Security & IAM
AWS Shield
AWS Shield provides managed distributed-denial-of-service protection: Shield Standard is automatically included for supported AWS resources, while Shield Advanced adds expanded detection, mitigation, visibility, cost protections, and Shield Response Team support.
Explore pricing models, common use cases, infrastructure support, and the AWS services that commonly work with AWS Shield.
AWS Shield pricing and cost programs
Pricing model: Included standard protection or subscription
- On-Demand
- Service-specific
- Reserved Instances or reserved capacity
- Not applicable
- Savings Plans
- Not applicable
- Spot
- Not applicable
Billing dimensions: Protection tier · Protected resources · Data transfer and acceleration
Programs and modes: Shield Standard · Shield Advanced subscription
Shield Standard is included with AWS accounts; Shield Advanced is a term subscription with additional resource charges.
Free Tier: Not applicable — verify current offers
Pricing reviewed 2026-07-25. Reviewed against the linked official AWS pricing page. Recheck regional rates and program terms before purchase.
Official AWS sources reviewed 2026-07-21.
Why implement AWS Shield?
- Shield Standard provides automatic baseline network and transport-layer DDoS protection for supported AWS services at no additional Shield charge.
- Shield Advanced adds more sensitive detection and mitigation, application-layer protections, attack diagnostics, and engagement with the Shield Response Team for eligible resources and support plans.
- Integrates with CloudFront, Route 53, Global Accelerator, load balancers, Elastic IP addresses, WAF, health checks, CloudWatch, and Firewall Manager.
How to implement AWS Shield
- Start with a DDoS-resilient architecture using scalable endpoints, distributed edge services, origin restrictions, caching, health checks, WAF, quotas, observability, and a response runbook.
- If risk and cost justify Shield Advanced, subscribe in the appropriate payer context, explicitly add every eligible resource, configure WAF protections, alarms, and DDoS cost-protection prerequisites.
- Associate accurate Route 53 health checks, configure and maintain 24-hour response contacts and proactive engagement where eligible, then run tabletop and controlled resilience exercises.
AWS Shield best practices
- Do not confuse automatic Shield Standard coverage with complete application resilience; protect origins, capacity dependencies, DNS, authentication, and business-level abuse paths.
- For Shield Advanced, protect all related eligible resources, use health-based detection, keep proactive-engagement contacts current, and understand support-plan and resource eligibility.
- Combine Shield with tuned WAF and architectural controls, baseline normal traffic, alarm on availability and DDoS metrics, rehearse escalation, and preserve event evidence for review.
AWS Shield use cases and server impact
- Public web and API DDoS resilience
- High-visibility event and commerce protection
- Critical DNS, acceleration, and load-balancer protection
Replaces much edge DDoS appliance capacity and specialist mitigation infrastructure, but resilient design, WAF tuning, health checks, incident command, and application recovery remain customer responsibilities.
Official implementation resources
Commonly paired AWS services
- AWS WAF — Web app firewall
- Amazon CloudFront — Global CDN
- Elastic Load Balancing — Load balancing
- Amazon Route 53 — DNS & routing
- AWS Global Accelerator — Global traffic acceleration
- Amazon CloudWatch — Metrics & logs
- AWS Firewall Manager — Central firewall policy management