Skip to main content

Management / Monitoring / Threats / DEV

Cost Exhaustion Through Tampered Alerts or Metrics Collection

CCC.Monitor.TH06

Monitoring systems are expected to generate traffic, but it a malicious actor were to change alerts that were being fired at an API which charged per requests or generate large volumes of metric data which would then need to be stored and processed, or even triggering resource scaling, this would cause an increase in cloud bill.

Related Capabilities

IDTitleDescription
CCC.Monitoring.CP01CCC.Monitoring.CP01
CCC.Monitoring.CP11CCC.Monitoring.CP11

Related Controls

IDTitleDescription
CCC.Monitor.CN02Rate Limiting on Metric GenerationPrevent Malicious Actor or misconfiguration from flooding services with metric data.

External Mappings

FrameworkIDRemarks
MITRE-ATT&CKT1565Data Manipulation