IoT Devices Using CoAP Increasingly Used in DDoS Attacks

GlobalDots
1 Min read

IoT devices in synchronised attacks on targets represent a growing part of global Distributed Denial of Service (DDoS) weapon arsenals. There is a significant potential for attackers to use an IoT-related protocol, the Constrained Application Protocol (CoAP), deployed on IoT devices to marshal attacks.

The A10 Networks report on the state of DDoS weapons in the first quarter of 2019 examines the types of weapons and attacks being used and where they are coming from. While the most prevalent types of weapons leverage other more established technologies and internet protocols, such as the Network Time Protocol (NTP), Domain Name System (DNS) resolvers, and the Simple Services Discovery Protocol (SSDP), CoAP-based devices represent a fast-emerging new weapon type in botnet arsenals.

The most common type of attack utilising many of these weapons is a reflective amplification attack through which attackers spoof a target’s IP address and send out requests for information to vulnerable servers that then send amplified responses back to the victim’s IP address overwhelming the capacity of the target’s servers.

CoAP is a lightweight machine-to-machine (M2M) protocol that can run on smart devices where memory and computing resources are scarce. From a DDoS perspective CoAP is a protocol which is implemented for both TCP and UDP and does not require authentication to reply with a large response to a small request. The latest A10 Networks report found that over 400,000 of the weapons are being used in attacks.

Read more: Help Net Security

Latest Articles

Navigating The Stormy Seas of Cloud Storage: Slash Cloud Storage Costs by 70% with GlobalDots’ Curated Autoscaler

Imagine navigating your digital ship through the turbulent seas of cloud storage management. One wrong calculation, and you’re either sinking under the weight of overprovisioning or losing speed due to performance hiccups. But what if there was a compass that could make this voyage smooth sailing? GlobalDots presents you with an Autoscaler that’s revolutionizing the […]

GlobalDots
28.09.23
Clarity in the Clouds: Innovative Solutions for Aviation

In the competitive world of aviation, where alliances are often forged with rivals, and competitors share skies as partners – GlobalDots is your co-pilot in navigating clouds of looming threats. Now, we are introducing our new e-book, which explores our curated innovative solutions for Aviation, including: Nowadays, where buying a ticket is just the beginning […]

Dr. Eduardo Rocha Senior Solutions Engineer & Security Analyst @ GlobalDots
21.09.23
FinOps vs DevOps: Key Differences and What Each Role Requires

Before widespread cloud adoption, the cloud’s major selling point was a reduction in computing costs. Today, however, many organizations find themselves mired in increasingly costly and complex cloud environments, even forcing industry leaders such as Nvidia back toward on-prem setups. The priorities upheld by DevOps throughout the last decade have played a major role in […]

GlobalDots
19.09.23

Unlock Your Cloud Potential

Schedule a call with our experts. Discover new technology and get recommendations to improve your performance.

Unlock Your Cloud Potential