DDoS and edge security
Shield Standard and Advanced, AWS WAF rules, Firewall Manager, CloudFront and Global Accelerator as the edge, and where Network Firewall and security groups fit.
Exam tasks: 2.3 (design security controls for edge and network protection, DDoS resilience)
The decision: which layer is the attack aimed at (network floods or application requests), and where should it be absorbed: at the AWS edge, at the load balancer, or inside the VPC?
A layered edge
The idea: stop as much as possible at the edge, where AWS has the most capacity, and make the origin reachable only through the edge.
Which control for which job?
| Control | Layer | Where it runs | Stops |
|---|---|---|---|
| Shield Standard | 3 and 4 | Every AWS edge and Region, automatically | SYN floods, UDP reflection and other common network attacks |
| Shield Advanced | 3, 4 and 7 | Resources you register | Larger and targeted attacks, with SRT help and cost protection |
| AWS WAF | 7 | CloudFront, ALB, API Gateway, AppSync, Cognito user pools, App Runner, Verified Access | SQL injection, XSS, bots, request floods from a single IP, blocked countries |
| Network Firewall | 3 to 7 | Firewall endpoints in your VPC subnets | East-west and egress traffic, domain allow lists, Suricata IPS rules |
| Security groups | 3 and 4 | Each ENI, stateful | Anything not explicitly allowed. No deny rules |
| Network ACLs | 3 and 4 | Each subnet, stateless | Explicit denies for IP ranges |
WAF on an NLB
WAF doesn't attach to a Network Load Balancer or directly to EC2. For layer 7 filtering in front of an NLB design, put CloudFront (with WAF) in front, or switch to an ALB.
Shield Standard vs Shield Advanced
| Standard | Advanced | |
|---|---|---|
| Cost | Included for everyone | Monthly subscription per organization with a 1-year commitment, plus data transfer fees |
| Protected resources | All | Those you register: CloudFront, Route 53 hosted zones, Global Accelerator, ELB, Elastic IPs on EC2 |
| Layer 7 protection | No | Yes, with WAF. Automatic application-layer mitigation can create WAF rules for you |
| Shield Response Team (SRT) | No | 24/7, with a Business or Enterprise support plan. Can act in your account through a role you grant |
| Proactive engagement | No | SRT contacts you when a protected resource's health degrades |
| Health-based detection | No | Uses Route 53 health checks to detect attacks faster and more accurately |
| Cost protection | No | Service credits for scaling charges caused by a DDoS attack |
| Visibility | Basic | Attack diagnostics and CloudWatch metrics |
| WAF charges | Normal | WAF included for protected resources |
Exam signal
Any of these words point to Shield Advanced: "24/7 access to DDoS experts", "protection against the bill from scaling during an attack", "near real-time attack visibility", or "a DDoS protection guarantee for business critical apps".
AWS WAF rules
A web ACL holds rules evaluated in priority order. Each rule allows, blocks, counts, or presents a CAPTCHA or challenge.
- Managed rule groups from AWS (core rule set, known bad inputs, SQL database, IP reputation, anonymous IP) or Marketplace sellers. Start in count mode to see what would be blocked.
- Rate-based rules block a source when its request count in a rolling window (1 to 10 minutes) exceeds a limit. The key can be the IP, a forwarded IP header, or a header, cookie or query value.
- Bot Control has a common level (known bots and scrapers) and a targeted level (sophisticated bots, using browser interrogation and behaviour).
- Fraud Control covers account takeover on login pages and fake account creation on sign-up pages.
- Geo match blocks or allows by country. CloudFront also has its own simpler geo restriction.
- IP sets and regex pattern sets are reusable building blocks.
- Logs go to CloudWatch Logs, S3 or Data Firehose.
Rate-based rules behind a proxy
If every request arrives from a CDN or corporate proxy, a rate-based rule keyed on the source IP sees only a few
IPs and blocks everyone. Key it on the X-Forwarded-For header instead. With CloudFront in front, put the web ACL
on CloudFront, where the real client IP is visible.
Firewall Manager
Firewall Manager applies security policies to every account in an organization, including accounts and resources created later.
- Prerequisites: AWS Organizations, a Firewall Manager administrator account, and AWS Config enabled in the member accounts and Regions.
- Policy types: WAF web ACLs, Shield Advanced, security groups (baseline and audit), Network Firewall, Route 53 Resolver DNS Firewall, and some third-party firewalls.
- Account owners can add their own rules, but can't remove the rules the central policy enforces.
Exam signal
"Ensure every new ALB in any account automatically gets the corporate WAF rules" is Firewall Manager, not a Config rule or a Lambda function per account.
Reducing attack surface
- Put CloudFront in front of both static and dynamic content. It absorbs floods at hundreds of edge locations and only forwards valid HTTP requests.
- Lock the origin: allow only the CloudFront managed prefix list in the ALB security group, and add a secret custom header that the ALB checks. Use origin access control for S3.
- Use Global Accelerator for non-HTTP traffic (TCP or UDP games, VoIP). Its two anycast static IPs sit on the AWS edge with Shield protection, and endpoints stay private behind it.
- Keep instances in private subnets, and scale with Auto Scaling so a flood that gets through doesn't take you down.
- Use Route 53 for DNS. It's served from a global anycast network with shuffle sharding.
Scenarios
Shield Advanced gives SRT access and cost protection, and it covers both CloudFront and the ALB. A WAF rate-based rule plus Bot Control filters the layer 7 flood at the edge. An NLB can't run WAF, NACLs have a small rule limit and can't track thousands of changing IPs, and Shield Standard doesn't include the SRT or cost protection.
Firewall Manager creates and associates the web ACL on existing and new in-scope resources across the organization. A Config rule only alerts, a StackSet creates the web ACL but doesn't associate it with resources created later, and an SCP can't check whether a web ACL is attached.
Further reading
Configuration and patching
Using Systems Manager to patch, configure, access and inventory EC2 and on-premises servers at scale, and building golden AMIs with EC2 Image Builder.
Private access to S3 content
S3 presigned URLs, CloudFront signed URLs and signed cookies, origin access control, S3 Access Points, Multi-Region Access Points and Block Public Access.