A Lightweight Edge-Based Framework for Network Traffic Monitoring and Anomaly Detection in Internet of Medical Things (IoMT) Systems
Abstract
The Internet of Medical Things (IoMT) connects health sensors to clinical networks, yet endpoint resource constraints prevent native security enforcement [17]. Cloudbased detection introduces latency that hinders real-time attack mitigation [10]. This paper proposes a lightweight, edge-based conceptual framework combining offline machine learning with live rule validation at the gateway layer [10], [11]. The design specifies an offline training pipeline on the CICIoT2023 dataset using Principal Component Analysis (PCA) to retain 95% cumulative explained variance while compressing feature dimensions [2], [6]. At the edge, a Raspberry Pi gateway architecture is modeled to ingest multi-device MQTT telemetry from sensor endpoints (e.g., ESP32 nodes), extract flow metrics, and compute hybrid risk scores using LightGBM inferences and rule-based checks [11]. The framework incorporates a dualaction threat response: external flood attacks can trigger automated iptables packet blocking against malicious source IPs to preserve sensor telemetry continuity, while internal node compromises can trigger device quarantine flags and alerts on a web dashboard [11]. The architecture supports local MQTT message buffering during network instability, time-windowed feature aggregation, MQTT QoS 1 reliability, and an administrative release workflow for benign device recovery [5], [10]. Advanced system extensions-including secure Over-TheAir (OTA) model updates via SHA-256 hash verification, multithreaded burst queue handling, and automated fallback recovery-are designated as future work. Theoretical design evaluations demonstrate the framework's viability for lowlatency threat mitigation in resource-constrained clinical environments [10], [11].