The downside of course, is that whilst their infrastructure can likely handle it, handling the bill associated with 'just scale up your service' could be worse than the attack itself.
The downside of course, is that whilst their infrastructure can likely handle it, handling the bill associated with 'just scale up your service' could be worse than the attack itself.
Interestingly, the presenter notes that Amazon had seen a drop in DNS as an attack vector in 2015. I asked the presenter (Product Manager) why they hadn't productized the DDoS attack dashboard so you could be aware if you were being attacked (and it was being absorbed by AWS) and his response was that there was insufficient demand at that point to justify the developer staffing. He gave me his card and asked to request the feature so he could us it to make the case internally.
Does anyone here have stories of being successfully DDoS'd on AWS (other than by their own staff :) ?
If I am an AWS customer I expect AWS to handle/prevent DDoS, same way as they do with S3 to achieve 11 9's availability (the files are saved in multiple AZs in the same region - Glacier IIRC copy files on different regions to avoid data loss in case of physical disaster).
One of the reason for choosing AWS is because AMZ has deep pockets and has the means (financial and technical) to fight against large DDoS attacks, while a smaller provider might not have to do that. Putting clients in a position to have to buy that sort of protection doesn't sound very smart to me.
I see so many people confused about this. Eleven nines is their durability guarantee, their availability that they guarantee is only 99.99%
Durability is the % of your data that doesn't die. Eleven 9s means that if you store 1TB on AWS S3 you can expect to lose 10 bytes and still be within SLA.
i.e. you could expect to lose 10 bytes of your 1TB every year if your stored it as a trillion one byte objects, but if you stored it as a single object you could expect to lose the whole thing once every hundred billion years, but none of it the rest of the time.
As a very simplified example, imagine they are expecting to lose 2 servers every day, this percentage might be the probability of those two servers storing the same exact object (and thus, losing it irretrievably).
availability means you'll get your bits immediately.
If you are an AWS customer you should have done your due diligence and know that amazon won't do a very good job at that.
Someone will always have the upper hand in an arms race, and it's not service providers yet. It's just a matter of finding the choke point between their transit and your code.
Well, the whole point of AWS is not having to deal with the usual hosting stuff. They'll naturally have lots of customers with high expectations and very little understanding of how things work in the background.
Offtopic but relevant. One of my customer moved their email to O365 without understanding the differences from being ON-Prem. Now they are struggling to adopt their business processes to then limitations MS imposes.
If the attack is tiny, sure. Otherwise they'll just cut you off.
Yet they get to claim inexhaustible capacity.
Amazon might wave the fee, but you are the first party responsible.
> My website is on Blogger, Google Sites, or Google App Engine. Am I eligible?
> As Google products, these sites already have similar DDoS protection to Project Shield. Your website would not need to be set up with Project Shield.
Wonder if that answer includes Compute Engine. Doubt it.Unless we can somehow secure every net-connected devices, ha (I don't know whether to cry or laugh right now)
I find your language to be of high interest like you had a "dUH" moment - which I am ignorant to get myself.
The Sons rays meat
Is this analogy accurate?
I have one road to get home. It got blocked so I create 2 more roads.
I now have 3 Roads to get home. All 3 become blocked. So now I have to make another road.
More roads is redundancy and requires capital.
The roads become unblocked but I now must expect future road blocks.
If you want HA at local level you'd go with AWS AZs but if you need real HA you need can do the same at region-level.
Of course not everyone has the money/need to go down that route, but it's possible and even advised for some AWS services.