Skip to main content

Networking / Loadbalancer / Controls / DEV

Secure Health-Check Telemetry

CCC.LB.CN06 · Observability

Monitor health-check endpoints for tampering and alert on abnormal status changes.

Related Capabilities

IDTitleDescription
CCC.LB.CP12Target Health ChecksAbility to continuously perform health checks on backend backend targets in form of checking the response to HTTP request, TCP connection or checking other application-specific parameter
CCC.LB.CP13Health Checks-based Target RemovalIf the health check detects that a backend target is unhealthy the load balancer will remove that unhealthy target from its list of available backend instances. This ensures that traffic is no longer routed to the unhealthy target.

Related Threats

IDTitleDescription
CCC.LB.TH05Health Checks Are Exploited to Take Services OfflineManipulating health-check endpoints or responses can cause healthy targets to be marked unavailable, leading to denial of service.

Assessment Requirements

IDTextApplicability
CCC.LB.CN06.AR01When more than 10 percent of targets change from healthy to unhealthy within five minutes, an alert MUST be issued.tlp-green, tlp-amber, tlp-red

Guideline Mappings

FrameworkIDRemarks
NIST-CSFDE.AE-2Detected events are analyzed
NIST_800_53SI-4System monitoring