AI Perimeter Guard & Autonomous Threat Mitigation
Table of Contents
Section titled “Table of Contents”- Overview & Heuristic Engine Architecture
- Business & Operational Significance
- 🎯 User Roles & Key Capabilities
- Visual Interface & Layout
- Threat Scoring Matrix & Event Taxonomies
- Field Reference & Defense Settings
- Kamailio & Kernel Mitigation Pipeline
- Forensic Audit & Event Analysis
- Operational Hardening & Best Practices
- Verification & Diagnostics
- Model Context Protocol (MCP) AI Integration
- Glossary
1. Overview & Heuristic Engine Architecture
Section titled “1. Overview & Heuristic Engine Architecture”In Ring2All SBC, the AI Perimeter Guard provides an autonomous, real-time cyber-defense shield engineered specifically for carrier-grade SIP infrastructure. Unlike conventional network firewalls that only inspect layer 3 and 4 packet headers, the AI Perimeter Guard performs continuous deep packet inspection (DPI), heuristic protocol entropy analysis, and machine-learning threat scoring on incoming SIP signaling.
The system detects distributed extension enumeration, credential stuffing, SIP scanner probes (SIPVicious, Friendly-Scanner, SentryPeer), malformed SIP headers, and high-velocity International Revenue Share Fraud (IRSF) attacks.
┌─────────────────────────────────────────────────────────────┐ │ INCOMING SIP SIGNALING TRAFFIC │ │ (UDP/TCP 5060, TLS 5061, IPv4/IPv6) │ └──────────────────────────────┬──────────────────────────────┘ │ ┌──────────────────────────────▼──────────────────────────────┐ │ KAMAILIO SANITIZATION & EVENT DISPATCH │ │ (siptrace, htable velocity counters, regex inspection) │ └──────────────────────────────┬──────────────────────────────┘ │ ┌──────────────────────────────▼──────────────────────────────┐ │ AI HEURISTIC INFERENCE & THREAT SCORING │ │ • Header Entropy • Scan Clustering • Toll Shield │ │ • User-Agent Hash • Anomaly Scoring • Geo Matching │ └──────────────────────────────┬──────────────────────────────┘ │ ┌───────────────────────┴───────────────────────┐ ▼ (Score >= 80) ▼ (Score 50-79) ┌──────────────────────────────┐ ┌──────────────────────────────┐ │ AUTONOMOUS BANNING │ │ CHALLENGE & RATE-LIMIT │ ├──────────────────────────────┤ ├──────────────────────────────┤ │ • Kamailio htable auto-block │ │ • SIP 407 Proxy Auth enforce │ │ • Kernel nftables rule drop │ │ • Tighten CPS in Pike htable │ │ • SecOps webhook/email alert │ │ • Forensic trace logging │ └──────────────────────────────┘ └──────────────────────────────┘When threat thresholds are breached, mitigation occurs at wire speed: offending IPs are instantly committed to Kamailio memory hash tables (htable:ipban) and synchronized down to Linux kernel packet filters (nftables / ip_bans).
2. Business & Operational Significance
Section titled “2. Business & Operational Significance”- Autonomous IRSF & Toll Fraud Shield: Proactively detects burst outbound calling sequences toward high-risk international prefixes (PRN), neutralizing account takeovers before carriers incur catastrophic interconnect charges.
- Elimination of SIP Scanner Noise: Automatically squelches automated botnets (e.g.,
sipvicious,sunday,friendly-scanner) before their authentication attempts exhaust Kamailio worker processes or database connection pools. - Microsecond Mitigation Latency: Enforces blocking rules in memory via Kamailio shared hash tables and kernel
nftablessets, avoiding CPU-intensive database round trips during active distributed denial of service (DDoS) events. - Self-Healing Adaptive Defense: Maintains dynamic IP forensic timelines with configurable ban durations, automatically expelling transient offenders while maintaining strict audit trails for regulatory reporting.
3. 🎯 User Roles & Key Capabilities
Section titled “3. 🎯 User Roles & Key Capabilities”| Role | Primary Use Case | Key Capabilities |
|---|---|---|
| SecOps & Security Lead | Perimeter Defense & Threat Hunting | Configure autonomous ban thresholds, review threat scoring weights, inspect forensic packet captures, and manage global whitelists. |
| SBC Administrator | Operational Shield Monitoring | Monitor real-time attack origin maps, observe top threat vectors, trigger manual IP unbans, and adjust notification webhooks. |
| Carrier Interconnect Engineer | Fraud Mitigation Oversight | Analyze IRSF threat telemetry, verify destination pattern heuristics, and safeguard wholesale trunk capacity. |
| Compliance & Forensic Auditor | Incident Reconstruction | Export historical security incident logs, review AI analysis rationales, and verify non-repudiation timestamps. |
| AI Perimeter Analyst & Autonomous Agent | Telemetry Ingestion & Incident Remediation | Query threat intelligence summaries, perform real-time deep IP forensics, track high-risk attack vectors, and execute autonomous mitigation actions via MCP. |
4. Visual Interface & Layout
Section titled “4. Visual Interface & Layout”The AI Perimeter Guard console features a dynamic NOC dashboard providing real-time telemetry, threat posture indicators, incident velocity sparklines, and live forensic tables.
4.1 Threat Overview Dashboard
Section titled “4.1 Threat Overview Dashboard”Displays active kernel bans, 24-hour attack volume, blocked toll fraud incidents, vector breakdown, and threat velocity timelines.

5. Threat Scoring Matrix & Event Taxonomies
Section titled “5. Threat Scoring Matrix & Event Taxonomies”The heuristic engine evaluates incoming SIP packets across multiple weighted attack vectors, assigning a cumulative Threat Score (0 to 100):
| Event Type | Severity | Default Weight | Description |
|---|---|---|---|
sipvicious_probe |
Critical | 90–100 | Known scanner signatures matching User-Agents, method sequences, or brute-force user lists. |
toll_fraud_attempt |
Critical | 85–100 | Rapid sequential calls to premium rate or unallocated international destinations matching IRSF patterns. |
distributed_scan |
High | 75–85 | Multi-IP coordinated reconnaissance probing sequentially across consecutive SIP extension ranges. |
header_anomaly |
Medium | 60–75 | Malformed Via branch parameters, missing Call-ID tokens, or conflicting SDP media descriptions. |
credential_stuffing |
High | 70–85 | Excessive 401/407 authentication failures within short sampling windows (>5 failures/min). |
high_failure_rate |
Medium | 50–65 | Abnormal ratio of non-200 OK responses to overall call attempts originating from an unpeered source. |
6. Field Reference & Defense Settings
Section titled “6. Field Reference & Defense Settings”The Defense Settings tab allows administrators to calibrate operational thresholds:
| Parameter | Type | Default | Description |
|---|---|---|---|
| Enable AI Defense Shield | Toggle | Enabled |
Master operational switch activating autonomous heuristic analysis and Kamailio integration. |
| Auto-Ban Threshold | Number (0–100) | 80 |
Minimum aggregate threat score required to trigger an immediate autonomous IP ban. |
| Challenge Threshold | Number (0–100) | 50 |
Threat score threshold at which suspicious sources are subjected to cryptographic SIP challenges and rate-limiting. |
| Ban Duration (Minutes) | Number | 1440 (24h) |
Time interval during which banned IPs remain blocked in memory and kernel filters before automatic expiration. |
| Distributed Scan Detection | Toggle | Enabled |
Correlates scanning patterns across disparate source IPs sharing similar subnets or user-agent footprints. |
| SIP Header Entropy Detection | Toggle | Enabled |
Analyzes structural randomness and protocol deviations in SIP headers to detect customized attack scripts. |
| Toll Fraud Shield | Toggle | Enabled |
Detects abnormal outbound call bursts to unassigned or premium-rate country codes. |
| Rate-Limiting Escalation | Toggle | Enabled |
Dynamically throttles requests from offending sources prior to full IP ban execution. |
| Whitelist Subnets | CIDR Array | 127.0.0.1/32, 192.168.10.0/24 |
Trusted management and carrier subnets that bypass autonomous banning mechanisms. |
7. Kamailio & Kernel Mitigation Pipeline
Section titled “7. Kamailio & Kernel Mitigation Pipeline”When an IP crosses the Auto-Ban Threshold, the AI Perimeter Guard initiates a two-tier enforcement workflow:
-
Kamailio Shared Memory Hash Table (
htable):Terminal window kamcmd htable.sets ipban "185.220.101.5" 1440In
kamailio.cfg, packets arriving from addresses present in$sht(ipban=>$si)are immediately dropped withdrop;or terminated withsl_send_reply("403", "Forbidden");. -
Linux Kernel Packet Filter (
nftables/iptables):Terminal window nft add element inet filter sbc_bans { 185.220.101.5 }Ensures that repeat packets are dropped directly inside the Linux network stack before reaching userspace memory.
8. Forensic Audit & Event Analysis
Section titled “8. Forensic Audit & Event Analysis”Each security event captures rich forensic JSON metadata in the ai_security_events table:
{ "ip_address": "185.220.101.5", "event_type": "sipvicious_probe", "threat_score": 92, "severity": "critical", "details": { "user_agent": "friendly-scanner", "attempts": 45, "target_port": 5060 }, "ai_analysis": "Heuristic signature match: SIPVicious scanning tool detected attempting extension enumeration across port 5060.", "action_taken": "banned", "country_code": "DE"}9. Operational Hardening & Best Practices
Section titled “9. Operational Hardening & Best Practices”- Whitelist Carrier SBCs: Always register wholesale interconnects and upstream PSTN gateways in the Whitelist Subnets array to prevent accidental carrier blacklisting during high-CPS traffic bursts.
- Calibrate Toll Fraud Prefixes: Align the Toll Fraud Shield with the platform’s Class 4 routing tables, ensuring valid high-volume international routes are exempted.
- Maintain Automated Notifications: Configure webhook endpoints (Slack, PagerDuty, or Microsoft Teams) to receive immediate alerts whenever critical (Score >= 90) bans are enforced.
- Periodic Expired Ban Cleanups: Enable the automated cleaner daemon to purge stale forensic records older than 90 days from the database.
10. Verification & Diagnostics
Section titled “10. Verification & Diagnostics”10.1 Live Incident Query
Section titled “10.1 Live Incident Query”Inspect the latest autonomous bans recorded in the PostgreSQL database:
sudo -u postgres psql -d sbc_admin -c "SELECT id, ip_address, event_type, threat_score, severity, action_taken, country_code, created_atFROM ai_security_eventsORDER BY id DESC LIMIT 5;"10.2 Kamailio Memory Inspection
Section titled “10.2 Kamailio Memory Inspection”Verify that banned IPs are active in Kamailio’s shared memory hash table:
kamcmd htable.dump ipban10.3 Kernel Filter Verification
Section titled “10.3 Kernel Filter Verification”Verify that blocked IP addresses are enforced in the kernel set:
nft list set inet filter sbc_bans11. Model Context Protocol (MCP) AI Integration
Section titled “11. Model Context Protocol (MCP) AI Integration”The Ring2All SBC MCP Server exposes specialized real-time security tools under the ai_perimeter_guard category. These tools empower autonomous SecOps agents and the Ring2All SBC NOC Copilot to ingest threat telemetry, audit suspect IPs on demand, inspect incident event streams, and take immediate defensive actions directly against Kamailio and operating system packet filters.
11.1 Available MCP Tools
Section titled “11.1 Available MCP Tools”| Tool Name | Operation Type | Risk Level | Description |
|---|---|---|---|
kalixor_get_threat_intelligence_summary |
Read-only | read_only |
Retrieves comprehensive real-time posture overview including threat levels, active AI bans, top attack vectors, and 24-hour incident velocity. |
kalixor_analyze_ip_security |
Read-only / Analytical | read_only |
Performs an on-demand AI deep forensic security audit on a specific IP, returning threat score (0–100), risk factors, and recommendations. |
kalixor_list_security_incidents |
Read-only | read_only |
Queries recent security events with filtering by severity (critical, high, medium, low) and event type. |
kalixor_mitigate_threat_ip |
Mutating / Defensive | critical |
Executes an immediate mitigation action (ban or unban) against a specified IP in Kamailio htable and OS firewall with audit tracking. |
11.2 Tool Schemas & Parameter Definitions
Section titled “11.2 Tool Schemas & Parameter Definitions”kalixor_get_threat_intelligence_summary
Section titled “kalixor_get_threat_intelligence_summary”- Description: Get a comprehensive real-time threat intelligence posture overview for Ring2All SBC.
- Input Schema:
{ "type": "object", "properties": {}}kalixor_analyze_ip_security
Section titled “kalixor_analyze_ip_security”- Description: Perform an on-demand AI deep forensic security audit on a specific IP address.
- Input Schema:
{ "type": "object", "properties": { "ipAddress": { "type": "string", "description": "The IP address to audit (e.g., '185.220.101.5')" } }, "required": ["ipAddress"]}kalixor_list_security_incidents
Section titled “kalixor_list_security_incidents”- Description: List recent SIP security events detected by AI Perimeter Guard with filtering.
- Input Schema:
{ "type": "object", "properties": { "limit": { "type": "number", "description": "Number of incidents to return (default 10, max 50)" }, "severity": { "type": "string", "enum": ["critical", "high", "medium", "low"], "description": "Filter by severity level" }, "eventType": { "type": "string", "description": "Filter by specific event type (e.g., distributed_scan, toll_fraud_attempt, sipvicious_probe)" } }}kalixor_mitigate_threat_ip
Section titled “kalixor_mitigate_threat_ip”- Description: Execute an immediate mitigation action (ban or unban) against a specific IP address.
- Input Schema:
{ "type": "object", "properties": { "ipAddress": { "type": "string", "description": "The target IPv4 or IPv6 address to mitigate" }, "action": { "type": "string", "enum": ["ban", "unban"], "description": "Defensive action to perform" }, "reason": { "type": "string", "description": "Operational rationale or forensic finding justifying the action" }, "durationMinutes": { "type": "number", "description": "Ban duration in minutes (default 1440 = 24 hours). Ignored for unban operations." } }, "required": ["ipAddress", "action"]}11.3 Sample Tool Execution Payloads
Section titled “11.3 Sample Tool Execution Payloads”Example 1: Ingesting Threat Overview
Section titled “Example 1: Ingesting Threat Overview”Request Payload:
{ "tool": "kalixor_get_threat_intelligence_summary", "parameters": {}}Response Payload:
{ "success": true, "data": { "threatLevel": "elevated", "activeBans": 27, "last24HoursIncidents": 142, "topAttackVectors": [ { "vector": "sipvicious_probe", "count": 89 }, { "vector": "distributed_scan", "count": 34 }, { "vector": "toll_fraud_attempt", "count": 19 } ], "shieldStatus": "operational", "lastEvaluatedAt": "2026-09-08T11:45:00Z" }}Example 2: Auditing Suspicious IP
Section titled “Example 2: Auditing Suspicious IP”Request Payload:
{ "tool": "kalixor_analyze_ip_security", "parameters": { "ipAddress": "185.220.101.5" }}Response Payload:
{ "success": true, "data": { "ipAddress": "185.220.101.5", "threatScore": 94, "verdict": "malicious", "countryCode": "DE", "autonomousBanActive": true, "riskFactors": [ "Known Tor exit relay signature", "Sequential extension enumeration across port 5060", "High authentication failure velocity (>12 req/sec)" ], "recommendation": "Maintain active perimeter ban; inspect upstream firewall drop logs." }}11.4 Bilingual Natural Language Copilot Prompts
Section titled “11.4 Bilingual Natural Language Copilot Prompts”English Prompts
Section titled “English Prompts”- “Give me the current AI perimeter threat intelligence summary and show the top attack vectors.”
→ Agent calls
kalixor_get_threat_intelligence_summary(). - “Analyze IP 185.220.101.5 and tell me its threat score and why it was flagged.”
→ Agent calls
kalixor_analyze_ip_security({"ipAddress": "185.220.101.5"}). - “List the last 5 critical security incidents involving toll fraud attempts.”
→ Agent calls
kalixor_list_security_incidents({"limit": 5, "severity": "critical", "eventType": "toll_fraud_attempt"}). - “Ban IP 198.51.100.44 for 720 minutes due to aggressive credential brute forcing.”
→ Agent calls
kalixor_mitigate_threat_ip({"ipAddress": "198.51.100.44", "action": "ban", "durationMinutes": 720, "reason": "Aggressive credential brute forcing"}).
Spanish Prompts (Español)
Section titled “Spanish Prompts (Español)”- “Muestra el resumen de inteligencia de amenazas del perímetro y los vectores de ataque principales.”
→ Agente invoca
kalixor_get_threat_intelligence_summary(). - “Analiza la seguridad de la IP 185.220.101.5 y dime su puntaje de amenaza.”
→ Agente invoca
kalixor_analyze_ip_security({"ipAddress": "185.220.101.5"}). - “Lista los últimos 10 incidentes de seguridad con severidad crítica.”
→ Agente invoca
kalixor_list_security_incidents({"limit": 10, "severity": "critical"}). - “Bloquea la IP 198.51.100.44 por 1440 minutos por intento de fraude telefónico.”
→ Agente invoca
kalixor_mitigate_threat_ip({"ipAddress": "198.51.100.44", "action": "ban", "durationMinutes": 1440, "reason": "Intento de fraude telefónico"}).
11.5 Enterprise Security & Execution Safeguards
Section titled “11.5 Enterprise Security & Execution Safeguards”- Strict Mitigation Privileges: Executing
kalixor_mitigate_threat_ipwithaction: 'ban'oraction: 'unban'requires high-level administrative or SecOps role clearance. Audit logs record the invoking user or AI session ID, IP, and reason string. - Whitelisted Subnet Bypass Prevention: If an agent or operator attempts to mitigate an IP address falling inside a protected internal subnet or carrier trunk range, the action is rejected with an explicit error.
- Dual-Layer Enforcement: Mitigations push entries simultaneously to the volatile Kamailio in-memory hash table (
htable) and the persistent PostgreSQL audit table, guaranteeing survivability across daemon restarts.
12. Glossary
Section titled “12. Glossary”- DPI (Deep Packet Inspection): Advanced inspection technique that examines data payloads and application-layer protocols (SIP, SDP) beyond packet header information.
- IRSF (International Revenue Share Fraud): Telecommunications fraud where attackers route illicit call traffic to high-cost premium numbers to share in generated termination revenue.
- SIP Entropy: Mathematical measure of disorder or randomness within SIP message headers used to identify synthetic exploit payloads.
- htable: Kamailio module providing high-performance in-memory key-value storage shared across all SIP processing worker threads.
- Model Context Protocol (MCP): An open standard enabling autonomous AI assistants and NOC copilots to securely discover and invoke SBC operational tools.

