
分布式拒绝服务 (DDoS) 攻击是指多个被入侵系统尝试用流量来"淹没"目标 (如网络或 Web 应用程序) 的攻击。DDoS 攻击会阻止合法用户访问服务,并可能导致系统由于流量过大而崩溃。AWS 提供两级防护 DDoS 攻击: AWS Shield Standard 和 AWS Shield Advanced.
简介
AWS Shield Standard
全部 AWS 客户受益于的自动保护 AWS Shield Standard,无需额外收费。 AWS Shield Standard 抵御最常见的、经常发生的网络和传输层 DDoS 针对您的网站或应用程序的攻击。虽然 AWS Shield Standard 有助于为所有 AWS 客户提供保护,但如果您使用 Amazon CloudFront 和 Amazon Route 53,则可以获得特殊的优势。这些服务获得全面的可用性保护,可以防范所有已知的基础设施(第 3 层和第 4 层)攻击,参考下图。

AWS Shield Advanced
要获得更高级别的攻击防护,您可以订购 AWS Shield Advanced。当您订阅 AWS Shield Advanced 并添加需要保护的特定资源, AWS Shield Advanced 对在资源上运行的Web应用程序提供扩展的 DDoS进行攻击保护。
AWS哪些资源可以被保护
您可以为任何以下类型的资源添加保护:
Amazon CloudFront 分发
Amazon Route 53 托管区域
AWS Global Accelerator 加速器
应用程序负载均衡器
Elastic Load Balancing (ELB) 负载均衡器
Amazon Elastic Compute Cloud (Amazon EC2) 弹性 IP 地址
Shield和Shield Advanced的对比

如何选择
您可以将 AWS WAF、AWS Firewall Manager 和 AWS Shield 一起使用来创建全面的安全解决方案。
一切都从 AWS WAF 入手。您可以实现自动化,然后简化 AWS WAF 使用 AWS Firewall Manager。 Shield Advanced 在的顶部添加其他功能 AWS WAF,例如来自 DDoS 响应小组 (DRT) 和高级报告。
如果您希望对添加到您的资源的保护进行精细控制,单独使用 AWS WAF 是正确的选择。如果您希望跨账户使用 AWS WAF、加快您的 AWS WAF 配置或自动执行新资源的保护,请将 Firewall Manager 与 AWS WAF 结合使用。
最后,如果您拥有高可见度的网站,或者容易频繁 DDoS 攻击时,您应该考虑购买 Shield Advanced 提供。
如何收费
AWS Shield Standard 为所有 AWS 客户提供保护,使其免受以网站或应用程序为目标的最频繁发生的常见网络和传输层 DDoS 攻击,且无需支付额外费用。
AWS Shield Advanced 是付费服务,可为在 Amazon Elastic Compute (EC2)、Elastic Load Balancing (ELB)、Amazon CloudFront、AWS Global Accelerator 和 Amazon Route 53 上运行的面向互联网的应用程序提供额外保护。AWS Shield Advanced 对所有客户开放,但只有 AWS Premium Support 的企业支持计划或商业支持计划客户才能联系 DDoS 响应团队。它需要为期 1 年的订购承诺,按月收费3000美金。数据传输资费情况如下表:

如需进一步协助或服务,请留言,泰岳云业务会提供自动化工具及专业服务。

返回技术博客

A Distributed Denial of Service (DDoS) attack is an attack where multiple compromised systems attempt to "flood" a target (such as a network or web application) with traffic. DDoS attacks prevent legitimate users from accessing services and can cause systems to crash due to excessive traffic. AWS provides two tiers of DDoS attack protection: AWS Shield Standard and AWS Shield Advanced.
Overview
AWS Shield Standard
All AWS customers benefit from the automatic protection of AWS Shield Standard at no additional charge. AWS Shield Standard defends against the most common, frequently occurring network and transport layer DDoS attacks targeting your websites or applications. While AWS Shield Standard helps protect all AWS customers, you can gain special advantages if you use Amazon CloudFront and Amazon Route 53. These services receive comprehensive availability protection against all known infrastructure (Layer 3 and Layer 4) attacks, as shown in the diagram below.

AWS Shield Advanced
For higher levels of attack protection, you can subscribe to AWS Shield Advanced. When you subscribe to AWS Shield Advanced and add specific resources to protect, AWS Shield Advanced provides extended DDoS attack protection for web applications running on those resources.
Which AWS Resources Can Be Protected
You can add protection for any of the following resource types:
Amazon CloudFront distributions
Amazon Route 53 hosted zones
AWS Global Accelerator accelerators
Application Load Balancers
Elastic Load Balancing (ELB) load balancers
Amazon Elastic Compute Cloud (Amazon EC2) Elastic IP addresses
Comparison Between Shield and Shield Advanced

How to Choose
You can use AWS WAF, AWS Firewall Manager, and AWS Shield together to create a comprehensive security solution.
Start with AWS WAF. You can automate and simplify AWS WAF using AWS Firewall Manager. Shield Advanced adds additional functionality on top of AWS WAF, such as support from the DDoS Response Team (DRT) and advanced reporting.
If you want fine-grained control over the protection added to your resources, using AWS WAF alone is the right choice. If you want to use AWS WAF across accounts, speed up your AWS WAF configuration, or automate protection for new resources, use Firewall Manager with AWS WAF.
Finally, if you have high-visibility websites or are prone to frequent DDoS attacks, you should consider purchasing Shield Advanced.
Pricing
AWS Shield Standard provides protection to all AWS customers against the most frequently occurring common network and transport layer DDoS attacks targeting websites or applications at no additional cost.
AWS Shield Advanced is a paid service that provides additional protection for internet-facing applications running on Amazon Elastic Compute (EC2), Elastic Load Balancing (ELB), Amazon CloudFront, AWS Global Accelerator, and Amazon Route 53. AWS Shield Advanced is available to all customers, but only AWS Premium Support Business or Enterprise support plan customers can contact the DDoS Response Team. It requires a 1-year subscription commitment, with a monthly fee of $3,000. Data transfer pricing is shown in the table below:

For further assistance or services, please leave a message. UltraPower Cloud Business will provide automation tools and professional services.

Back to Tech Blog