IVR (Interactive Voice Response)

Interactive Voice Response systems let callers interact with a service by speaking commands or pressing DTMF keys. IVRs front contact centres, banking lines, and operator self-service. From a security perspective, poorly designed IVRs leak information through speech recognition errors and are a common target of social-engineering attacks against authentication.

Categories: Security ControlsThreats and AttacksEncryption and Cryptography

IVR in context

Security controls span signaling firewalls (SS7/Diameter/GTP screening), transport encryption (IPsec, TLS, PRINS), identity and access on OSS/BSS, and monitoring at both packet and log level. Controls are audited against GSMA FS.11/FS.19/FS.20/FS.36.

Telecom threats range from opportunistic SMS phishing and SIM swap to nation-state grade location tracking. The common thread is that most attacks exploit the inherited trust model of legacy signaling protocols.

To place IVR in the wider telecom-security picture, review Slice Security, A5/2, AP, BGP Hijacking, Cipher Downgrade Attack and EDR: each entry cross-references back to this page so you can walk the topic in either direction.

Related terms

Related topic hubs

  • Diameter Attacks S6a IDR/PUR/CLR abuse, subscriber tracking, LTE signaling attacks.

More from the TelcoSec Glossary

Browse the full TelcoSec Glossary, the Ultimate Guide to Mobile Network Security, or the P1 Arsenal of telecom-security tools.