Understanding the Feature Space and Decision Boundaries of Commercial WAFs Using Maximum Entropy in the Mean

Entropy (Basel). 2023 Oct 24;25(11):1476. doi: 10.3390/e25111476.

Abstract

The security of a network requires the correct identification and characterization of the attacks through its ports. This involves the follow-up of all the requests for access to the networks by all kinds of users. We consider the frequency of connections and the type of connections to a network, and determine their joint probability. This leads to the problem of determining a joint probability distribution from the knowledge of its marginals in the presence of errors of measurement. Mathematically, this consists of an ill-posed linear problem with convex constraints, which we solved by the method of maximum entropy in the mean. This procedure is flexible enough to accommodate errors in the data in a natural way. Also, the procedure is model-free and, hence, it does not require fitting unknown parameters.

Keywords: cyber security; decision boundary; feature space; ill-posed linear inverse problem; maximum entropy in the mean; web application firewalls.

Grants and funding

This research received no external funding.