New issue
Advanced search Search tips

Issue 638871 link

Starred by 1 user

Issue metadata

Status: Fixed
Owner:
Closed: Aug 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: All
Pri: 2
Type: Bug



Sign in to add a comment

Add UMA metric for Expect-CT headers observed

Project Member Reported by est...@chromium.org, Aug 18 2016

Issue description

Currently we have UMA metrics for Expect-CT report-sending attempts, but no UMA metric for when a client sees an Expect-CT header and decides not to send a report.

It would be useful to know how often clients are seeing Expect-CT headers for sites on the preload list and deciding *not* to send a report. This will help us estimate a worst case load we can expect on the report collection server.
 
Project Member

Comment 1 by bugdroid1@chromium.org, Aug 27 2016

The following revision refers to this bug:
  https://chromium.googlesource.com/chromium/src.git/+/d7ef7ecd31c1a7a6cbbe054445e96ca5130a0f1d

commit d7ef7ecd31c1a7a6cbbe054445e96ca5130a0f1d
Author: estark <estark@chromium.org>
Date: Sat Aug 27 16:43:09 2016

Add UMA histogram for Expect-CT header processing

This CL adds a histogram to record the result of processing an Expect-CT
header. (An Expect-CT header tells Chrome that the site wants to receive
reports whenever a connection does not comply with Chrome CT policy.)

For example, a header might be received but thrown out because the site
was not on the preload list, or it might be ignored because the site
complied with the CT policy. This histogram will help us sanity-check
server-side metrics. (In particular, we aren't receiving any reports --
we'd like to sanity check that that is because Chrome users are always
getting CT-compliant connections, and not because there is a bug in
report-sending or Expect-CT header-serving.) This will also give us an
easy way to estimate worst-case traffic on the report collection server
(if we know how many users are seeing Expect-CT headers, we can estimate
the number of reports that would be sent if a large-scale
misconfiguration made an Expect-CT site non-compliant.)

BUG= 638871 

Review-Url: https://codereview.chromium.org/2272323004
Cr-Commit-Position: refs/heads/master@{#414940}

[modify] https://crrev.com/d7ef7ecd31c1a7a6cbbe054445e96ca5130a0f1d/net/http/transport_security_state.cc
[modify] https://crrev.com/d7ef7ecd31c1a7a6cbbe054445e96ca5130a0f1d/tools/metrics/histograms/histograms.xml

Comment 2 by est...@chromium.org, Aug 27 2016

Labels: M-55
Status: Fixed (was: Assigned)

Sign in to add a comment