Securing DDoS protection services
Each cloud provider has its own implementation of a managed DDoS protection service.
Because cloud providers have very large bandwidth, they can offer (as a paid service) mechanisms to protect customers' environments from DDoS attacks.
The following services help to mitigate DDoS attacks:
- DDoS protection services (discussed in this section)
- Auto-scaling groups combined with load-balancing services
- CDN services (discussed earlier in this chapter)
- WAF services (discussed later in this chapter)
In this section, we will focus on DDoS protection services.
Securing AWS Shield
AWS Shield is the Amazon managed DDoS protection service.
It comes in two price models:
- AWS Shield Standard: This is the default and free Layer 7 DDoS protection (HTTP/HTTPS), provided for all customers.
- AWS Shield Advanced: This offers Layers 3/4 (Network layer) and Layer 7 (Application layer) DDoS protection, with additional...