5.3 AWS Shield Advanced & DDoS Defense Architectures

Key Takeaways

  • AWS Shield Standard provides automatic, perimeter Layer 3 and Layer 4 DDoS protection for all AWS customers at no cost, mitigating common volumetric attacks like SYN floods, UDP reflection, and packet fragmentation.

  • AWS Shield Advanced offers comprehensive Layer 3, 4, and 7 DDoS defense for Route 53 hosted zones, CloudFront distributions, Elastic IPs, ALBs, and AWS Global Accelerator, backed by 24/7 access to the AWS Shield Response Team (SRT).

  • SRT help requires Business or Enterprise Support and an access role that trusts drt.shield.amazonaws.com with the AWSShieldDRTAccessPolicy managed policy; WAF logs come with that access, and up to 10 extra unencrypted or SSE-S3 log buckets can be shared.

  • Automatic Layer 7 DDoS mitigation analyzes traffic anomalies in real time, automatically authoring, testing, and deploying custom AWS WAF rules to block Layer 7 attacks without manual operational intervention.

  • Health-Based Detection pairs Route 53 health checks with Shield Advanced to eliminate false-positive mitigations during legitimate traffic spikes and trigger proactive outreach from the SRT when endpoint health degrades.

Last updated: September 2026

5.3 AWS Shield Advanced & DDoS Defense Architectures

Distributed Denial of Service (DDoS) attacks seek to exhaust system availability, saturate network bandwidth, consume connection tables, and deplete backend compute resources. In modern multi-tier cloud environments, attacks occur across different layers of the Open Systems Interconnection (OSI) model, ranging from massive multi-terabit volumetric Layer 3 and Layer 4 floods to subtle, application-specific Layer 7 query floods.

AWS delivers a layered defense model anchored by AWS Shield Standard and AWS Shield Advanced. For the AWS Certified Security – Specialty exam, security engineers must understand attack vector classifications, protected resource scopes, the mechanics of Automatic Layer 7 DDoS Mitigation, Health-Based Detection via Route 53, operational integration with the AWS Shield Response Team (SRT), and financial cost protection against scaling spikes.


DDoS Attack Taxonomy: Layer 3/4 vs Layer 7 Attacks

Effective DDoS mitigation requires diagnosing the specific OSI layer targeted by an adversary.

Loading diagram...

Infrastructure Layer Attacks (Layers 3 & 4)

  • UDP Reflection / Amplification: Attackers send spoofed requests with the victim's source IP address to publicly accessible third-party reflection servers (e.g., open NTP, DNS, CLDAP, or Memcached servers). The reflection servers return responses amplified by factors of 10x to 50,000x, saturating the victim's inbound internet connectivity.
  • SYN Floods: Attackers initiate vast numbers of TCP handshakes with spoofed IPs by sending SYN packets but never completing the three-way handshake with an ACK. This consumes the TCP state table and half-open connection buffers of edge firewalls and load balancers.
  • IP Packet Fragmentation: Attackers transmit overlapping, out-of-order, or malformed UDP/ICMP fragments to exhaust operating system defragmentation memory buffers.

Application Layer Attacks (Layer 7)

  • HTTP GET/POST Floods: Attackers submit high volumes of validly formed HTTP requests targeting CPU-intensive or database-heavy endpoints (e.g., dynamic reporting queries, PDF generation, or checkout processing). Because requests conform to standard TLS handshakes and HTTP protocols, Layer 3/4 firewalls cannot distinguish them from legitimate user traffic.
  • Slowloris / Slow POST: Attackers open thousands of HTTP connections and transmit request headers or payload bytes extremely slowly (e.g., 1 byte every 15 seconds). This keeps web server threads and connection sockets open indefinitely, preventing real users from connecting.

AWS Shield Standard vs AWS Shield Advanced

AWS provides two distinct tiers of DDoS defense:

Feature DimensionAWS Shield StandardAWS Shield Advanced
Subscription & PricingFree / Automatic. Enabled by default for all AWS customers worldwide.Paid Subscription: $3,000 per month per AWS Organization (requires a 1-year commitment), plus Shield data transfer out usage fees.
Layer 3 & 4 ProtectionComprehensive protection against standard volumetric infrastructure attacks (SYN floods, UDP reflection).Enhanced Layer 3 and 4 protection with automated packet scrubbing at AWS edge PoPs.
Layer 7 ProtectionNone. Shield Standard does not inspect or mitigate Layer 7 application attacks.Comprehensive Layer 7 defense integrated with AWS WAF, including automated rule synthesis.
Protected Resource TypesBorder infrastructure protecting all AWS services globally.Specific resources: CloudFront distributions, Route 53 hosted zones, Elastic IP addresses (EC2 and NLB), Application Load Balancers (ALBs), and AWS Global Accelerator.
DDoS Response Team (SRT)No access to the specialized SRT.24/7 direct access to the AWS Shield Response Team during active incidents.
Automated WAF RulesNot available.Automatic Layer 7 DDoS Mitigation: Generates and deploys WAF rules in real time.
Financial Cost ProtectionNone. Customers pay for scaling spikes incurred during attacks.Cost Protection: Customers can request billing credits for EC2, CloudFront, ALB, and Route 53 scaling charges caused by a verified DDoS attack.
Telemetry & ReportingBasic CloudWatch metrics (e.g., dropped packets on border routers).Real-time DDoS metrics, CloudWatch alarms, attack vector breakdowns, and Global Threat Dashboard visibility.

Automatic Layer 7 DDoS Mitigation

A signature capability of AWS Shield Advanced is Automatic Layer 7 DDoS Mitigation. When an enterprise associates a WebACL with a protected resource (such as an Application Load Balancer or CloudFront distribution), Shield Advanced continuously profiles the application's normal traffic patterns.

Loading diagram...

How Automatic Mitigation Functions

  1. Continuous Baselining: Shield Advanced analyzes historical traffic telemetry to establish diurnal baseline models for request rates, client IP distributions, user agents, and URL endpoints.
  2. Anomaly Isolation & Signature Extraction: During an active attack, the mitigation engine uses machine learning algorithms to isolate the unique fingerprint of the malicious traffic (e.g., identical uncommon header values, specific URI combinations, or abnormal geographic concentrations).
  3. Automated Rule Synthesis: Shield Advanced authors a custom AWS WAF rule targeting the isolated attack signature and deploys it into a rule group that Shield owns (named ShieldMitigationRuleGroup_<account-id>_<web-acl-id>_<unique-id>), referenced from your web ACL by a rule at priority 10,000,000 so it runs after your own rules.
  4. Mitigation Action Configuration: Security engineers can configure automatic mitigation to operate in Count mode (logs the rule evaluation without dropping traffic) or Block mode (actively terminates attack connections at the edge).
  5. Automated Rule Teardown: When the attack terminates and traffic returns to baseline, Shield Advanced automatically removes the generated rule to conserve WebACL capacity and prevent stale rules from impacting future operations.

Health-Based Detection via Amazon Route 53

A critical challenge in automated DDoS defense is distinguishing between an active malicious flood and a legitimate traffic surge (such as a viral marketing campaign, flash sale, or breaking news broadcast).

If a mitigation system relies solely on traffic volume, it risks generating severe false positives—blocking legitimate customers during high-revenue business events.

The Health-Based Detection Mechanism

Shield Advanced resolves this through Health-Based Detection by integrating with Amazon Route 53 Health Checks:

  • The security engineer creates a Route 53 health check monitoring the operational health of the application (probing endpoint latency, HTTP status codes, or internal backend health).
  • The health check is associated with the Shield Advanced protected resource.
  • Operational Logic:
    • Traffic Surge + Healthy Application: If traffic volume spikes by 500% but the Route 53 health check remains completely healthy (low latency, 200 OK responses), Shield Advanced determines the application is handling the load successfully. It does not engage aggressive mitigations, protecting legitimate user transactions.
    • Traffic Surge + Degraded Application: If a traffic surge coincides with failing health checks (elevated backend latency or 5xx error responses), Shield Advanced immediately lowers its anomaly threshold, engages automated Layer 7 WAF mitigations, and alerts the AWS Shield Response Team.

Exam Tip: Always configure Health-Based Detection for Shield Advanced protected resources! On the exam, when asked how to minimize false positives during legitimate traffic spikes or enable proactive SRT engagement, the correct architectural answer involves associating Route 53 health checks with the Shield Advanced protected resources.


24/7 AWS Shield Response Team (SRT) Integration

Subscribers to AWS Shield Advanced gain direct, 24/7 access to the AWS Shield Response Team (SRT)—formerly known as the DDoS Response Team (DRT). The SRT consists of specialized security engineers who assist customers in triaging, analyzing, and mitigating complex, multi-vector DDoS attacks.

Loading diagram...

Configuration Prerequisites for SRT Support

To allow the SRT to manage mitigations on the customer's behalf during an active emergency, three prerequisites must be completed before an attack occurs:

  1. Support Plan: The AWS account must be subscribed to either Business Support or Enterprise Support.
  2. SRT access role:
    • In the Shield console, choose to create a new role or select an existing one; either way the role must trust the service principal drt.shield.amazonaws.com (via sts:AssumeRole).
    • The role carries the AWS managed policy AWSShieldDRTAccessPolicy, which lets the SRT call Shield Advanced and AWS WAF APIs on your behalf and read your AWS WAF web ACL logs.
  3. Optional extra log buckets:
    • WAF web ACL logs need no extra step. For other evidence (ALB or CloudFront access logs, packet captures), add up to 10 buckets; Shield grants the SRT s3:GetBucketLocation, s3:GetObject, and s3:ListBucket on them.
    • Those buckets must be unencrypted or SSE-S3 encrypted. The SRT cannot read logs in buckets encrypted with AWS KMS keys.

Proactive Engagement

When Proactive Engagement is enabled in the Shield console, the SRT does not wait for the customer to open a support ticket. If a protected resource with an associated Route 53 health check becomes unhealthy during a detected DDoS event, the SRT will proactively contact the customer's designated emergency contacts (via phone and high-priority ticket) to begin mitigation immediately.


Financial Protection: DDoS Cost Protection for Scaling

A devastating secondary effect of a Layer 7 DDoS attack is financial exhaustion. In a well-architected cloud environment, Auto Scaling groups, Application Load Balancers, and CloudFront distributions automatically scale up to handle incoming request volume. During an attack, hundreds of EC2 instances may be provisioned, resulting in catastrophic compute and data transfer out (DTO) bills.

AWS Shield Advanced Cost Protection shields organizations against these economic damages:

  • If an attack causes a surge in resource usage across protected resources (such as Amazon EC2, CloudFront, ALB, or Route 53), the customer can submit a claim for billing credits.
  • The credit covers the difference between normal baseline operational usage and the spike charges directly attributable to the DDoS attack.
  • Claims are submitted via AWS Support after the incident, referencing the attack identifier, affected resource ARNs, and billing cycle.

End-to-End Edge DDoS Defense Architecture

A resilient, enterprise-grade edge defense architecture integrates Route 53, CloudFront, AWS WAF, AWS Shield Advanced, and AWS Global Accelerator:

Loading diagram...

Defense-in-Depth Components

  1. Route 53 Shuffle Sharding: Route 53 provides authoritative DNS resolution utilizing anycast routing across dozens of edge locations. Each hosted zone is assigned four virtual name servers hosted on isolated failure domains (shuffle sharding), ensuring that a DDoS flood against one name server does not impact resolution on the remaining three.
  2. AWS Global Accelerator: For non-HTTP TCP/UDP workloads (such as gaming, VoIP, or proprietary financial trading protocols), Global Accelerator provisions static anycast IP addresses routed across the AWS global backbone. It terminates TCP connections at edge PoPs, absorbing SYN floods and UDP reflection before traffic enters the VPC.
  3. CloudFront Edge Termination: Terminating TLS connections at edge PoPs ensures that Layer 3 and 4 attacks are absorbed by AWS border routers and transit centers without reaching regional VPC gateways.
  4. Origin Cloaking: Enforcing custom header verification (X-Origin-Verify) and restricting security groups to the CloudFront managed prefix list guarantees that malicious traffic cannot bypass edge mitigations.

Specialty Exam Pitfalls & Architectural Traps

  1. Assuming Shield Standard Covers Layer 7 Floods: Shield Standard is entirely automated and provides world-class Layer 3 and Layer 4 defense. However, it provides zero protection against Layer 7 application attacks (such as HTTP GET floods). Defending against Layer 7 attacks requires AWS WAF or AWS Shield Advanced with automatic Layer 7 mitigation.
  2. Overlooking the SRT IAM Role and S3 Log Permissions: In an active DDoS emergency, customers cannot simply open a ticket and expect the SRT to modify their WebACLs. If SRT access has not been granted (no role trusting drt.shield.amazonaws.com with AWSShieldDRTAccessPolicy), the SRT is legally and technically constrained from accessing the customer's account or deploying mitigations on their behalf.
  3. Misunderstanding Cost Protection Mechanics: Shield Advanced Cost Protection does not cap or prevent auto-scaling charges in real time. Backend resources will still scale up to attempt to handle the load, incurring charges. The protection functions as a post-incident billing credit applied after AWS verifies the incident.
  4. Failing to Associate Route 53 Health Checks: Operating Shield Advanced without Route 53 Health-Based Detection severely impairs its defensive capabilities. The system cannot distinguish legitimate marketing surges from distributed attacks, increasing the risk of false positives, and proactive SRT engagement will remain disabled.
Loading diagram...
AWS Shield Advanced Multi-Layer DDoS Defense & SRT Incident Workflow
Test Your Knowledge

A global banking corporation with AWS Business Support anticipates high-volume distributed Layer 7 HTTP floods during a contentious shareholder vote. The security engineering team subscribes to AWS Shield Advanced and protects their public Application Load Balancers. The chief information security officer (CISO) mandates that if an attack causes backend web servers to degrade, AWS specialized engineers must proactively contact the company and help modify WAF rules without waiting for an internal support ticket. Which combination of actions satisfies these requirements?

A

Enable AWS Shield Standard on all Route 53 hosted zones and attach an IAM user policy with AdministratorAccess to the AWS Support portal.

B

Configure an Amazon EventBridge rule matching GuardDuty high-severity findings that triggers an SNS topic subscribed to the AWS DDoS Response Team email alias.

C

Deploy an AWS Lambda function running every 60 seconds to inspect CloudWatch ALB metrics and execute the AWS CLI command aws shield update-emergency-contact.

D

Create a Route 53 health check for the ALB, configure Proactive Engagement in Shield Advanced associating the health check and emergency contacts, and grant SRT access with a role that trusts drt.shield.amazonaws.com and has the AWSShieldDRTAccessPolicy managed policy.

Test Your Knowledge

A retail platform protected by AWS Shield Advanced and AWS WAF experiences an unannounced flash sale driven by an influencer endorsement. Incoming traffic surges by 800% in five minutes. The platform's security team worries that automated DDoS defenses will mistake the legitimate shoppers for an HTTP GET flood attack and block customers. Which feature in AWS Shield Advanced prevents false-positive mitigations during legitimate traffic spikes?

A

AWS WAF Amazon IP Reputation list, which automatically whitelists domestic consumer IP ranges.

B

Shield Advanced Health-Based Detection using Amazon Route 53 health checks, which avoids engaging aggressive mitigations as long as application health indicators remain healthy.

C

CloudFront Geo-restriction configured in Blocklist mode targeting non-domestic country codes.

D

AWS Shield Standard border scrubbing, which automatically drops all traffic exceeding 100,000 requests per minute.

Test Your Knowledge

An e-commerce company experiences a sustained 48-hour Layer 7 DDoS attack targeting its checkout API. The attack bypassed static rate limits and caused backend EC2 Auto Scaling groups to scale from 10 instances to their maximum limit of 200 instances to handle the request volume. The company successfully mitigated the attack with assistance from the AWS Shield Response Team, but the finance director is concerned about the $25,000 EC2 compute and ALB data transfer scaling bill incurred during the attack. How does AWS Shield Advanced address this financial risk?

A

Through AWS Shield Advanced Cost Protection, which allows the customer to request service billing credits for the excess scaling charges incurred directly from the verified DDoS attack.

B

Shield Advanced automatically limits Auto Scaling groups from expanding beyond 10% of their baseline during detected attacks.

C

AWS Support automatically cancels all AWS invoices for any month in which a DDoS attack occurred.

D

Shield Advanced automatically converts all running EC2 On-Demand instances into 3-year All Upfront Reserved Instances during an active incident.

Test Your Knowledge

A media streaming application protected by AWS Shield Advanced is targeted by a sophisticated Layer 7 HTTP query flood with rapidly shifting header values and randomized user-agents. The security team needs AWS WAF to isolate the attack signature and block malicious requests in real time without requiring engineers to manually analyze logs and write custom rules during the incident. Which Shield Advanced capability should be enabled?

A

CloudFront Viewer Protocol Policy set to redirect-to-https.

B

AWS Shield Standard automated UDP reflection packet filtering.

C

Automatic Layer 7 DDoS Mitigation, which uses machine learning to isolate the attack signature and automatically deploys custom WAF rules into the associated WebACL in Block mode.

D

AWS WAF Core Rule Set (CRS) configured with an Action Override set to Count.

Sections you finish are checked off in the contents.