{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,17]],"date-time":"2025-10-17T14:27:44Z","timestamp":1760711264356,"version":"build-2065373602"},"reference-count":13,"publisher":"MDPI AG","issue":"11","license":[{"start":{"date-parts":[[2023,10,24]],"date-time":"2023-10-24T00:00:00Z","timestamp":1698105600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Entropy"],"abstract":"<jats:p>The security of a network requires the correct identification and characterization of the attacks through its ports. This involves the follow-up of all the requests for access to the networks by all kinds of users. We consider the frequency of connections and the type of connections to a network, and determine their joint probability. This leads to the problem of determining a joint probability distribution from the knowledge of its marginals in the presence of errors of measurement. Mathematically, this consists of an ill-posed linear problem with convex constraints, which we solved by the method of maximum entropy in the mean. This procedure is flexible enough to accommodate errors in the data in a natural way. Also, the procedure is model-free and, hence, it does not require fitting unknown parameters.<\/jats:p>","DOI":"10.3390\/e25111476","type":"journal-article","created":{"date-parts":[[2023,10,24]],"date-time":"2023-10-24T06:28:25Z","timestamp":1698128905000},"page":"1476","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Understanding the Feature Space and Decision Boundaries of Commercial WAFs Using Maximum Entropy in the Mean"],"prefix":"10.3390","volume":"25","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-3781-8848","authenticated-orcid":false,"given":"Henryk","family":"Gzyl","sequence":"first","affiliation":[{"name":"Centro de Finanzas IESA, Caracas 1010, Venezuela"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5153-1475","authenticated-orcid":false,"given":"Enrique","family":"ter Horst","sequence":"additional","affiliation":[{"name":"School of Management, Universidad de los Andes, Bogota 111711, Colombia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6594-5940","authenticated-orcid":false,"given":"Nathalie","family":"Pe\u00f1a-Garcia","sequence":"additional","affiliation":[{"name":"Research Department, CESA Business School, Bogota 110311, Colombia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-1794-0303","authenticated-orcid":false,"given":"Andres","family":"Torres","sequence":"additional","affiliation":[{"name":"School of Management, Universidad de los Andes, Bogota 111711, Colombia"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2023,10,24]]},"reference":[{"key":"ref_1","unstructured":"Matatall, N., and Arseniev, M. (2008). Web Application Security, University of California."},{"key":"ref_2","unstructured":"Prandl, S., Lazarescu, M., and Pham, D.S. (2015). Information Systems Security, Springer International Publishing. Lecture Notes in Computer Science."},{"key":"ref_3","unstructured":"Biggio, B., Corona, I., Maiorca, D., Nelson, B., \u0160rndi\u0107, N., Laskov, P., Giacinto, G., and Roli, F. (2013). Advanced Information Systems Engineering, Springer. Lecture Notes in Computer Science."},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Papernot, N., McDaniel, P., Goodfellow, I., Jha, S., Celik, Z.B., and Swami, A. (2017, January 2\u20136). Practical Black-Box Attacks against Machine Learning. Proceedings of the ACM Asia Conference on Computer and Communications Security, Abu Dhabi, United Arab Emirates.","DOI":"10.1145\/3052973.3053009"},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"e4150","DOI":"10.1002\/ett.4150","article-title":"Network intrusion detection system: A systematic study of machine learning and deep learning approaches","volume":"32","author":"Ahmad","year":"2020","journal-title":"Trans. Emerg. Telecommun. Technol."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"105","DOI":"10.1186\/s40537-020-00379-6","article-title":"Performance Analysis of Intrusion Detection Systems Using a Feature Selection Method on the UNSW-NB15 Dataset","volume":"7","author":"Kasongo","year":"2020","journal-title":"J. Big Data"},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"255","DOI":"10.1016\/j.cose.2017.06.005","article-title":"A GA-LR wrapper approach for feature selection in network intrusion detection","volume":"70","author":"Khammassi","year":"2017","journal-title":"Comput. Secur."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"32464","DOI":"10.1109\/ACCESS.2020.2973730","article-title":"Network Intrusion Detection Combined Hybrid Sampling With Deep Hierarchical Network","volume":"8","author":"Jiang","year":"2020","journal-title":"IEEE Access"},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"195","DOI":"10.1016\/j.neucom.2019.03.057","article-title":"Timescale diversity facilitates the emergence of cooperation-extortion alliances in networked systems","volume":"350","author":"Xu","year":"2019","journal-title":"Neurocomputing"},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"4778","DOI":"10.1080\/03610926.2020.1723639","article-title":"Construction of contingency tables by maximum entropy in the mean","volume":"50","author":"Gzyl","year":"2021","journal-title":"Commun. Stat. Theory Methods"},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Sharafaldin, I., Lashkari, A.H., and Ghorbani, A.A. (2018, January 22\u201324). Toward Generating a New Intrusion Detection Dataset and Intrusion Traffic Characterization. Proceedings of the International Conference on Information Systems Security and Privacy, Funchal, Portugal.","DOI":"10.5220\/0006639801080116"},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Rossow, C., Dietrich, C.J., Bos, H., Cavallaro, L., van Steen, M., Freiling, F.C., and Pohlmann, N. (2011, January 10\u201313). Sandnet. Proceedings of the First Workshop on Building Analysis Datasets and Gathering Experience Returns for Security, Salzburg, Austria.","DOI":"10.1145\/1978672.1978682"},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"1","DOI":"10.18637\/jss.v040.i06","article-title":"DEoptim: An R Package for Global Optimization by Differential Evolution","volume":"40","author":"Mullen","year":"2011","journal-title":"J. Stat. Softw."}],"container-title":["Entropy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1099-4300\/25\/11\/1476\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T21:10:47Z","timestamp":1760130647000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1099-4300\/25\/11\/1476"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,10,24]]},"references-count":13,"journal-issue":{"issue":"11","published-online":{"date-parts":[[2023,11]]}},"alternative-id":["e25111476"],"URL":"https:\/\/doi.org\/10.3390\/e25111476","relation":{},"ISSN":["1099-4300"],"issn-type":[{"type":"electronic","value":"1099-4300"}],"subject":[],"published":{"date-parts":[[2023,10,24]]}}}