Network security in the Internet of Medical Things (IoMT) requires intrusion detection that is accurate and interpretable, yet IoMT traffic is often imbalanced and heavy-tailed, complicating feature selection and evaluation. This study characterizes the MedSec-25 dataset and identifies influential network-flow features for stage-aware IoMT intrusion detection. Using 10,000 stratified flows (approximately 40 features), we apply robust descriptive statistics and compare linear relevance (ANOVA F-score) with nonlinear relevance (Mutual Information), supported by correlation auditing and non-parametric testing. The data exhibit strong class imbalance (IR about 10.9:1) and predominantly non-Gaussian distributions. The overlap of ANOVA and MI highlights a compact, interpretable core of temporal and rate/volume indicators, while multivariate interactions help explain why many univariate Kruskal–Wallis tests are non-significant. Based on these findings, we provide a practical IDS design guideline: an auditable pre-filter followed by a nonlinear classifier, assessed with MCC and AUPRC to better reflect minority attack stages. The analysis offers a reproducible foundation for feature-driven IDS development in healthcare IoMT.
Copyrights © 2026