In short
Send Routing Information for Short Message (SRI-SM) is a MAP procedure used during SMS routing, in which the sending SMSC asks the recipient's HLR where that subscriber currently is. Monitoring SRI-SM behaviour helps operators identify abnormal routing requests, unauthorised network activity, information exposure and certain forms of messaging abuse.
What the query returns
Before delivering a mobile-terminated message, the sending SMSC issues SRI-SM to the destination subscriber's HLR. A normal response contains the subscriber's IMSI and the address of the serving MSC or SGSN — everything needed to deliver the message, and rather more than a stranger should learn about a subscriber.
That is the security tension at the heart of this procedure: the information required for delivery is also the information required to locate, track or impersonate a subscriber.
Abuse patterns visible in SRI-SM
Because every genuine MT delivery is preceded by an SRI-SM, the ratio and shape of these queries is highly diagnostic:
- High SRI-SM volumes with few or no subsequent delivery attempts, suggesting information harvesting rather than messaging
- Sequential queries walking through an MSISDN range, indicating enumeration
- Queries from Global Titles with no messaging relationship with the operator
- SRI-SM results that do not match the path the message subsequently took, an indicator of route manipulation
- Repeated queries for the same subscriber from unrelated sources in a short window
How home routing changes the picture
With SMS home routing, the HLR does not hand out the real serving-node address. It answers with the address of the home SMSC or firewall, usually together with a correlation identifier. The originating network then delivers the message into the home network, which screens it and performs the real delivery itself.
This has two effects that matter here. Subscriber information stops leaking to every network that asks, and inbound international and roaming traffic is forced through a point where policy can be applied. Attempts to avoid that path — delivering without a preceding SRI-SM, or ignoring the returned address — are themselves a strong bypass indicator.