Mediation Device (Lawful Interception)

A Mediation Device is the network element that sits between Intercept Access Points and the law-enforcement monitoring facility in a lawful-interception architecture. It aggregates intercepted traffic and metadata, normalises it to the standard handover formats (ETSI TS 102 232, TS 103 221), and applies access controls, audit, and delivery to the requesting agency.

Categories: Security ControlsThreats and AttacksProtocols and Standards

Mediation Device (Lawful Interception) in context

Security controls span signaling firewalls (SS7/Diameter/GTP screening), transport encryption (IPsec, TLS, PRINS), identity and access on OSS/BSS, and monitoring at both packet and log level. Controls are audited against GSMA FS.11/FS.19/FS.20/FS.36.

Telecom threats range from opportunistic SMS phishing and SIM swap to nation-state grade location tracking. The common thread is that most attacks exploit the inherited trust model of legacy signaling protocols.

To place Mediation Device (Lawful Interception) in the wider telecom-security picture, review Cipher Downgrade Attack, HI2, OAM, RPKI, SCADA and UEA — each entry cross-references back to this page so you can walk the topic in either direction.

Related terms

More from the TelcoSec Glossary

Browse the full TelcoSec Glossary, the Ultimate Guide to Mobile Network Security, or the P1 Arsenal of telecom-security tools.