An Efficient Intrusion Detection System using Advanced Machine Learning Techniques in Software-Defined Networks (SDN) for Healthcare System.

Asif, Muhammad Waseem; Aqdus, Aqsa; Amin, Rashid; Chaudhry, Shehzad Ashraf; Alsubaei, Faisal S; Iqbal, Sajid · IEEE J Biomed Health Inform · 2025

basic_science · Level V

Where this comes from

Abstract

The quick advancement of healthcare systems necessitates robust and efficient network security keys to defend sensitive patient records and guarantee uninterrupted service delivery. The current IDS have many challenges such as high false positive rate, poor accuracy of detection, slow response to threat, and inability to scale well. These problems result in poor threat management, resource wastage, compromised network efficiency, and health care system insecurity. This paper proposes an efficient and real-time intrusion detection system (IDS) using advanced machine learning techniques within a software-defined networking (SDN) framework specifically tailored for healthcare systems. In this paper, the proposed architecture implement machine learning model that combines the SVM and KNN to better identify and address malicious activities in healthcare. The SDN architecture also has control over the network where it is possible to add new control layer application for dynamic processing of emerging threats. Full sets of detection and mitigation capabilities are implemented to address different types of traffic in the network and with least interference. Through the different evaluation measures, the efficiency of the proposed model is assured. Network performance is determined by success rate queries, packet losses in each domain path, and the CPU being used by the system. Responsiveness is measured through delay metrics grounded on end-to-end delay, hop-to-hop packet delay, latency rate, and propagation delay. Moreover, model accuracy fidelity is reviewed via precision assessment, alpha () effecting on accuracy of the model and confusion matrix with different techniques with the proposed hybrid SVM-KNN model. Last of all, a comparison of the security of the models in question strengthens the argument in favor of the proposed model. More specifically, flow and network topology diagrams are included to show how integration may be accomplished in linkage or merger with existing health care networks. The results also present a 30% overall advancement in detection and mitigation by presenting the hybrid SVM-KNN model to overcome other traditional models. This proposed model shows significant improvements not less than 20-30% improvement in CPU use, 30-50% reduction in end-to- end delay, 30-40% less latency rate, 20-40% less propagation delay and 20-30% better prediction accuracy and it outperforms Fuzzy, Logistic Regression and Decision Tree methods.