Cisco release , an open-source intrusion detection and prevention system that combines signature matching methods, protocol inspection tools, and anomaly detection mechanisms.
The new release features an early HTTP data inspection mode that operates before the regular handlers are triggered. To enable this mode, use the fast_blocking option in the HTTP inspection settings block. Additionally, the new release provides normalization of randomly encoded null values in HTTP server responses to UTF-8, as well as support for Glibc 2.30 and 64-bit Windows 10.
Source: opennet.ru
