Abstract
The rapid adoption of Internet of Medical Things (IoMT) devices in healthcare environments has increased exposure to network-based cyberattacks, highlighting the need for effective post-incident forensic analysis. While existing research largely focuses on real-time intrusion detection, comparatively little attention has been given to forensic approaches that support attack reconstruction and attribution in IoMT networks. This paper presents a forensic analysis framework for IoMT network traffic that emphasises interpretable flow-level artefacts, temporal behaviour, and protocol-level evidence. Using an IoMT network traffic dataset, the framework analyses statistical, temporal, volume-related, and protocol indicators derived from flow metadata, without relying on payload inspection or device-specific information. Statistical artefact profiling and inter-arrival time-based temporal reconstruction reveal distinct behavioural patterns across benign and attack traffic, enabling relative timeline reconstruction of attack activity. Protocol-level analysis further supports forensic attribution by linking observed anomalies to exploited network protocols. A lightweight Random Forest model is included solely as a supporting triage mechanism to prioritise suspicious traffic while preserving interpretability. The results demonstrate that meaningful forensic insight can be derived from flow-level artefacts alone, making the framework suitable for privacy-sensitive healthcare environments and complementary to detection-oriented IoMT security research.
| Original language | English |
|---|---|
| Article number | 302073 |
| Journal | Forensic Science International: Digital Investigation |
| Volume | 57 |
| DOIs | |
| Publication status | Published - 06-2026 |
All Science Journal Classification (ASJC) codes
- Pathology and Forensic Medicine
- Information Systems
- Computer Science Applications
- Medical Laboratory Technology
- Law
Fingerprint
Dive into the research topics of 'A forensic analysis framework for IoMT network traffic using temporal reconstruction and artefact profiling'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver