Mitigating Ransomware Attacks in Internet of Medical Things Networks
Usman Tariq, Fehmi Jaafar, Yasir Malik · 2025
The proliferation of Internet of Things (IoT) devices has significantly expanded the attack surface for ransomware, with the healthcare sector-particularly Internet of Medical Things (IoMT) devices-emerging as a critical target. Traditional cybersecurity solutions often fail to address the unique vulnerabilities and operational constraints of eHealth IoT environments, where ransomware attacks can result in severe consequences, including patient safety risks and operational disruptions. This paper introduces a novel hybrid detection framework that combines Long Short-Term Memory (LSTM) networks with Autoencoders to identify ransomware activity in IoMT devices. By leveraging the sequential data analysis capabilities of LSTMs and the anomaly detection strengths of Autoencoders, the proposed model effectively detects subtle and sophisticated ransomware behaviors while maintaining computational efficiency suitable for real-world deployment. The approach incorporates adaptive thresholding to accommodate dynamic IoMT environments and employs continuous learning to adapt to evolving ransomware tactics. Experimental results demonstrate that the hybrid model outperforms conventional detection methods in both accuracy and sensitivity, achieving robust real-time detection with minimal false positives. These findings lay the groundwork for future research into resilient, AI-driven security solutions for industrial and medical IoT applications