Enhancing IoMT Security using Multi-Layer Authentication: A Zero-Trust Machine Learning Case Study for Emergency Medical Services
Abstract
The growing use of the Internet of Medical Things (IoMT) in ambulances enables real-time transmission of patients’ vital signs to hospitals. However, this exchange is increasingly exposed to cyber threats, especially Distributed Denial of Service (DDoS) and data injection attacks that can delay critical decisions and compromise patient safety. This IoMT system is subject to various kinds of attacks across multiple layers. While many existing solutions focus on securing medical data through encryption or blockchain, they do not focus on detecting anomalies during transmission or analyzing network and data content behavior in real-time. This paper proposes a real-time security framework for Emergency Medical Services (EMS) that monitors and analyzes both levels, network and data content, based on the principle of “never trust, always verify.” The aim is to detect specific threats and take immediate action in real time before the data reach the hospital. The model integrates Machine Learning (ML), a Signature Intrusion Detection System (SIDS), the Zero Trust Model (ZTM), and Two-Factor Authentication (2FA) to simulate the application at two levels: (1) DDoS attacks at the network level with a general description and less simulation; (2) data injection attacks at the content level with focusing in detail at this level.Once an attack is detected, the system applies an isolation mechanism that either isolates the compromised IoMT device from it’s network at the ambulance in case data injection comes from that device, or disconnects the ambulance’s network interface in case of DDoS at the network level, preventing further propagation of malicious traffic. ML classifiers such as Decision Tree (DT), K-Nearest Neighbors (KNN), and Random Forest (RF) are trained in the cloud represented in our work by the hospital and then tested at the edge node (ambulance), which is the closest point to the data collection to ensure real-time decision-making. The simulation results demonstrate that the DT model achieved the best performance for multiclass classification at the data-content level (attack, medical issue, normal), with an overall accuracy of 98.096% and an Matthews’ Correlation Coefficient (MCC) of 97.172%. Compared with other models, including RF with an accuracy of 98.01% and MCC of 97.055%, and KNN with an accuracy of 97.72% and MCC of 96.56%.
The submitting author warrants that the submission is original and that she/he is the author of the submission together with the named co-authors; to the extend the submission incorporates text passages, figures, data or other material from the work of others, the submitting author has obtained any necessary permission.
Articles in this journal are published under the Creative Commons Attribution Licence (CC-BY). This is to get more legal certainty about what readers can do with published articles, and thus a wider dissemination and archiving, which in turn makes publishing with this journal more valuable for you, the authors.
In order for iJIST to publish and disseminate research articles, we need publishing rights. This is determined by a publishing agreement between the author and iJIST.
By submitting an article the author grants to this journal the non-exclusive right to publish it. The author retains the copyright and the publishing rights for his article without any restrictions.
Privacy Statement
The names and email addresses entered in this journal site will be used exclusively for the stated purposes of this journal and will not be made available for any other purpose or to any other party.