This document proposes an approach to mitigate distributed denial of service (DDoS) attacks on voice over internet protocol (VoIP) systems. It discusses common VoIP attacks like eavesdropping, reconnaissance, and DDoS attacks. The proposed system would use Suricata as an intrusion detection and prevention system to analyze VoIP traffic, detect attacks, and trigger mitigation responses. It recommends configuring call limits, updating device firmware, and using a buffer server to filter traffic as countermeasures against DDoS attacks on SIP-based VoIP networks.