AWS Shield Advanced DDoS Protection

Implement enterprise-grade DDoS protection with AWS Shield Advanced for comprehensive application resilience.

AWS Shield Advanced provides enhanced DDoS protection with automatic mitigation, 24/7 DDoS Response Team access, and cost protection for scaling during attacks.

Shield Advanced Setup

Enable Shield Advanced

import boto3

shield = boto3.client('shield')

def enable_shield_advanced():
    # Create subscription
    response = shield.create_subscription()
    
    # Protect resources
    resources = [
        'arn:aws:elasticloadbalancing:us-east-1:123456789012:loadbalancer/app/my-alb/abc123',
        'arn:aws:cloudfront::123456789012:distribution/E1234567890',
        'arn:aws:route53:::hostedzone/Z1234567890'
    ]
    
    for resource_arn in resources:
        shield.create_protection(
            Name=f"Protection-{resource_arn.split('/')[-1]}",
            ResourceArn=resource_arn
        )
    
    return response

CloudFormation Configuration

ShieldProtection:
  Type: AWS::Shield::Protection
  Properties:
    Name: ProductionALBProtection
    ResourceArn: !Ref ApplicationLoadBalancer
    HealthCheckArns:
      - !GetAtt ALBHealthCheck.Arn
    ApplicationLayerAutomaticResponseConfiguration:
      Status: ENABLED
      Action:
        Block: {}

Route53HealthCheck:
  Type: AWS::Route53::HealthCheck
  Properties:
    HealthCheckConfig:
      Type: HTTPS
      FullyQualifiedDomainName: app.example.com
      Port: 443
      ResourcePath: /health
      RequestInterval: 30
      FailureThreshold: 3

Automatic Application Layer DDoS Mitigation

def configure_automatic_mitigation(protection_id):
    shield = boto3.client('shield')
    
    # Enable automatic response
    shield.enable_application_layer_automatic_response(
        ResourceArn='arn:aws:elasticloadbalancing:us-east-1:123456789012:loadbalancer/app/my-alb/abc123',
        Action={'Block': {}}
    )
    
    # Associate health check
    shield.associate_health_check(
        ProtectionId=protection_id,
        HealthCheckArn='arn:aws:route53:::healthcheck/abc123'
    )

Proactive Engagement

Configure DRT Access

def configure_drt_access():
    shield = boto3.client('shield')
    
    # Grant DRT role access
    shield.associate_drt_role(
        RoleArn='arn:aws:iam::123456789012:role/ShieldDRTAccessRole'
    )
    
    # Add S3 log buckets for DRT analysis
    shield.associate_drt_log_bucket(
        LogBucket='my-waf-logs-bucket'
    )
    
    # Enable proactive engagement
    shield.enable_proactive_engagement()

# DRT Access Role
DRTRole:
  Type: AWS::IAM::Role
  Properties:
    RoleName: ShieldDRTAccessRole
    AssumeRolePolicyDocument:
      Version: '2012-10-17'
      Statement:
        - Effect: Allow
          Principal:
            Service: drt.shield.amazonaws.com
          Action: sts:AssumeRole
    ManagedPolicyArns:
      - arn:aws:iam::aws:policy/service-role/AWSShieldDRTAccessPolicy

Attack Visibility

CloudWatch Metrics

DDoSAlarm:
  Type: AWS::CloudWatch::Alarm
  Properties:
    AlarmName: DDoSDetected
    MetricName: DDoSDetected
    Namespace: AWS/DDoSProtection
    Statistic: Sum
    Period: 60
    EvaluationPeriods: 1
    Threshold: 1
    ComparisonOperator: GreaterThanOrEqualToThreshold
    Dimensions:
      - Name: ResourceArn
        Value: !Ref ApplicationLoadBalancer
    AlarmActions:
      - !Ref DDoSAlertSNSTopic

Attack Analysis

def analyze_attack(attack_id):
    shield = boto3.client('shield')
    
    # Get attack details
    attack = shield.describe_attack(
        AttackId=attack_id
    )
    
    attack_detail = attack['Attack']
    
    analysis = {
        'attack_id': attack_id,
        'start_time': attack_detail['StartTime'],
        'end_time': attack_detail.get('EndTime'),
        'resource_arn': attack_detail['ResourceArn'],
        'attack_vectors': [],
        'mitigations': []
    }
    
    for vector in attack_detail.get('AttackVectors', []):
        analysis['attack_vectors'].append({
            'vector_type': vector['VectorType'],
            'vector_counters': vector.get('VectorCounters', [])
        })
    
    for mitigation in attack_detail.get('Mitigations', []):
        analysis['mitigations'].append({
            'mitigation_name': mitigation['MitigationName']
        })
    
    return analysis

Cost Protection

Shield Advanced includes DDoS cost protection for scaling charges:

def request_credit(attack_id):
    support = boto3.client('support')
    
    # Create support case for DDoS cost credit
    response = support.create_case(
        subject='DDoS Cost Protection Credit Request',
        serviceCode='shield-advanced',
        severityCode='low',
        categoryCode='ddos-cost-protection',
        communicationBody=f'''
        Attack ID: {attack_id}
        
        Requesting credit for scaling costs incurred during 
        the DDoS attack. Please review attached attack details 
        and associated CloudWatch metrics.
        ''',
        attachmentSetId=upload_attack_evidence(attack_id)
    )
    
    return response['caseId']

Working with Warqline

We are a cloud engineering consultancy and an official AWS and Google Cloud partner. If you are running this in production and want a second pair of eyes, we scope work in a free 45-minute technical call: you describe what you are running and what worries you, and we tell you what we would look at first.

Talk to an engineer

Conclusion

AWS Shield Advanced provides comprehensive DDoS protection with automatic mitigation and expert support. Combine with WAF for complete application layer protection.