Summary

  • Revision 15 of the IETF collected-data-manifest draft now identifies current-period, the effective interval between periodic updates, as a potentially sensitive readable value. It says exposure of the collection schedule could help an attacker time activity around collection gaps.
  • The same revision separates controls on a NETCONF/RESTCONF read from controls on retained copies in a time-series database. A 24 September security review judged those concerns adequately addressed in the draft; it did not approve a standard or verify any deployment.

There is a reason to publish the interval at which a network instrument actually reports. A subscription might ask for one cadence while an overloaded device quietly lengthens it. Without the effective current-period, an analyst could misread that slower stream as packet loss or a software fault. The manifest gives the data its operational context. But context is useful to more than the intended analyst. A reader who can see the interval may also learn when observations are sparse.

That double use is the significant change in draft-ietf-opsawg-collected-data-manifest-15. Revision 14 already defined and explained the current-period node; the field is not new. Its security section, however, said there were no particularly sensitive readable nodes in that module. Revision 15 replaces that conclusion with an explicit warning: the effective period can expose the collection schedule, and someone who learns when collection is not occurring could try to place malicious activity between collections to reduce the chance of detection. This is a prospective threat described by the draft, not an account of a successful attack.

An interval is not an omniscient map of a network's blind spots. The value alone does not prove that every sensor stops watching between updates, nor does it necessarily disclose the phase of each sampling cycle. What an outsider can infer depends on other timing clues, the actual collection design and which metadata the outsider can read. The draft's narrower point still matters: a measurement field used to interpret a dataset can become a disclosure field when handed to the wrong reader.

The version history explains why this belongs in a security story rather than a second article about missing samples. A Security Area Directorate review of revision 14 on 1 September flagged collection-period sensitivity, questioned whether generic access filters would exist in every receiving system and urged operators not to send sensitive metadata indiscriminately. Revision 15's security section addresses those concerns. A follow-up review completed on 24 September returned “Ready” and said the issues around platform and collection-time disclosure had been addressed adequately. That is a reviewer's judgment about draft text.

The live Datatracker still shows an active Internet-Draft intended for Proposed Standard and an IESG state of Waiting for AD Go-Ahead, not an RFC.

The draft now describes two different control planes for the same metadata. For YANG-based management reads over NETCONF or RESTCONF, secure transport, mutual authentication and the Network Configuration Access Control Model can restrict who sees data nodes. Once manifests and samples are copied into a downstream time-series database, that management-plane permission boundary is no longer the whole story. A store may offer only coarse permissions, or none suitable for these fields. The text advises using whatever controls the store provides and withholding a metadata item altogether when its disclosure would be sensitive in that deployment.

A signed manifest may help establish integrity or provenance, but signing does not stop an authorized or poorly controlled reader from learning the cadence.

This distinction is operationally concrete. The collector needs enough context to explain why a stream slowed. An investigation system may need the same period history. A broad dashboard, data export or retained archive may not need to expose it to every user. The decision is not simply whether telemetry should be collected; it is which audience receives which part of the context, at collection time and after copying. Earlier BTW coverage of this draft asked whether a manifest could account for datapoints that never arrived. Here the question is what successfully retained metadata can reveal.

Sources