Blog Blog Posts Business Management Process Analysis

What is AWS Shield?

Distributed Denial of Service (DDoS) is a kind of cyber attack that tries to put a load on web services but uses lots of servers at a single time, it mainly aims to bring down the applications and servers by making them completely unusable.

In this blog, we will be discussing how AWS Shield protects during such attacks and plays a vital role in safeguarding various web applications and AWS services.

Table of Contents:

Watch this YouTube video on AWS training for beginners!

What is DDoS?

A distributed denial-of-service (DDoS) attack is used when someone maliciously wants to disturb the traffic reaching any targeted server to bring it down.

DDoS uses lots of computers which are firstly converted into bots by infecting them through viruses for disrupting any online service.

The infected devices are known as bots or zombies, and botnet is a term used for a group of such bots. After creating a botnet successfully, the attacker can easily send remote instructions to every bot and plan an attack accordingly.

Once the botnet targets the victim’s network or server, bots start sending requests to the IP address, due to which the server gets overwhelmed and results in denial of service to the normal traffic. As each bot is a computer device, it becomes difficult to differentiate between normal traffic and attack traffic.

Interested in AWS? Learn AWS with a comprehensive AWS tutorial!

What is AWS Shield?

AWS Shield provides protection to web applications against DDoS attacks. Standard and Advanced Shield are two versions of AWS Shield. AWS Shield Standard is by default applied when you start using the AWS, whereas Advanced Shield is a paid version.

AWS Shield Tiers

AWS Shield Tiers

AWS Shield Standard

AWS Shield Advanced

AWS Shield Benefits

AWS Shield offers some great benefits when it comes to protecting AWS cloud services and also other third-party solutions. Let’s discuss those benefits one by one:

Benefits of AWS Shield Standard:

Global threat dashboard

Benefits of AWS Shield Advanced

Looking for a source to prepare for your interview? Check these top 55 AWS interview questions by Intellipaat!

Career Transition

What is AWS WAF?

Web Application Firewall (WAF) by AWS helps defend applications against web attacks. AWS WAF can control and manage both traffic, and also block common attack patterns.

AWS WAF can be used to protect web services against the following cyber attacks:

Let’s talk about AWS WAF features:

AWS WAF costs nothing initially with running cost being only $20/month making it quite a cheaper solution when compared to the competition which may cost you thousands of dollars for the initial cost.

You can set up AWS WAF in just a few clicks provided you have basic security knowledge. In case you have no prior knowledge, you can refer to “Managed Rules” for AWS WAF.

AWS Shield vs AWS WAF

Both AWS Shield and AWS WAF are included in AWS Edge service ecosystems and are responsible for defending against DDoS attacks. The major difference between them is that AWS WAF provides application layer protection whereas AWS Shield is responsible for OSI model infrastructure layers.

Type AWS WAF AWS Shield
Operation OSI Layer Operates in Application Layer (layer 7) If you choose Shield Advanced, it will function in the Network Layer (Layer 3), Transport Layer (Layer 4), and Application Layer (Layer 7).
Use-case Protects against web attacks like Cross-site Scripting, DDoS, SQL injection, etc. It protects mainly against DDoS
Pricing You have to pay for using AWS WAS, although initially, it’s free. In AWS Shield, Shield Standard works with no additional cost whereas with Shield Advanced you have to pay as you use.

Now coming to the conclusion that which one is better, the simple answer will be it all depends on your needs. You can even use both for better security implementation.

Are you interested in Amazon Web Services (AWS)? Sign up for AWS Certification Training to master Amazon Web Services!

AWS Shield Advanced vs Standard

AWS Shield Advanced vs Standard

Pricing

The AWS Shield Standard is free, whereas the AWS Shield Advanced is not. The monthly charge for Advanced is around US$ 3,000.

Furthermore, usage fees are assessed based on the volume of data moved from Amazon CloudFront, Amazon Elastic Compute (EC2) Elastic Load Balancing (ELB), Amazon Route 53, and AWS Global Accelerator.

Conclusion

AWS Shield gives you some peace of mind.  All the applications deployed using Amazon EC2, Elastic Load Balancing, CloudFront, and Amazon Route 53 are by default guarded by the AWS Shield Standard. In case you are looking for more control and support you can choose the AWS Shield Advanced.

If you still have any queries, please feel free to post them in our AWS community!

The post What is AWS Shield? appeared first on Intellipaat Blog.

Blog: Intellipaat - Blog

Leave a Comment

Get the BPI Web Feed

Using the HTML code below, you can display this Business Process Incubator page content with the current filter and sorting inside your web site for FREE.

Copy/Paste this code in your website html code:

<iframe src="https://www.businessprocessincubator.com/content/what-is-aws-shield/?feed=html" frameborder="0" scrolling="auto" width="100%" height="700">

Customizing your BPI Web Feed

You can click on the Get the BPI Web Feed link on any of our page to create the best possible feed for your site. Here are a few tips to customize your BPI Web Feed.

Customizing the Content Filter
On any page, you can add filter criteria using the MORE FILTERS interface:

Customizing the Content Filter

Customizing the Content Sorting
Clicking on the sorting options will also change the way your BPI Web Feed will be ordered on your site:

Get the BPI Web Feed

Some integration examples

BPMN.org

XPDL.org

×