AWS Shield – Managed DDoS Protection
aws.amazon.com
aws.amazon.com
1.) They mention in the compare tiers "Application traffic monitoring" for Advanced. However in the FAQ: "In addition, customers can also use AWS WAF to protect against Application layer attacks". WAF is only available through CloudFront, and CloudFront charges 600 dollars a month for a custom SSL certificate with dedicated IP.
So do they have "Application traffic monitoring" outside of WAF? I'm lead to believe not.
2.) They mentioned multiple times you can call on the DRT team to help you. However buried in the FAQ is this little gem: "Response times for DRT depends on the AWS Support plan you are subscribed to".
So for 3k/mo I can't get better than 24/hr turnaround when I'm under attack without ALSO having a business/enterprise support plan?
"AWS Shield Advanced is available to customers who are enrolled in either the Enterprise or Business Support levels of AWS Premium Support."
Look like I'd need to pony up >1k/mo on top of 3k to get access to the service then...
So if you get hit by DDOS, you can't just pay $3,000 and hope that DDOS is gone within a month. Looks like you have to sign up for a year's worth of protection.
this is one thing that does not enjoy economies of scale. competent people working under pressure at 3AM on a holiday are extremely expensive.
would _you_ do that job? and how much do you get paid?
Amazon.com manages to have 24/7 chat support and they certainly aren't charging $3K/month. That's just the power of multi-tasking.
Most of the big names in DDoS protection, looking only at enterprise tier support, have tens of clients per network support tech minimum.
I feel like you're trying to mock him for being so self evidently wrong that it's (apparently) funny, but I don't see it. How does criticism of a support model lead to "then you do it"?
Or are you implying something else? That's what I hate about these coy between-the-lines replies in chat forums. It's not obvious and I don't know what to reply to! Just say what's on your mind, don't play games. Give the rest of us a chance to reply to something.
/rant, sorry :)
They're out there, you just have to look.
https://console.aws.amazon.com/support/plans/home?region=us-...
Enterprise tier's minimum is $15K by the way.
And the Business Tier lacks "Business-critical system down" support with a 15 minute response time. But it does have the "Production system down" level with a "less than 1 hour" response.[1]
AWS's support isn't cheap. And it isn't simply "$100/month" that's the minimum for real support (and no, developer tier isn't real support for production systems).
If you bought a rack of servers and storage from HP, IBM or Dell and wanted a tier that got you to an engineer in <15m, that would cost far more.
We have Enterprise level support which starts at $15,000/month and is very comprehensive. Then again we also have 90k employees.
https://console.aws.amazon.com/support/plans/home?region=us-...
This is a very big deal!
EDIT: Number is professional opinion from my experience running large AWS accounts over the last 10 years.
This is the first thing that I do any time I'm involved with a new infrastructure.
AWS desperately needs a way to turn off pay-by-use services through billing alerts. I don't believe this is possible right now.
Nice!
>Hardly any better.
...what?
Additionally: you can totally set up CloudWatch Alarms for billing events, it's one of the categories they provide out-of-the-box, and alarms can trigger notifications, lambdas, SQS, etc. So you can totally wire alarm -> lambda and have lambda spin down the thing costing you the money.
And doing it through Lambda is possible, but the friction there almost feels deliberate. They should make it a first-class option you don't need to wire together yourself.
AWS is the ultimate "wire it together yourself" tool. If that's _not_ what you're after, there are many other vendors eager to take your money.
It's a practically unlimited scale-to-the-moon platform that allows you to provision hundreds or thousands of virtualised bits of internet infrastructure in seconds or minutes - and automate it all.
All their "light pattern" UX is laser focused on allowing you to instantly provision all the capacity you ask for.
If you expect a UX oriented to "cost minimisation" or "potential user error protection", AWS is the wrong choice of tool. You can still use it, but what seems to you to be "Bad UX" or "dark patterns" can easily be explained as "you chose the wrong tool" if you view AWS from a different angle (and I'd argue, that angle is the one all AWS's 7 digit per month customers see it from, and hence the way the AWS team builds and prioritises everything)
They have decided to "resolve" this problem by using it as an opportunity to further gouge their customers on bandwidth (which is already 12x+ more expensive than market rate for IP transit), instead of absorbing it into their existing cost structure. Which still would have meant their bandwidth was overpriced, and still would be way higher than what you can get pretty much everywhere else.
For a contrast, OVH provides this protection as an included feature in all of their offerings. Before everyone writes it off as junk in comparison to the glorious AWS black box (AWS is amazing at marketing), bear in mind that the OVH scrubber just took a terabit DDoS attack against it and survived: http://www.securityweek.com/hosting-provider-ovh-hit-1-tbps-...
OVH correctly realizes that the only way to solve this problem is to make sure everybody gets access to it. Otherwise you're just encouraging the democratization of censorship for those without the means to protect themselves against it. I hope the "cloud" providers follow their example.
But yeah, it's interesting to learn there's a baseline anti-DDoS thing that's on by default.
I switched to AWS 1.5 years ago, and all my DDOS issues magically disappeared overnight.
And I don't understand which traffic they bill. Usually AWS bills outgoing traffic, but for DDOS costs only occur ingress, or am I wrong? Can't see from the price list what they'll actually bill (ingress or egress).
Let’s assume that you deploy an Amazon CloudFront Distribution in front of the Application Load Balancer from Example 3. You then enable AWS Shield Advanced protection for your Amazon CloudFront Distribution, and remove it from your Application Load Balancer. (If you have deployed Amazon CloudFront in front of Application Load Balancer, you only need to enable protection for Amazon CloudFront).
Under this scenario, at the end of the month, you will pay the AWS Shield Advanced monthly fee of $3,000. In addition to the monthly fee, you will be charged the AWS Shield Advanced usage based fee of $25 for the 1,000 GB of Regional Data Transfer out at $0.025 per GB. Your total AWS Shield charges for the month will be $3,000 + $25 = $3,025.
In addition, you will pay standard Application Load Balancer and Amazon CloudFront fees as described in the Application Load Balancer Pricing and Amazon CloudFront Pricing pages.
As if their existing margins on bandwidth aren't high enough.
Sure, protections like what OVH "already offers" when a DDOS attack downs their entire administrative portal?
It's clear to heavy AWS users that Amazon was already providing certain DDoS protections before this announcement.
For people who host their own servers or systems (or who cloud but not on AWS), this doesn't appear to be an option and you still have to go with Cloudflare.
And at Amazon that's just the ddos costs, the cdn and traffic cost extra.
> usage spikes on Elastic Load Balancing (ELB)
If traffic has reached the load balancer than it's probably reached your app. No ec2 / storage / traffic credits here.
> Amazon CloudFront
Neat. Like cloudflare but with less features though.
> or Amazon Route 53
DNS... Not really sure what to make of this one.
You only have to think back a couple of weeks to recall the DDos that took down Dyn:
https://news.ycombinator.com/item?id=12759697
DDos attacks DNS servers are pretty common, not least because a lot of hosting companies regard DNS as low priority.
I have an interest in Amazon's DNS setup, as I use it to provide my own git-based DNS hosting <https://dns-api.com> so I'll be curious to see how this works in practice myself.
If you are on AWS, you are already protected up to a certain size for free. This you can compare to a dosarrest, small 10,20,30 gbps attacks and yet you are getting it for free, at no cost! The advance opens you up to a team of actual ddos experts 24/7, this is meant for the serious players that cant afford interuptions or downtime.
If your worried about blogs and wiki stuff, use google's ddos shield which is free for bloggers and news outfits.
This is a huge deal people, i cant understand why there are people out here bashing it, what a joke.
Disclosure: I work at Google Cloud (but not in networking / would know the answer)
[1] https://www.lowendtalk.com/discussion/70274/hetzner-new-ex41...
[1] https://www.hetzner.de/en/hosting/unternehmen/rechenzentrum
Been a Hetzner customer for years now
I had several servers from them over the years without issues and great performance.
Never been DDOSed though...