Detection of abnormal chunk size with Signature module (7.6.1)
In scenarios where an abnormal chunk size is detected at the HTTP protocol layer, FortiWeb's Signature module now flags the relevant session and takes appropriate actions.
Previously, abnormal chunk size detection was limited to the HPC (HTTP Protocol Constraints) module. With this enhancement in the Signature module, FortiWeb’s factory default settings can screen out sessions with abnormal chunk sizes without requiring additional HPC configuration.
It's included as Abnormal HTTP Format under Generic Attacks and Generic Attacks (Extended) (Web Protection > Known Attacks > Signatures).
For more information about Signatures, see Blocking known attacks