Loading…
While this loads — worth knowing
Redis has data structures — sorted sets, counters, pub/sub. Memcached has plain keys and nothing else.
Loading…
While this loads — worth knowing
Redis has data structures — sorted sets, counters, pub/sub. Memcached has plain keys and nothing else.
DDoS protection: Shield Standard guards every AWS customer against common network and transport layer attacks at no extra charge, and Shield Advanced adds more for the resources you choose.
Where Shield takes you5 steps, all open
AWS Shield protects applications against distributed denial of service (DDoS) attacks at their perimeter: the first place traffic from outside enters. For users sent through Route 53 to CloudFront or Global Accelerator, that is the edge of the AWS network; for anything reached directly in a Region, it is your VPC.
Standard for everyone, Advanced by choice. Shield Standard is automatic, at no extra charge, and defends against the most common network and transport layer attacks. Shield Advanced is a subscription that adds application layer protection, the Shield Response Team, and credits for bills an attack runs up.
A city's flood defences. Every street has the river walls, built for the floods that come every year, and nobody pays extra for them. A waterfront district can pay for more: extra barriers, an engineering crew on call day and night, and a promise to cover the pumping bill if a flood gets through.
Shield StandardShield AdvancedShield Response TeamCost protectionWAF web ACLPerimeterIs it one of the common network or transport layer attacks, such as a flood of packets? Standard stops those for every customer.
Does a rule in the web ACL match the request, such as a rate-based rule for one address sending too many?
On a resource Advanced protects, with automatic mitigation on, is the request part of an application layer attack Advanced has detected?
Can the servers take whatever gets this far?
Pick a case to follow the traffic through each check.
Move the perimeter to the edge. With users sent by Route 53 to CloudFront, the perimeter begins at the edge of the AWS network, where Standard gives its fullest protection.
Advanced on each way in. Protect the distribution, the hosted zone and the load balancer; a protection group treats them as one application for detection and mitigation.
Health checks speed things up. Route 53 health checks on protected resources make detection faster, and proactive engagement, where the SRT contacts you, needs them.
The right support plan. Working with the Shield Response Team needs Shield Advanced and the Business or Enterprise Support plan.
What they can do. Analyse your WAF logs and, with your approval, change the web ACL; write custom network mitigations; and recommend changes to the architecture.
Proactive engagement. If a protected resource's health check turns unhealthy during an event Advanced has detected, the SRT contacts you directly.
Across accounts. Firewall Manager can apply Shield Advanced protections to new accounts and resources automatically, and its Shield Advanced policies cost Advanced customers nothing extra.
Shield Standard costs nothing extra.
Shield Advanced is a monthly fee with a one-year commitment, billed to the organization's payer account; one fee covers the subscribed accounts that the organization owns.
Data transfer out usage fees for Advanced, by protected resource type: EC2, Elastic Load Balancing, CloudFront and Global Accelerator.
WAF is included for protected resources: web ACLs, rules and up to 50 billion requests a month, but not Bot Control, CAPTCHA, or more than 1,500 WCUs.
Cost protection arrives as Shield Advanced service credits for the spikes an attack causes.
Prices change, so none are printed here. Check the Shield pricing page on aws.amazon.com.
| Feature | Shield Standard | Shield Advanced |
|---|---|---|
| Cost | No extra charge | Monthly fee, one-year commitment |
| Turned on | Automatically, for everyone | By subscribing, then adding resources |
| Layers | 3 and 4 | 3, 4 and 7 |
| Resources | All; fullest at Route 53, CloudFront, Global Accelerator | EC2, ELB, CloudFront, Route 53, Global Accelerator |
| Expert help | Your usual support plan | The SRT, with Business or Enterprise Support |
| An attack's bill | Yours | Service credits for attack-driven spikes |
| Service | Protects against | Choose it when |
|---|---|---|
| Shield | DDoS attacks | Staying up under a flood |
| WAF | Requests that match your rules | Blocking exploits, bad addresses and too many requests |
| Firewall Manager | Protection that differs from account to account | The same WAF and Shield setup in every account |
DDoS protection at no additional costShield Standard
It is automatic for every AWS customer.
24/7 access to DDoS experts during an attackShield Advanced with Business or Enterprise Support
The Shield Response Team needs both.
cover the scaling charges a DDoS attack causedShield Advanced cost protection
It gives service credits for the spikes an attack causes.
mitigate an application layer DDoS attack automaticallyShield Advanced automatic mitigation
It adds and manages WAF rules against the attack, using 150 WCUs of the web ACL.
Advanced protection for EC2 instances and load balancers, not just the edgeSupported
Advanced covers EC2, Elastic Load Balancing, CloudFront, Route 53 and Global Accelerator.
stop SQL injection attemptsWAF, not Shield
Shield deals with floods, not with what a request contains.
Shield Advanced for every account in the organizationOne subscription fee
It covers the subscribed accounts in the consolidated billing family.
the SRT should call us when the site turns unhealthyProactive engagement
It needs a Route 53 health check on the protected resource.
WAF charges on resources Shield Advanced protectsThe standard ones are covered
Web ACLs, rules and inspection up to 1,500 WCUs are; Bot Control and CAPTCHA are not.
A news company's site on CloudFront and an Application Load Balancer is hit by large DDoS attacks several times a month. It wants specialists to help during attacks, automatic mitigation of application layer floods, and protection from the charges the attacks cause. What should a solutions architect recommend?
A news site on CloudFront and a load balancer is hit by large DDoS attacks every month. The company wants attacks mitigated at every layer, specialists to call at any hour, and protection from the charges an attack runs up. What protects the distribution?
3 and 4.3, 4 and 7.This whole page is free right now.The AWS library is still being written, so every page of it is open to everyone while that lasts. It becomes a paid bundle later; what you read today costs you nothing.
Every fact on this page was checked against AWS’s own documentation on 15 Sept 2026. If AWS has changed something since, its page is the one to trust.