Modern Internet of Things environments use lightweight communication protocols to exchange telemetry, commands, and resource information between constrained devices and backend services. The Constrained Application Protocol (CoAP) is designed for such environments, and Eclipse Californium provides a Java-based CoAP framework for building IoT services and applications. Californium supports CoAP features and provides configurable protocol and resource-management controls.
A CoAP request-flooding attack occurs when a large number of requests are generated against an IoT service within a short period. The objective of the controlled attack is to increase request-processing activity and consume available protocol or application resources, such as processing threads, peer state, exchanges, blockwise-transfer state, or application memory.
Californium provides several resource-protection controls. Its CoAP configuration includes controls for maximum active peers, maximum peer inactivity period, maximum message size, maximum resource-body size, blockwise status lifetime, server-side observe limits, exchange lifetime, and related protocol state. These controls can reduce the amount of state and data that a CoAP service is required to maintain.
In this use case, a controlled Eclipse Californium CoAP server is deployed on Ubuntu Linux inside an isolated VirtualBox laboratory. A synthetic IoT resource is created to represent a realistic sensor or device-management endpoint. Kali Linux is used as the controlled security-testing platform to generate a repeatable burst of CoAP requests against the laboratory Californium service. The testing remains restricted to the authorized laboratory network.
A request-rate enforcement layer is implemented before resource processing so that excessive requests from a controlled source can be identified and restricted. The Californium server is additionally configured with protocol resource controls such as maximum active peers, maximum message size, maximum resource-body size, peer inactivity limits, blockwise-transfer limits, and server-side observe limits where applicable.
The security workflow therefore uses two complementary protection layers: request-rate enforcement controls how frequently a client is allowed to generate requests, while protocol resource controls restrict the amount of state, message data, peer state, blockwise state, and observation state that the Californium service can maintain.
Wazuh monitors the Ubuntu host and relevant Californium activity, while OpenSearch provides centralized investigation and correlation of request-flooding events. The controlled flooding test is performed first against the baseline configuration and then repeated after the defensive controls are implemented. The objective is to verify that excessive request activity is detected and restricted while legitimate CoAP requests continue to operate normally.
Complete IoT Cyber Security Workflow : CoAP Client → Eclipse Californium IoT Service → Request Processing → Request-Rate Measurement → Excessive Request Detection → Rate Enforcement → Protocol Resource Controls → Excessive Request Restriction → Security Event Logging → Wazuh Monitoring → OpenSearch Investigation → Remediation → Post-Remediation Validation