AI-driven cyber forensics for critical healthcare infrastructure security
Sainag Nethala · 2025
Securing critical healthcare infrastructure against evolving cyber threats requires real-time forensic analysis, adaptive anomaly detection, and automated response mechanisms. Traditional forensic tools struggle with high false positive rates, delayed incident response, and inefficient log correlation. This research proposes an advanced Splunk-integrated forensic framework that combines security information and event management (SIEM) automation, AI-driven log filtering, and graph-based event correlation to enhance threat detection, response efficiency, and forensic intelligence. The model is evaluated on the IoT Healthcare Security Dataset, demonstrating a 97.6% accuracy, 96.8% precision, and a 40% reduction in detection latency compared to existing forensic systems. The integration of machine learning, log-based feature engineering, and real-time event correlation significantly improves attack detection, forensic efficiency, and automated security enforcement within healthcare networks. Experimental results validate the effectiveness of AI-enhanced forensic methodologies in minimizing false positives, optimizing detection accuracy, and accelerating response times. This study establishes a scalable, adaptive, and intelligent forensic security framework for proactive threat mitigation and resilient protection of medical IoT infrastructure.