Mapping Cyber Threats in IoT-Driven MSPs: An Explainable Machine Learning Approach for Remote Work Security
James Johnstone, Adewale Akinfaderin · 2025
Objectives: This study evaluates supervised machine learning (ML) models for predicting and classifying cybersecurity threats in remote work environments of U.S. Managed Service Providers (MSPs) using IoT devices. Methods/Statistical Analysis: A comparative analysis was conducted using Random Forest, XGBoost, and Artificial Neural Networks (ANNs). Two datasets, NF-UQ-NIDS-v2 and CICIDS2017, were used for training and validation. Recursive Feature Elimination (RFE) optimized feature selection. Post hoc explainability techniques-LIME and SHAP-were employed to enhance interpretability. Model performance was measured via accuracy, precision, recall, and false positive rates. Findings: Random Forest achieved the highest accuracy ($\mathbf{98.98 \%}$) with a minimal false positive rate ($\mathbf{(0.0044) \text {, excelling in}}$ precision-focused environments. XGBoost demonstrated broader generalizability for diverse threats. ANN classified complex patterns effectively. Feature mapping to the Cyber Kill Chain framework contextualized threat stages, enhancing detection strategies. Results indicate that a refined set of features can achieve robust threat predictions, minimizing computational costs while maintaining high accuracy. Application/Improvements: This study provides actionable ML insights to improve MSP cybersecurity defenses in IoTintegrated remote work environments.