NORMA eResearch @NCI Library

Building a Lightweight Rule-Based Anomaly Intrusion Detection System for Internet of Medical Things Networks

Bhumireddi, Sowmya (2025) Building a Lightweight Rule-Based Anomaly Intrusion Detection System for Internet of Medical Things Networks. Masters thesis, Dublin, National College of Ireland.

[thumbnail of Master of Science]
Preview
PDF (Master of Science)
Download (776kB) | Preview
[thumbnail of Configuration Manual]
Preview
PDF (Configuration Manual)
Download (353kB) | Preview

Abstract

The rapid proliferation of Internet of Medical Things (IoMT) devices in healthcare settings has rapidly increased and transformed patient monitoring, diagnostics, and operations. Nevertheless, they are very susceptible to cyber threats because of their low computational capabilities, security profiles, and heterogeneous deployment environments varying in configurations and infrastructure. The research project focuses on building and rigorously evaluating a lightweight, rule-based anomaly Intrusion Detection System (IDS), which is specifically designed and tailored for an IoMT network. The suggested IDS observes key metrics of the system, namely CPU load, memory usage, processes, and network traffic of various devices and alerts to possible anomaly signals of a cyber-attack. The system was tested with two exemplary IoMT devices, a Heart Monitor and a Glucose Sensor, to prove that the system is secure under controlled attack conditions, which are CPU overload, memory overload, process injection, and network flooding. The evaluation results show that the IDS had 100% detection rate, an average latency of 14.2 seconds and no false positives during prolonged monitoring periods of the baseline. However, some of them may be due to real-world noise with low resource consumption (less than 5% CPU) when tested with two simulated IoMT devices in repeated attack simulated conditions. The prototype was tested with two simulated nodes of an IoMT (HeartMonitor and GlucoseSensor) and one central gateway in the controlled attack environment. This research is built upon the partial data-collection prototype by Zachos et al. (2022), and turns it into a fully functional, rule-based IDS to demonstrate the viability of lightweight and fully explainable anomaly detection in real IoMT deployments, without the use of machine learning.

Item Type: Thesis (Masters)
Supervisors:
Name
Email
Salahuddin, Jawad
UNSPECIFIED
Subjects: Q Science > QA Mathematics > Computer software > Computer Security
T Technology > T Technology (General) > Information Technology > Computer software > Computer Security
R Medicine > Healthcare Industry
T Technology > TK Electrical engineering. Electronics. Nuclear engineering > Telecommunications > Computer networks > Internet of things
Divisions: School of Computing > Master of Science in Cyber Security
Depositing User: Ciara O'Brien
Date Deposited: 03 Sep 2026 10:26
Last Modified: 03 Sep 2026 10:26
URI: https://norma.ncirl.ie/id/eprint/9791

Actions (login required)

View Item View Item