NetBot-AI: A Deep Reinforcement Learning Framework for Real-Time Threat Detection and Mitigation in VoIP Networks Using Call Detail Record Analytics

Authors

  • S. M. Ekolama Niger Delta University
  • W. Minah-Eeba

Keywords:

Anomaly detection, Call detail records, Deep reinforcement learning, Network security, Voice over IP

Abstract

The rapid expansion of Voice over IP (VoIP) has enabled scalable communication solutions; however, it has also introduced significant security vulnerabilities, particularly in developing regions that rely on legacy infrastructure. Traditional intrusion detection systems remain largely reactive, struggling to mitigate evolving threats such as Session Initiation Protocol (SIP) flooding and toll fraud within dynamic network environments. To address these limitations, this study proposes NetBot-AI, an artificial intelligence-driven framework designed for real-time threat detection and adaptive mitigation in VoIP networks. The methodology integrates Call Detail Record (CDR) analytics with a Deep Q-Network (DQN), enhanced by a novel dynamic scaling mechanism termed the Ekolama Constant (Ek). Evaluated on a consolidated dataset comprising over ten million real-world and NS-3 simulated call records, the proposed model achieved a binary classification accuracy of 98% and a multi-class accuracy of 95%, maintaining a false positive rate below 5%. Furthermore, integrating the Ek accelerated model convergence by 33% and reduced validation loss by 31% relative to conventional loss functions. These findings demonstrate that NetBot-AI offers a robust, scalable, and proactive cybersecurity solution capable of enhancing VoIP resilience across both advanced and resource-constrained telecommunications environments.

References

E. Koivusalo, “Converged Communications: Evolution from Telephony to 5G Mobile Internet,” 1st ed. Hoboken, NJ, USA: Wiley-IEEE Press, 2022.

A. H. Mohseni, A. H. Jahangir, and S. M. Hosseini, “Toward a comprehensive subjective evaluation of VoIP users’ quality of experience (QoE): A case study on Persian language,” Multimedia Tools and Applications, vol. 80, no. 21–23, pp. 31783–31802, 2021.

A. M. Ramly, Z. W. Ng, Y. Khamayseh, C. S. C. Kwan, A. Amphawan, and T.-K. Neo, “Review and enhancement of VoIP security: Identifying vulnerabilities and proposing integrated solutions,” Journal of Telecommunications and the Digital Economy, vol. 12, no. 4, pp. 109–136, Dec. 2024.

M. M. Naeem, I. Hussain, and M. M. S. Missen, “A survey on registration hijacking attack consequences and protection for Session Initiation Protocol (SIP),” Computer Networks, vol. 175, p. 107250, Jul. 2020.

B. I. Bakare and S. M. Ekolama, “Preventing man-in-the-middle (MiTM) attack of GSM calls,” European Journal of Electrical Engineering and Computer Science, vol. 5, no. 4, pp. 63–68, Aug. 2021.

D. Suthar and P. H. Rughani, “A comprehensive study of VoIP security,” in Proceedings. 2020 2nd International Conference Advances in Computing, Communication Control and Networking (ICACCCN), Greater Noida, India, 2020, pp. 812–817.

S. Gupta, “A review on real-time suspicious call detection systems in telecom networks,” Asian Journal of Computer Science Engineering, vol. 10, no. 4, pp. 1–10, Dec. 2025.

M. M. H. Rahman, M. Alnaeem, and A. A. Ibrahim, “Detection of DSCP-based traffic prioritization manipulations and their impact on network performance,” Scientific Reports, vol. 16, p. 10637, 2026.

I. S. A. Soumya, B. B. Foysal, and M. N. F. Sharkar, “Deep residual CNN-attention model with GMM statistical injection: A forensic approach to mitigating dataset bias for zero-day detection in SDN,” Ph.D. dissertation, BRAC University, Dhaka, Bangladesh, 2026.

J. Alom, M. S. Ullah, M. T. Islam, M. Niloy, R. Islam, and S. Firdaus, “Adaptive multi-agent reinforcement learning for intrusion mitigation aligned with smart city,” in Proceedings 2025 IEEE International Conference Quantum Photonics, Artificial Intelligence, and Networking (QPAIN), 2025, pp. 1–6.

O. D. G. Alvarez and G. D. R. Rafael, “VoIP Security Auditing Model Based on COBIT 4.1,” International Journal of Security and Networks, vol. 17, no. 2, p. 63-76, Jun. 2022.

O. S. Younes, “A hybrid deep learning model for detecting DDoS flooding attacks in SIP-based systems,” Computer Networks, vol. 240, p. 110146, Feb. 2024.

F. Cecchinato, L. Vangelista, G. Biondo and M. Franchin, "Anomaly detection using LSTM neural networks: an application to VoIP traffic," 2021 IEEE International Conference on Recent Advances in Systems Science and Engineering (RASSE), Shanghai, China, 2021, pp. 1-7.

V. P. Bijlwan and N. Kumar, “Deep reinforcement learning in software defined networking: A survey, research challenges, and future perspectives,” IEEE Communications Surveys & Tutorials, vol. 28, pp. 4624–4653, 2026.

Y. Li, J. Chen, and J. Yang, “Smart optimization method for safety signs in innovative manufacturing environments integrating industrial field IoT sensors and knowledge graphs,” Sensors, vol. 26, no. 12, p. 3965, 2026.

Snom Service Hub “VoIP - IP Telephony - Snom Service Hub - Snom Confluence,” https://service.snom.com/spaces/wiki/pages/234345678/VoIP+-+IP+Telephony, 2021.

Published

2026-08-27

How to Cite

S. M. Ekolama, & W. Minah-Eeba. (2026). NetBot-AI: A Deep Reinforcement Learning Framework for Real-Time Threat Detection and Mitigation in VoIP Networks Using Call Detail Record Analytics. International Journal of AI and Machine Learning Innovations in Electronics and Communication Technology, 1–17. Retrieved from https://matjournals.net/engineering/index.php/IJAIMLECT/article/view/4045