Misclassification in voice over internet protocol honeypots: distinguishing genuine calls from malicious traffic
摘要
Voice over Internet Protocol (VoIP) security has advanced in detecting attack patterns and signaling behaviors, but most efforts focus on identifying malicious traffic rather than avoiding misclassification of legitimate calls. Traditional voice activity detection (VAD) systems rely on fixed thresholds to distinguish speech from silence, often misinterpreting natural pauses as threats, leading to high false positives and disruptions in essential services such as business, finance, and healthcare. VAD-based methods require constant threshold adjustments, which makes them unreliable in real-world scenarios. This study proposes an adaptive VoIP call classification model using a hidden Markov model (HMM) to address these limitations. The HMM-based model improves accuracy, reduces false positives, and adapts dynamically to changing call conditions without the need for manual tuning. Unlike VAD, it effectively handles call anomalies and adjusts to silence sensitivity in real time. By improving the accuracy and adaptability of threat detection, this approach improves VoIP security and ensures uninterrupted communication.