Skip to main content

Networking / Loadbalancer / Threats / DEV

Health Checks Are Exploited to Take Services Offline

CCC.LB.TH05

Manipulating health-check endpoints or responses can cause healthy targets to be marked unavailable, leading to denial of service.

Related Capabilities

IDTitleDescription
CCC.LB.CP12Target Health ChecksAbility to continuously perform health checks on backend backend targets in form of checking the response to HTTP request, TCP connection or checking other application-specific parameter
CCC.LB.CP13Health Checks-based Target RemovalIf the health check detects that a backend target is unhealthy the load balancer will remove that unhealthy target from its list of available backend instances. This ensures that traffic is no longer routed to the unhealthy target.

Related Controls

IDTitleDescription
CCC.LB.CN06Secure Health-Check TelemetryMonitor health-check endpoints for tampering and alert on abnormal status changes.

External Mappings

FrameworkIDRemarks
MITRE-ATT&CKT1499
MITRE-ATT&CKT1583