Skip to main content

Attacks on the Constrained Application Protocol (CoAP)
draft-ietf-core-attacks-on-coap-06

Document Type Expired Internet-Draft (core WG)
Expired & archived
Authors John Preuß Mattsson , John Fornehed , Göran Selander , Francesca Palombini , Christian Amsüss
Last updated 2025-12-26 (Latest revision 2025-06-24)
Replaces draft-mattsson-core-coap-attacks
RFC stream Internet Engineering Task Force (IETF)
Intended RFC status (None)
Formats
Additional resources Working Group Repo
Mailing list discussion
Stream WG state WG Document
Document shepherd (None)
IESG IESG state Expired
Consensus boilerplate Unknown
Telechat date (None)
Responsible AD (None)
Send notices to (None)

This Internet-Draft is no longer active. A copy of the expired Internet-Draft is available in these formats:

Abstract

Being able to securely retrieve information from sensors and control actuators while providing guards against distributed denial-of- service (DDoS) attacks are key requirements for CoAP deployments. To that aim, a security protocol (e.g., DTLS, TLS, or OSCORE) can be enabled to ensure secure CoAP operation, including protection against many attacks. This document identifies a set of known CoAP attacks and shows that simply using CoAP with a security protocol is not always enough for secure operation. Several of the identified attacks can be mitigated with a security protocol providing confidentiality and integrity combined with the solutions specified in RFC 9175.

Authors

John Preuß Mattsson
John Fornehed
Göran Selander
Francesca Palombini
Christian Amsüss

(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)