Dependability Analysis of Cloud‐Based VoIP Under an Advanced Persistent Threat Attack: A Semi‐Markov Approach
Nikesh Choudhary, Vandana Khaitan · Transactions on Emerging Telecommunications Technologies · 2026
ABSTRACT Voice over Internet Protocol (VoIP) has emerged as a game‐changing communication technology given that it allows for low‐cost long‐distance conversations with plenty of additional benefits. In this era of cloud computing, VoIP can offer even cheaper calls and scalable services with the help of virtualized telephone infrastructure. The integration of virtualized telephone infrastructure with VoIP is known as “ cloud‐based VoIP .” In this paper, we investigate a cloud‐based VoIP under the advanced persistent threat (APT) attack. An APT attack is a sophisticated type of cyberattack that tries to steal personal information by staying in the infected system for an extended period of time, thereby impacting the system dependability. “Dependability is a measure of a system's availability, reliability, maintainability, and in some cases, other characteristics such as durability, safety and security”. Hence, we develop a robust mechanism for mitigating APT attack in a cloud‐based VoIP phone system and investigate its dependability to minimize the aftermaths of the attack. We employ a semi‐Markov process (SMP) model to study the dependability as it gives consideration to the non‐Markovian nature of the holding times of various system states. The SMP model is then used to analyze both the time‐dependent behavior and the long‐term (stationary) performance characteristic of the cloud‐based VoIP system, specifically in terms of availability, reliability, and confidentiality. Numerical results are displayed graphically, and the proposed dependability model is supported by stochastic simulation. It has been established from the numerical results that the cloud‐based VoIP is the most sensitive and critical when it is exploited by cyberattacks, and the lifetime of the system can be extended if the weaknesses of the system are discovered before it is exploited by the attackers.