Analyzing the CoAP DDoS Amplification Attack Ecosystem: A Honeypot Study

Deploying the First CoAP-Specific Amplification Honeypot

Bachelor Thesis (2026)
Author(s)

A. Kalpakchiev (TU Delft - Electrical Engineering, Mathematics and Computer Science)

Contributor(s)

H.J. Griffioen – Mentor (TU Delft - Electrical Engineering, Mathematics and Computer Science)

M.J.G. Olsthoorn – Graduation committee member (TU Delft - Electrical Engineering, Mathematics and Computer Science)

Faculty
Electrical Engineering, Mathematics and Computer Science
More Info
expand_more
Publication Year
2026
Language
English
Graduation Date
23-06-2026
Awarding Institution
Delft University of Technology
Project
CSE3000 Research Project
Programme
Computer Science and Engineering
Faculty
Electrical Engineering, Mathematics and Computer Science
Downloads counter
16
Reuse Rights

Other than for strictly personal use, it is not permitted to download, forward or distribute the text or part of it, without the consent of the author(s) and/or copyright holder(s), unless the work is under an open content license such as Creative Commons.

Abstract

DDoS amplification attacks exploit connectionless protocols to overwhelm victims
with traffic far exceeding the attacker's own bandwidth. The Constrained Application
Protocol (CoAP), designed for IoT devices, has emerged as an amplification vector
with over 1.7 million exposed reflectors and an amplification factor of approximately
34x, yet no prior work has studied CoAP amplification through honeypot-based
observation. We hypothesize that CoAP's extreme reflector instability - 80\% of
IP addresses change within two weeks - imposes a higher sophistication floor on
adversaries compared to previously studied protocols. To evaluate this, we deploy
the first CoAP-specific amplification honeypot with eight protocol configurations
testing blockwise transfer at four block sizes and rate limiting at three thresholds
across 18 IP addresses for 23 days. The scanning traffic reveals behaviors
undocumented in prior honeypot research: multi-phase CBOR fingerprinting that
distinguishes genuine Eclipse Californium devices from other implementations,
sustained reliability validation over repeated scanning cycles, and efficient list
management where probing ceases after device cataloguing. Notably, our honeypot was
likely filtered out after failing this fingerprinting test - a finding that
contrasts sharply with prior work on other protocols, where attackers were largely
indifferent to honeypot responses. No amplification attacks were observed, preventing
empirical evaluation of the tested defenses. However, our
findings provide the first evidence that CoAP's structural properties demand higher
adversary sophistication than previously studied amplification protocols, and suggest
that threat models for CoAP must account for fingerprinting-capable actors.

Files

Research-paper-template.pdf
(pdf | 0.297 Mb)
License info not available