AWS Shield
View on GitHubAWS Shield
AWS Shield is a managed DDoS protection service that provides automatic detection and mitigation of distributed denial-of-service attacks against AWS-hosted resources. It operates in two tiers: Shield Standard (broad, no-cost protections for common network and transport layer attacks) and Shield Advanced (paid subscription with additional detection, mitigation controls, and operational support). Shield normally sits at AWS edge and regional entry points to protect services such as Amazon CloudFront, Elastic Load Balancing, and Amazon Route 53.
🗂 Resource Category
Security, Identity, and Compliance • Networking and Content Delivery
🧠 Exam Memory Hook
Think: Protect internet-facing endpoints from DDoS at AWS edge and regional entry points = AWS Shield
📖 Ownership
Classification: AWS Managed Service
AWS responsibilities: AWS operates and maintains the Shield control plane and mitigation infrastructure, detects attacks against protected AWS resources, and delivers network- and transport-layer mitigation capability. For Shield Advanced, AWS provides attack diagnostics and access to the DDoS Response Team when the customer has subscribed and enrolled resources. AWS is responsible for the underlying physical infrastructure and the Shield service platform availability and updates.
Customer responsibilities: The customer configures which resources are enrolled (required for Shield Advanced), configures mitigation preferences and AWS WAF rules where applicable, monitors alerts and metrics, integrates Shield with incident response workflows, and implements application- and network-level hardening. The customer remains responsible for the security of their applications, including OS and application patching, access control, and any custom remediation automation.
Patching responsibilities: AWS patches and maintains the physical infrastructure and the Shield managed service platform. There is no guest operating system or customer runtime in the Shield control plane to patch. The customer patches guest operating systems, application runtimes, libraries, dependencies, and customer-deployed applications running on their compute resources that Shield protects.
🏗 Typical Architecture
💡 Top 5 Features
- Automatic network- and transport-layer DDoS detection and mitigation for frequently observed attack types (Shield Standard).
- Additional detection, mitigation controls, and attack diagnostics when resources are enrolled under Shield Advanced.
- Integration points with AWS WAF and Amazon CloudFront to coordinate application-layer protections and edge delivery.
- Access to the DDoS Response Team (DRT) and advanced operational support for subscribed Shield Advanced customers.
- Attack visibility and metrics surfaced through Amazon CloudWatch and Shield Advanced attack diagnostics.
✅ Top 5 Use Cases
- Protecting edge-distributed content and APIs served through Amazon CloudFront from volumetric and transport-layer DDoS attacks.
- Protecting DNS infrastructure hosted in Amazon Route 53 from high-volume query floods and abusive traffic patterns.
- Protecting load-balanced web applications behind Elastic Load Balancing to reduce network-layer disruption during attacks.
- Providing dedicated operational support and diagnostic information for business-critical applications by subscribing to Shield Advanced.
- Combining Shield with AWS WAF to address both network/transport-layer attacks and application-layer threats in a layered defence.
🏗 Architecture Placement
AWS Shield operates at AWS edge and regional ingress points to monitor and mitigate DDoS traffic destined for AWS resources; internet traffic to services such as Amazon CloudFront, Elastic Load Balancing, and Amazon Route 53 is evaluated by Shield protections. Shield is an account- or resource-level protection service requiring enrolment for Advanced features and integrates with monitoring and policy controls in the same AWS account or organization. Placement depends on which resources are protected and whether Shield Standard or Shield Advanced is used.
🎯 Commonly Used With
- Amazon CloudFront
- Amazon Route 53
- Elastic Load Balancing
- AWS WAF
- Amazon CloudWatch
🌍 5 Real-World Examples
- A bank enrolls public-facing API endpoints under Shield Advanced to obtain additional mitigation controls and operational support for online banking services.
- An e-commerce retailer uses Shield protections for CloudFront and ELB during high-traffic promotional events to reduce service disruption risk.
- A media streaming provider relies on Shield and CloudFront to protect CDN endpoints from volumetric attacks that could interrupt content delivery.
- A gaming company protects login and matchmaking endpoints behind Elastic Load Balancing and uses Shield Advanced for faster diagnostics during attack events.
- A government portal protects public web endpoints and DNS using Shield Standard and integrates alerting into incident response runbooks.
🎓 AWS Exam Clues
- Shield provides managed DDoS mitigation; Shield Standard is automatically available for supported AWS services and resources.
- Choose Shield Advanced when a requirement specifies dedicated DDoS mitigation support, detailed attack diagnostics, or access to the DRT.
- Use Shield in combination with AWS WAF to handle both network/transport-layer DDoS and application-layer threats in a layered defence.
- Shield protections are applied at AWS edge and regional entry points; resource enrolment is required for Advanced features and diagnostics.
- Monitoring and alerts for Shield are exposed through Amazon CloudWatch and should be integrated into incident response automation.
📝 Quick Revision
AWS Shield is AWS’s managed DDoS protection service with Shield Standard for common automatic protections and Shield Advanced for subscription-based enhanced mitigation, diagnostics, and DRT support. Use Shield where internet-facing AWS resources require DDoS mitigation and integrate with AWS WAF and CloudWatch; the customer remains responsible for enrolling resources, monitoring, and application-level security.
🏷 Keywords
DDoS protection • Shield Standard • Shield Advanced • DDoS Response Team • DDoS cost protection • attack diagnostics • protection groups • network-layer mitigation • transport-layer attacks • integration with AWS WAF • edge protection • Amazon CloudWatch metrics