Asterrr's Handbook

DDoS and edge security

Shield Standard and Advanced, AWS WAF rules, Firewall Manager, CloudFront and Global Accelerator as the edge, and where Network Firewall and security groups fit.

Exam tasks: 2.3 (design security controls for edge and network protection, DDoS resilience)

The decision: which layer is the attack aimed at (network floods or application requests), and where should it be absorbed: at the AWS edge, at the load balancer, or inside the VPC?

A layered edge

The idea: stop as much as possible at the edge, where AWS has the most capacity, and make the origin reachable only through the edge.

Which control for which job?

ControlLayerWhere it runsStops
Shield Standard3 and 4Every AWS edge and Region, automaticallySYN floods, UDP reflection and other common network attacks
Shield Advanced3, 4 and 7Resources you registerLarger and targeted attacks, with SRT help and cost protection
AWS WAF7CloudFront, ALB, API Gateway, AppSync, Cognito user pools, App Runner, Verified AccessSQL injection, XSS, bots, request floods from a single IP, blocked countries
Network Firewall3 to 7Firewall endpoints in your VPC subnetsEast-west and egress traffic, domain allow lists, Suricata IPS rules
Security groups3 and 4Each ENI, statefulAnything not explicitly allowed. No deny rules
Network ACLs3 and 4Each subnet, statelessExplicit denies for IP ranges

WAF on an NLB

WAF doesn't attach to a Network Load Balancer or directly to EC2. For layer 7 filtering in front of an NLB design, put CloudFront (with WAF) in front, or switch to an ALB.

Shield Standard vs Shield Advanced

StandardAdvanced
CostIncluded for everyoneMonthly subscription per organization with a 1-year commitment, plus data transfer fees
Protected resourcesAllThose you register: CloudFront, Route 53 hosted zones, Global Accelerator, ELB, Elastic IPs on EC2
Layer 7 protectionNoYes, with WAF. Automatic application-layer mitigation can create WAF rules for you
Shield Response Team (SRT)No24/7, with a Business or Enterprise support plan. Can act in your account through a role you grant
Proactive engagementNoSRT contacts you when a protected resource's health degrades
Health-based detectionNoUses Route 53 health checks to detect attacks faster and more accurately
Cost protectionNoService credits for scaling charges caused by a DDoS attack
VisibilityBasicAttack diagnostics and CloudWatch metrics
WAF chargesNormalWAF included for protected resources

Exam signal

Any of these words point to Shield Advanced: "24/7 access to DDoS experts", "protection against the bill from scaling during an attack", "near real-time attack visibility", or "a DDoS protection guarantee for business critical apps".

AWS WAF rules

A web ACL holds rules evaluated in priority order. Each rule allows, blocks, counts, or presents a CAPTCHA or challenge.

  • Managed rule groups from AWS (core rule set, known bad inputs, SQL database, IP reputation, anonymous IP) or Marketplace sellers. Start in count mode to see what would be blocked.
  • Rate-based rules block a source when its request count in a rolling window (1 to 10 minutes) exceeds a limit. The key can be the IP, a forwarded IP header, or a header, cookie or query value.
  • Bot Control has a common level (known bots and scrapers) and a targeted level (sophisticated bots, using browser interrogation and behaviour).
  • Fraud Control covers account takeover on login pages and fake account creation on sign-up pages.
  • Geo match blocks or allows by country. CloudFront also has its own simpler geo restriction.
  • IP sets and regex pattern sets are reusable building blocks.
  • Logs go to CloudWatch Logs, S3 or Data Firehose.

Rate-based rules behind a proxy

If every request arrives from a CDN or corporate proxy, a rate-based rule keyed on the source IP sees only a few IPs and blocks everyone. Key it on the X-Forwarded-For header instead. With CloudFront in front, put the web ACL on CloudFront, where the real client IP is visible.

Firewall Manager

Firewall Manager applies security policies to every account in an organization, including accounts and resources created later.

  • Prerequisites: AWS Organizations, a Firewall Manager administrator account, and AWS Config enabled in the member accounts and Regions.
  • Policy types: WAF web ACLs, Shield Advanced, security groups (baseline and audit), Network Firewall, Route 53 Resolver DNS Firewall, and some third-party firewalls.
  • Account owners can add their own rules, but can't remove the rules the central policy enforces.

Exam signal

"Ensure every new ALB in any account automatically gets the corporate WAF rules" is Firewall Manager, not a Config rule or a Lambda function per account.

Reducing attack surface

  • Put CloudFront in front of both static and dynamic content. It absorbs floods at hundreds of edge locations and only forwards valid HTTP requests.
  • Lock the origin: allow only the CloudFront managed prefix list in the ALB security group, and add a secret custom header that the ALB checks. Use origin access control for S3.
  • Use Global Accelerator for non-HTTP traffic (TCP or UDP games, VoIP). Its two anycast static IPs sit on the AWS edge with Shield protection, and endpoints stay private behind it.
  • Keep instances in private subnets, and scale with Auto Scaling so a flood that gets through doesn't take you down.
  • Use Route 53 for DNS. It's served from a global anycast network with shuffle sharding.

Scenarios

Scenario · choose 2
An online ticketing company is hit by HTTP floods whenever popular events go on sale. The traffic comes from thousands of IPs, each sending a few hundred requests per minute. The site runs on an ALB behind CloudFront. The company wants DDoS experts on call and protection from the extra scaling charges. Which TWO actions should the architect take?
Scenario
A company with 150 accounts in AWS Organizations must guarantee that every internet-facing ALB and API Gateway stage, including those created in the future, has the security team's WAF rules attached. What is the MOST operationally efficient solution?

Further reading

On this page