3 ms·
I don't think you're going to catch a lot of what you think you're going to catch with HTTP inspection. Actually getting data out of a compromised system could
by 13 12y ago
I don't think you're going to catch a lot of what you think you're going to catch with HTTP inspection. Actually getting data out of a compromised system could happen with all manor of seemingly innocent information that would pass through even a fine tooth comb of every packet. What if there's malware leaking data by appending whitespace on the end of URLs, messing with the timing of DNS requests, adding pixels to images on the fly? I don't think it's humanly possible to validate the amount of data which floods out of systems on a daily basis.
- click170 12y agoI agree, it's easy to get around these systems with minimal effort. I disagree that I shouldn't try to catch the low hanging fruit because of the existence of higher hanging fruit.