Summary

  • Revision 01 of the BMP Statistics Information TLV adds a measurement-window duration, sample count, P5 and P95 values, a timestamp-presence flag and microsecond timestamps for minima and maxima.
  • Those fields reveal variation hidden by endpoint snapshots, but they do not reconstruct the sample sequence, time spent at a value or the moment a collector could first act. A summary is stronger evidence than a snapshot and still weaker than an event history.

At noon, a collector receives a route count of 10,000. Fifteen minutes later, it receives 10,000 again. The old view says the Adj-RIB-In was stable. The new Statistics Information TLV can report that the router actually observed a minimum of 8,000, a maximum of 15,000 and an average somewhere between them. It can attach an observation time to the minimum and maximum.

That is a material improvement. It is not a replay of the quarter hour.

The same exported summary can describe a one-second burst to 15,000 followed by immediate recovery, a ten-minute plateau near the maximum, repeated oscillation, or a surge that occurred before rather than after the fall to 8,000. The minimum and maximum have timestamps. The average, median, P5 and P95 do not. Sample Count provides a denominator, not an ordering. Measurement Window Duration provides a span, not dwell time.

This is the decisive boundary in revision 01 of BMP Statistics Information TLV. The revision was uploaded on 11 September 2026 and expires on 15 March 2027. It is a GROW Working Group Internet-Draft in I-D Exists. Its masthead says Standards Track, while Datatracker's Intended RFC status is blank. No document shepherd, responsible area director or telechat is recorded. Its new registries and type remain IANA requests with TBD1, not assigned code points. The document supplies no implementation report, interoperability trace or production measurement.

Revision 01 adds the missing denominator

RFC 7854 defines BMP Statistics Reports, but a periodic gauge snapshot can miss everything that happened between messages. The draft's motivating example uses Stat Type 7, the number of routes in Adj-RIB-In. A collector sees 10,000 at T0, T15, T30 and T45 and might reasonably infer stability. Inside one reporting period, however, the route count may have reached 15,000 and fallen to 8,000 before returning to 10,000.

Revision 00 proposed minimum, maximum, snapshot, average and median entries. Revision 01 substantially sharpens the evidence. The TLV now carries a 32-bit Measurement Window Duration in seconds and a 32-bit Sample Count. It adds P5 and P95. It replaces a reserved byte with flags, using the T bit to say whether an entry includes a timestamp. Minimum and maximum must carry timestamps in seconds and microseconds since 1970 UTC; snapshot, average, median, P5 and P95 must not.

The sample count matters twice. A small sample population weakens the representativeness of derived values such as average and percentiles. It also reduces the chance that periodic observation caught the true extrema between sample instants. A reported maximum is therefore the greatest observed sample, not proof that no higher value occurred.

The window matters too. It can differ from the Statistics Report transmission interval, for example after an event-triggered report or a newly established session. A sender needing different windows for the same referenced statistic must use separate Information TLVs. The first report after session establishment or peer transition may omit the TLV or use partial data.

Compression preserves distribution and discards chronology

The format deliberately compresses a series into selected properties. Consider fifteen one-minute samples. Window A stays near 10,000 for thirteen minutes, spikes to 15,000 for one sample and falls to 8,000 for one. Window B begins at 15,000, descends through the same multiset of values and ends at 8,000. Rearrange the samples and the minimum, maximum, average, median, P5, P95 and count can remain identical. Operational narratives do not.

Order determines whether a routing surge preceded a withdrawal wave, whether recovery followed mitigation and whether two symptoms were causally plausible. Dwell time determines whether a threshold excursion was a transient or the dominant state. Neither follows from a percentile alone. Timestamps on extrema anchor two points; they do not order every value between them or tell how long the system remained close to either extreme.

That limitation is not a flaw hidden by the draft. Revision 01 says average and percentiles depend on the sample population, that collection may be periodic, event-driven or hybrid, and that percentile algorithms such as nearest-rank and linear interpolation can disagree even on identical samples. It also says the document does not export the configuration or internal methodology that produced the values. Comparisons across routers require compatible measurement-window and collection configurations established elsewhere.

The important editorial distinction is that methodology differences are not this Article's central thesis. Even with identical sampling, identical clocks and the same percentile algorithm, a distribution summary cannot recover the order of a discarded series. Configuration compatibility makes numbers comparable; it does not recreate time.

A timestamp records observation, not incident duration

For minimum and maximum, the sender should report the actual observation time rather than message-generation time. This helps a collector place an extreme earlier in the reporting period. Precision and accuracy, however, depend on the router's clock resolution and timekeeping. Transport protection cannot repair a wrong clock.

Nor does the timestamp reveal when the underlying condition began. If samples arrive once a minute and the maximum is observed at 12:08, the route count may have crossed the threshold at 12:07:01 or 12:07:59. It may have fallen one second after the observation or remained elevated until the next sample. “Maximum at 12:08” is one witnessed point, not a start time, end time or duration.

The reporting interval adds another clock. The mechanism permits longer intervals to reduce messages and collector load while keeping a faster internal sampling rate. An extreme observed at 12:01 may reach the collector at 12:15. The event timestamp partly restores historical placement, but it does not make the alert timely. Evidence time, report-generation time, transport time, collector-receipt time and operator-action time must remain separate.

The parser still needs exact context

The TLV references a valid BMP gauge Stat Type. It must not describe a monotonically increasing counter; a receiver should ignore and may log such misuse. Unknown Entry Types can be skipped because the T bit determines whether an entry occupies 10 or 18 bytes. Duplicate Entry Types after the first should be ignored and may be logged.

For Stat Types 9 and 10, which carry per-AFI/SAFI meaning, the Information TLV does not include that address-family identity itself. The sender must include the corresponding ordinary statistic TLV with the same AFI/SAFI in the same report. Without it, the collector cannot know which address family the distribution describes, making the summary unusable.

When both an ordinary snapshot statistic and the Information TLV appear, the snapshot should fall between the reported minimum and maximum. When the Information TLV appears alone, the sender should include its Snapshot entry. These are useful consistency tests. They prove neither that every sample was correct nor that the monitored router was honest.

BMP does not cryptographically authenticate the statistics themselves. TLS or IPsec can protect the session, and connection authentication can identify the speaker, but a compromised monitored router can still emit false summaries. The richer TLV also increases message size and state cost; rate limiting and resource management remain necessary.

Preserve a narrow trace around consequential summaries

Heng Lu's minimum-initial-specification doctrine supports the draft's restraint. An interoperable envelope for referenced metric, window, denominator and common summaries is valuable even when vendors keep different collection machinery. Running-code primacy asks for additional evidence where a compressed value becomes an alert, change request or automated mitigation.

For consequential thresholds, retain a bounded local ring of raw samples or events around the crossing. Record window start and end, sampling mode and cadence, percentile algorithm, clock source and observed offset, report-generation time, collector-receipt time, configuration generation and exact TLV bytes. Compare summary-driven alerts with the retained trace before lengthening the reporting interval.

Those are operational recommendations, not requirements in revision 01. They need not be standardized into every BMP message. Their purpose is to keep an operator from treating a faithful summary as a complete history.

The new TLV can overturn a false claim of stability. It cannot, by itself, explain the incident that produced the distribution. A timestamped peak is evidence that one value was observed. Leadership still needs the missing sequence before it assigns cause, duration or accountability.

Sources