[RSSAC Caucus] 48 HOUR LAST CALL : RSSAC002v4

Ray Bellis ray at isc.org
Fri Feb 21 10:59:48 UTC 2020


On 21/02/2020 10:34, Andrew McConachie wrote:

> Hi Ray,
> 
> Thanks for raising this concern.
> 
> The following text is in this section in RSSAC002v3: "This set of
> metrics is marked as optional for a 3-year period following the
> acceptance and publication of version 1 of this document by RSSAC. As
> experience grows with fine-grained reporting from many operational
> root-server instances these values can be phased in over this 3-year
> period. In case experience shows that these values provide little
> value overall, or constitute a memory exhaustion attack upon
> monitoring infrastructure, an amendment should be issued by RSSAC to
> deprecate the documented collection of this data.”
> 
> The above paragraph and the metric num-sources-ipv6 have been removed
> from section 3.5 in the draft of RSSAC002v4.
> 
> If the Caucus would like the collection of num-sources-ipv4 and
> num-sources-ipv6-aggregate to become optional I recommend a single
> sentence at the end of the section. Something like, “The collection
> of these two values is optional.”

I'm fine with the removal of the individual IPv6 source count.

However it's unclear whether these figures actually do provide any
value, and they are not that easy to collate.

Roughly, the process we have at ISC is that each instance (where
possible) runs a custom-written daemon that records the unique IPs seen
in each one hour interval, and then submits that to a central collector
over HTTPs.  A daily process then reads in every one of those files
(thousands of them!) to determine the union of those data sets.

> Then in section 6.6 we will need some way to distinguish between
> num-sources-* with zero counts, and num-sources-* that are not being
> collected. Suggestions are welcome.

The particular issue I have is not that they are not collected, but that
we are only able to report a figure from a subset of our nodes.

However I would rather not be collecting the data at all if there's no
value to it.

Ray



More information about the rssac-caucus mailing list