ETSI X2 interface and is produced whether or not Content of Communication is authorised.

Categories: Threats and AttacksProtocols and Standards

IRI in context

Telecom threats range from opportunistic SMS phishing and SIM swap to nation-state grade location tracking. The common thread is that most attacks exploit the inherited trust model of legacy signaling protocols.

Telecom security is written into standards from 3GPP, GSMA, ETSI, IETF and ITU-T. Understanding which body owns which specification, and how they interlock, is essential for both design and audit work.

To place IRI in the wider telecom-security picture, review ETSI TS 103 221, X2 (LI), X3 (LI), CC (LI), MDF2 and HI2: each entry cross-references back to this page so you can walk the topic in either direction.

Related terms

Related topic hubs

  • Diameter Attacks S6a IDR/PUR/CLR abuse, subscriber tracking, LTE signaling attacks.
  • SMS Firewall SMS spam, phishing, A2P bypass and MAP-layer SMS filtering.
  • Signaling Firewall Unified SS7/Diameter/GTP/SMS signaling firewall framework.

More from the TelcoSec Glossary

Browse the full TelcoSec Glossary, the Ultimate Guide to Mobile Network Security, or the P1 Arsenal of telecom-security tools.