AWS Shield Advanced DDoS Protection
Implement enterprise-grade DDoS protection with AWS Shield Advanced for comprehensive application resilience.
AWS Shield Advanced provides enhanced DDoS protection with automatic mitigation, 24/7 DDoS Response Team access, and cost protection for scaling during attacks.
Shield Advanced Setup
Enable Shield Advanced
import boto3
shield = boto3.client('shield')
def enable_shield_advanced():
# Create subscription
response = shield.create_subscription()
# Protect resources
resources = [
'arn:aws:elasticloadbalancing:us-east-1:123456789012:loadbalancer/app/my-alb/abc123',
'arn:aws:cloudfront::123456789012:distribution/E1234567890',
'arn:aws:route53:::hostedzone/Z1234567890'
]
for resource_arn in resources:
shield.create_protection(
Name=f"Protection-{resource_arn.split('/')[-1]}",
ResourceArn=resource_arn
)
return response
CloudFormation Configuration
ShieldProtection:
Type: AWS::Shield::Protection
Properties:
Name: ProductionALBProtection
ResourceArn: !Ref ApplicationLoadBalancer
HealthCheckArns:
- !GetAtt ALBHealthCheck.Arn
ApplicationLayerAutomaticResponseConfiguration:
Status: ENABLED
Action:
Block: {}
Route53HealthCheck:
Type: AWS::Route53::HealthCheck
Properties:
HealthCheckConfig:
Type: HTTPS
FullyQualifiedDomainName: app.example.com
Port: 443
ResourcePath: /health
RequestInterval: 30
FailureThreshold: 3
Automatic Application Layer DDoS Mitigation
def configure_automatic_mitigation(protection_id):
shield = boto3.client('shield')
# Enable automatic response
shield.enable_application_layer_automatic_response(
ResourceArn='arn:aws:elasticloadbalancing:us-east-1:123456789012:loadbalancer/app/my-alb/abc123',
Action={'Block': {}}
)
# Associate health check
shield.associate_health_check(
ProtectionId=protection_id,
HealthCheckArn='arn:aws:route53:::healthcheck/abc123'
)
Proactive Engagement
Configure DRT Access
def configure_drt_access():
shield = boto3.client('shield')
# Grant DRT role access
shield.associate_drt_role(
RoleArn='arn:aws:iam::123456789012:role/ShieldDRTAccessRole'
)
# Add S3 log buckets for DRT analysis
shield.associate_drt_log_bucket(
LogBucket='my-waf-logs-bucket'
)
# Enable proactive engagement
shield.enable_proactive_engagement()
# DRT Access Role
DRTRole:
Type: AWS::IAM::Role
Properties:
RoleName: ShieldDRTAccessRole
AssumeRolePolicyDocument:
Version: '2012-10-17'
Statement:
- Effect: Allow
Principal:
Service: drt.shield.amazonaws.com
Action: sts:AssumeRole
ManagedPolicyArns:
- arn:aws:iam::aws:policy/service-role/AWSShieldDRTAccessPolicy
Attack Visibility
CloudWatch Metrics
DDoSAlarm:
Type: AWS::CloudWatch::Alarm
Properties:
AlarmName: DDoSDetected
MetricName: DDoSDetected
Namespace: AWS/DDoSProtection
Statistic: Sum
Period: 60
EvaluationPeriods: 1
Threshold: 1
ComparisonOperator: GreaterThanOrEqualToThreshold
Dimensions:
- Name: ResourceArn
Value: !Ref ApplicationLoadBalancer
AlarmActions:
- !Ref DDoSAlertSNSTopic
Attack Analysis
def analyze_attack(attack_id):
shield = boto3.client('shield')
# Get attack details
attack = shield.describe_attack(
AttackId=attack_id
)
attack_detail = attack['Attack']
analysis = {
'attack_id': attack_id,
'start_time': attack_detail['StartTime'],
'end_time': attack_detail.get('EndTime'),
'resource_arn': attack_detail['ResourceArn'],
'attack_vectors': [],
'mitigations': []
}
for vector in attack_detail.get('AttackVectors', []):
analysis['attack_vectors'].append({
'vector_type': vector['VectorType'],
'vector_counters': vector.get('VectorCounters', [])
})
for mitigation in attack_detail.get('Mitigations', []):
analysis['mitigations'].append({
'mitigation_name': mitigation['MitigationName']
})
return analysis
Cost Protection
Shield Advanced includes DDoS cost protection for scaling charges:
def request_credit(attack_id):
support = boto3.client('support')
# Create support case for DDoS cost credit
response = support.create_case(
subject='DDoS Cost Protection Credit Request',
serviceCode='shield-advanced',
severityCode='low',
categoryCode='ddos-cost-protection',
communicationBody=f'''
Attack ID: {attack_id}
Requesting credit for scaling costs incurred during
the DDoS attack. Please review attached attack details
and associated CloudWatch metrics.
''',
attachmentSetId=upload_attack_evidence(attack_id)
)
return response['caseId']
Working with Warqline
We are a cloud engineering consultancy and an official AWS and Google Cloud partner. If you are running this in production and want a second pair of eyes, we scope work in a free 45-minute technical call: you describe what you are running and what worries you, and we tell you what we would look at first.
Conclusion
AWS Shield Advanced provides comprehensive DDoS protection with automatic mitigation and expert support. Combine with WAF for complete application layer protection.