Chunked transfer encoding is a data transfer mechanism of HTTP (HyperText Transfer Protocol) version 1.1. Here, the web servers break the HTTP response content into series of non-overlapping chunks. These chunks contain http response payload. It uses transfer encoding header in place of the content-length header, which the protocol would otherwise require. Chunked transfer encoding supports sending dynamically generated content to clients without having to buffer it. Such payload chunks could be used to evade network inspection devices.
When Chunked HTTP Response Decoding is enabled, the Sensor inspects chunks in the http response traffic. The chunks identified are dechunked, and the dechunked payload is inspected further after separating the metadata. Post inspection, the response actions configured in inspection options are triggered.
Points for consideration:
Chunked HTTP Response Decoding is disabled by default.
To enable Chunked HTTP Response Decoding, HTTP Response Traffic Scanning should be enabled.
Chunked HTTP Response Decoding is supported in inline and span modes for both Intrusion Prevention Systems (IPS) and Intrusion Detection Systems (IDS).
Chunked HTTP Response Decoding feature relatively lowers overall performance of the Sensors depending on chunked content in the network traffic.
Advance Malware inspection of dechunked payload is not supported.