Skip to main content

Rate Limiting on Metric Generation

CCC.Monitor.CN02 · Observability

Prevent Malicious Actor or misconfiguration from flooding services with metric data.

Related Capabilities

IDTitleDescription
CCC.Monitor.CP01Metric collectionGathering numerical (quantitative) data points about the performance, health, or behaviour of systems, applications or infrastructure.
CCC.Monitor.CP11Integration with Third-Party ToolsMonitoring tools are able to integrate with a number of downstream systems in order to send notifications and alerts, raise tickets and create incident reports.

Related Threats

IDTitleDescription
CCC.Monitor.TH06Cost Exhaustion Through Tampered Alerts or Metrics CollectionMonitoring systems are expected to generate traffic, but it a malicious actor were to change alerts that were being fired at an API which charged per requests or generate large volumes of metric data which would then need to be stored and processed, or even triggering resource scaling, this would cause an increase in cloud bill.

Assessment Requirements

IDTextApplicability
CCC.Monitor.CN02.AR01When an Custom or User-Defined Metric starts to flood a collector, then a rate limit MUST be applied to reduce the network impact of traffic and an alert must triggered.tlp-clear, tlp-green, tlp-amber, tlp-red

Guideline Mappings

FrameworkIDRemarks
NIST-CSFDE.CM-01
NIST_800_53SC-5(2)
NIST_800_53CA-7
NIST_800_53SI-4