College

College of Engineering

Mentor Information

Trung Le

Description

The growing use of interconnected medical devices expands the attack surface of healthcare networks and creates the possibility that a compromise affecting one device, gateway, or communication channel may propagate through connected systems, producing cascading operational and patient-safety consequences. This research investigates whether temporal graph learning can improve intrusion detection and dynamic cyber-risk assessment in Internet of Medical Things networks. A Temporal Graph Network represents network flows as time-ordered interactions between communicating devices, uses each interaction to update their evolving behavioral profiles. The model jointly supports attack-type classification, anomaly detection, and dynamic risk scoring. The design also explores Dynamic Mode Decomposition as an approach for modeling network-wide behavioral regimes and identifying patterns such as coordinated scanning, rapid attack growth, lateral propagation, and cascading attacks that may not be evident from isolated flows. Initial experiments use established NetFlow- based intrusion detection datasets to compare the proposed approach with other graph-based detection systems. The model will then be evaluated on a standardized, NetFlow-inspired flow-based version of CICIoMT2024, a realistic multi-protocol dataset of cyberattacks in Internet of Medical Things networks containing traffic generated by real and simulated medical devices across benign, profiling, and attack scenarios. The expected contribution is an adaptive streaming security framework that combines local device behavior with global network dynamics to improve the early detection of coordinated, cascading, and previously unseen threats; thus, producing interpretable risk estimates that reflect the potential malicious activity occurring within the network.

Share

COinS
 

Temporal Graph Networks with Dynamic Mode Decomposition for IoMT Threat and Risk Detection

The growing use of interconnected medical devices expands the attack surface of healthcare networks and creates the possibility that a compromise affecting one device, gateway, or communication channel may propagate through connected systems, producing cascading operational and patient-safety consequences. This research investigates whether temporal graph learning can improve intrusion detection and dynamic cyber-risk assessment in Internet of Medical Things networks. A Temporal Graph Network represents network flows as time-ordered interactions between communicating devices, uses each interaction to update their evolving behavioral profiles. The model jointly supports attack-type classification, anomaly detection, and dynamic risk scoring. The design also explores Dynamic Mode Decomposition as an approach for modeling network-wide behavioral regimes and identifying patterns such as coordinated scanning, rapid attack growth, lateral propagation, and cascading attacks that may not be evident from isolated flows. Initial experiments use established NetFlow- based intrusion detection datasets to compare the proposed approach with other graph-based detection systems. The model will then be evaluated on a standardized, NetFlow-inspired flow-based version of CICIoMT2024, a realistic multi-protocol dataset of cyberattacks in Internet of Medical Things networks containing traffic generated by real and simulated medical devices across benign, profiling, and attack scenarios. The expected contribution is an adaptive streaming security framework that combines local device behavior with global network dynamics to improve the early detection of coordinated, cascading, and previously unseen threats; thus, producing interpretable risk estimates that reflect the potential malicious activity occurring within the network.