Characterization of Network Traffic Features for Intrusion Detection in IoMT Cybersecurity
DOI:
https://doi.org/10.52958/iftk.v22i2.12606Keywords:
IoMT, Intrusion Detection, Network flow, Feature selection, Class imbalanceAbstract
Network security in the Internet of Medical Things (IoMT) requires intrusion detection that is accurate and interpretable, yet IoMT traffic is often imbalanced and heavy-tailed, complicating feature selection and evaluation. This study characterizes the MedSec-25 dataset and identifies influential network-flow features for stage-aware IoMT intrusion detection. Using 10,000 stratified flows (approximately 40 features), we apply robust descriptive statistics and compare linear relevance (ANOVA F-score) with nonlinear relevance (Mutual Information), supported by correlation auditing and non-parametric testing. The data exhibit strong class imbalance (IR about 10.9:1) and predominantly non-Gaussian distributions. The overlap of ANOVA and MI highlights a compact, interpretable core of temporal and rate/volume indicators, while multivariate interactions help explain why many univariate Kruskal–Wallis tests are non-significant. Based on these findings, we provide a practical IDS design guideline: an auditable pre-filter followed by a nonlinear classifier, assessed with MCC and AUPRC to better reflect minority attack stages. The analysis offers a reproducible foundation for feature-driven IDS development in healthcare IoMT.
References
S. Messinis, N. Temenos, N. E. Protonotarios, I. Rallis, D. Kalogeras, and N. Doulamis, “Enhancing Internet of Medical Things security with artificial intelligence: A comprehensive review,” Comput. Biol. Med., vol. 170, p. 108036, Mar. 2024, doi : https://doi.org/10.1016/j.compbiomed.2024.108036
A. Si-Ahmed, M. A. Al-Garadi, and N. Boustia, “Survey of Machine Learning based intrusion detection methods for Internet of Medical Things,” Appl. Soft Comput., vol. 140, p. 110227, Jun. 2023, doi : https://doi.org/10.1016/j.asoc.2023.110227
I. Sharafaldin, A. Habibi Lashkari, and A. A. Ghorbani, “Toward Generating a New Intrusion Detection Dataset and Intrusion Traffic Characterization,” in Proceedings of the 4th International Conference on Information Systems Security and Privacy, SCITEPRESS - Science and Technology Publications, 2018, pp. 108–116. Doi : https://doi.org/10.5220/0006639801080116
M. L. Hernandez-Jaimes, A. Martinez-Cruz, K. A. Ramírez-Gutiérrez, and C. Feregrino-Uribe, “Artificial intelligence for IoMT security: A review of intrusion detection systems, attacks, datasets and Cloud–Fog–Edge architectures,” Internet of Things, vol. 23, p. 100887, Oct. 2023, doi : https://doi.org/10.1016/j.iot.2023.100887
B. Al-Sada, A. Sadighian, and G. Oligeri, “MITRE ATT: State of the Art and Way Forward,” ACM Comput. Surv., vol. 57, no. 1, pp. 1–37, Jan. 2025, doi : https://doi.org/10.1145/3687300
S. Dadkhah, E. C. P. Neto, R. Ferreira, R. C. Molokwu, S. Sadeghi, and A. A. Ghorbani, “CICIoMT2024: A benchmark dataset for multi-protocol security assessment in IoMT,” Internet of Things, vol. 28, p. 101351, Dec. 2024, doi : https://doi.org/10.1016/j.iot.2024.101351
M. Alalhareth and S.-C. Hong, “Enhancing the Internet of Medical Things (IoMT) Security with Meta-Learning: A Performance-Driven Approach for Ensemble Intrusion Detection Systems,” Sensors, vol. 24, no. 11, p. 3519, May 2024, doi : https://doi.org/10.3390/s24113519
M. Ahmed, S. Byreddy, A. Nutakki, L. F. Sikos, and P. Haskell-Dowland, “ECU-IoHT: A dataset for analyzing cyberattacks in Internet of Health Things,” Ad Hoc Networks, vol. 122, p. 102621, Nov. 2021, doi : https://doi.org/10.1016/j.adhoc.2021.102621
A. Alabbadi and F. Bajaber, “An Intrusion Detection System over the IoT Data Streams Using eXplainable Artificial Intelligence (XAI),” Sensors, vol. 25, no. 3, p. 847, Jan. 2025, doi: https://doi.org/10.3390/s25030847
G. Thamilarasu, A. Odesile, and A. Hoang, “An Intrusion Detection System for Internet of Medical Things,” IEEE Access, vol. 8, pp. 181560–181576, 2020, doi : https://doi.org/10.1109/ACCESS.2020.3026260
M. M. Ozcelik, I. Kok, and S. Ozdemir, “A Survey on Internet of Medical Things IoMT: Enabling Technologies, Security and Explainability Issues, Challenges, and Future Directions,” Expert Syst., vol. 42, no. 5, May 2025, doi: https://doi.org/10.1111/exsy.70010
M. Abdullah, “MedSec-25: IoMT Cybersecurity Dataset,” Kaggle. Accessed: Sep. 26, 2025. [Online]. Available: https://www.kaggle.com/datasets/abdullah001234/medsec-25-iomt-cybersecurity-dataset/data
W. Almobaideen, M. Abdullah, U. Alam, S. B. Hussain, and A. Bouharrat, “MedSec-25: Creating an IoMT Dataset for a Healthcare IoT Environment,” in the 7th International Conference on Blockchain Computing and Applications, 2025. Doi : https://doi.org/10.1109/BCCA66705.2025.11229535
A. Habibi Lashkari, G. Draper Gil, M. S. I. Mamun, and A. A. Ghorbani, “Characterization of Tor Traffic using Time based Features,” in Proceedings of the 3rd International Conference on Information Systems Security and Privacy, SCITEPRESS - Science and Technology Publications, 2017, pp. 253–262. doi: https://doi.org/10.5220/0006105602530262
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Bayu Hananto, Ridwan Raafi'udin, Didit Widiyanto

This work is licensed under a Creative Commons Attribution 4.0 International License.
KEBIJAKAN YANG DIAJUKAN UNTUK JURNAL YANG MENAWARKAN AKSES TERBUKA
Syarat yang harus dipenuhi oleh Penulis sebagai berikut:
- Penulis menyimpan hak cipta dan memberikan jurnal hak penerbitan pertama naskah secara simultan dengan lisensi di bawah Creative Commons Attribution License yang mengizinkan orang lain untuk berbagi pekerjaan dengan sebuah pernyataan kepenulisan pekerjaan dan penerbitan awal di jurnal ini.
- Penulis bisa memasukkan ke dalam penyusunan kontraktual tambahan terpisah untuk distribusi non ekslusif versi kaya terbitan jurnal (contoh: mempostingnya ke repositori institusional atau menerbitkannya dalam sebuah buku), dengan pengakuan penerbitan awalnya di jurnal ini.
- Penulis diizinkan dan didorong untuk mem-posting karya mereka online (contoh: di repositori institusional atau di website mereka) sebelum dan selama proses penyerahan, karena dapat mengarahkan ke pertukaran produktif, seperti halnya sitiran yang lebih awal dan lebih hebat dari karya yang diterbitkan. (Lihat Efek Akses Terbuka).




