Skip to main content

Management / Monitoring / Controls / DEV

Rate Limiting on Metric Generation

CCC.Monitor.CN02 · Observability

Prevent Malicious Actor or misconfiguration from flooding services with metric data.

Related Capabilities

IDTitleDescription
CCC.Monitoring.CP01CCC.Monitoring.CP01
CCC.Monitoring.CP11CCC.Monitoring.CP11

Related Threats

IDTitleDescription
CCC.Monitor.TH06Cost Exhaustion Through Tampered Alerts or Metrics CollectionMonitoring systems are expected to generate traffic, but it a malicious actor were to change alerts that were being fired at an API which charged per requests or generate large volumes of metric data which would then need to be stored and processed, or even triggering resource scaling, this would cause an increase in cloud bill.

Assessment Requirements

IDTextApplicability
CCC.Monitor.CN02.AR01When an Custom or User-Defined Metric starts to flood a collector, then a rate limit MUST be applied to reduce the network impact of traffic and an alert must triggered.tlp-clear, tlp-green, tlp-amber, tlp-red

Guideline Mappings

FrameworkIDRemarks
NIST-CSFDE.CM-01
NIST_800_53SC-5(2)
NIST_800_53CA-7
NIST_800_53SI-4