When you say GCP, Azure and AWS have the capacity to defy the ddos, what capacity are you reffering to?
Are you talking about actually scaling and serving the bogus requests? Or capacity to have enoough bandwith and firewall power to fend it off?
When you say GCP, Azure and AWS have the capacity to defy the ddos, what capacity are you reffering to?
Are you talking about actually scaling and serving the bogus requests? Or capacity to have enoough bandwith and firewall power to fend it off?
Shield (https://aws.amazon.com/shield/) is AWS's DDOS protection service. It's free and is basic protection against L3/4 attacks.
Shield Advanced (same URL as above) is a big step up in price, but gives you access to 'improved protection' and a global response team.
Cloudfront (https://aws.amazon.com/cloudfront) is a CDN with global edge locations.
WAF (https://aws.amazon.com/waf) is AWS's web application firewall service. It's less about DDOS and more about specific application attacks, but is part of the whole solution.
For more detail, you can have a look at AWS's DDOS whitepaper: https://d0.awsstatic.com/whitepapers/Security/DDoS_White_Pap...
You probably would have been better off using a cloud mitigator from the start. Their pricing is competitive when you factor in all of the costs.
They've very effective network level ddos detector/filtering