Previously, the decoding of Chunked HTTP responses supported text file format (.txt). With this release of 10.1, Chunked HTTP Response Decoding engine is enhanced to support evasion techniques that are based on HTTP response deviations from RFC standards.
Points for consideration:
- Chunked HTTP Response Decoding is disabled by default.
- To enable Chunked HTTP Response Decoding, HTTP Response Traffic Scanning should be enabled.
- Chunked HTTP Response Decoding is supported in inline and span modes for both Intrusion Prevention Systems (IPS) and Intrusion Detection Systems (IDS).
- Chunked HTTP Response Decoding feature impacts the Sensor performance depending on chunked content in the network traffic.
- Advance malware inspection of dechunked payload is not supported.