CORTEXA
← Browse
crossrefAcademic Society for Appropriate Technology2026-04-30Cited by 0

Comparative Study of Machine Learning-based Network Anomaly Detection Models for Digital Healthcare Environments

Doyun Lee, Joohwan Son, Deokyeon Go

In the digital healthcare environment, the risk of cyberattacks is continuously increasing due to the proliferation of medical information systems and network-based medical devices. While traditional signature-based and rule-based security technologies are effective against known attacks, they have limitations in detecting new or variant attacks. This study analyzes the applicability of traditional concept learning-based algorithms (Find-S, Version Space, Candidate Elimination) for network anomaly detection in medical environments and proposes machine learning-based detection models (K-means Clustering, Random Forest, LightGBM) to overcome their limitations. We constructed a dataset of approximately 200,000 records using CIC-IDS2017 for normal traffic and a combination of Emerging Threats Rules and real-world security operation data for malicious traffic. The models were evaluated based on Precision, Recall, and F1-score. The experimental results showed that Random Forest and LightGBM achieved high detection performance. In particular, Random Forest demonstrated the most superior results in terms of overall accuracy and stability. These findings provide practical implications for designing AI-based network anomaly detection models suitable for medical environments.

View free PDFSource page