Security
AWS Shield
DDoS Protection, Shield Standard (Free), Shield Advanced, DRT, Cost Protection
Giới thiệu
AWS Shield là managed DDoS protection service bảo vệ ứng dụng chạy trên AWS khỏi các cuộc tấn công DDoS (Distributed Denial of Service).
DDoS Attack Types
| Layer | Attack Type | Ví dụ |
|---|---|---|
| Layer 3 (Network) | Volumetric | UDP floods, ICMP floods |
| Layer 4 (Transport) | Protocol | SYN floods, TCP connection attacks |
| Layer 7 (Application) | Application | HTTP floods, DNS query floods |
Shield Standard vs Advanced
So sánh chi tiết
| Feature | Shield Standard | Shield Advanced |
|---|---|---|
| Giá | ✅ FREE | $3,000/tháng + DTO |
| Protection | Layer 3, 4 | Layer 3, 4, 7 |
| Detection | Always-on | Always-on + Enhanced |
| Mitigation | Automatic | Automatic + Custom |
| DRT Access | ❌ | ✅ 24/7 |
| Cost Protection | ❌ | ✅ |
| Real-time Visibility | Basic | ✅ Advanced |
| WAF Integration | ❌ | ✅ Included |
| Commitment | None | 1 year |
Shield Standard
Shield Advanced
Protected Resources
| Resource | Standard | Advanced |
|---|---|---|
| Amazon CloudFront | ✅ | ✅ |
| Amazon Route 53 | ✅ | ✅ |
| AWS Global Accelerator | ✅ | ✅ |
| Elastic Load Balancing | ✅ | ✅ |
| Amazon EC2 | ✅ | ✅ |
| Elastic IP | - | ✅ |
Tip: Đặt CloudFront/Route 53 phía trước để tận dụng Shield Standard tối đa!
DDoS Response Team (DRT)
DRT = Đội ngũ chuyên gia DDoS của AWS (chỉ có với Shield Advanced)
| Feature | Chi tiết |
|---|---|
| Availability | 24/7/365 |
| Contact | Phone, chat, ticket |
| Proactive engagement | Tự động liên hệ khi phát hiện attack |
| Custom mitigations | Viết rules riêng cho ứng dụng của bạn |
Khi nào DRT giúp?
Pricing
Shield Standard
- FREE - Tự động bật cho tất cả AWS customers
Shield Advanced
| Component | Chi phí |
|---|---|
| Monthly fee | $3,000/tháng/organization |
| Commitment | 1 năm |
| Data Transfer Out | Varies by resource |
| WAF | ✅ Included (up to 50B requests) |
Cost Protection (Advanced)
Nếu DDoS attack gây ra scaling charges, AWS sẽ credit lại:
So sánh Shield vs WAF vs Firewall Manager
| Shield | WAF | Firewall Manager | |
|---|---|---|---|
| Purpose | DDoS protection | Web app security | Central management |
| Layer | 3, 4, 7 | 7 only | N/A (management) |
| Attack type | DDoS | SQL injection, XSS, bots | N/A |
| Pricing | Free / $3K/mo | Per rule, request | Per policy |
Exam Tips
Key Points
| Câu hỏi | Đáp án |
|---|---|
| "DDoS protection miễn phí?" | Shield Standard |
| "24/7 DDoS response team?" | Shield Advanced |
| "Cost protection from DDoS scaling?" | Shield Advanced |
| "Layer 7 DDoS protection?" | Shield Advanced |
| "Protect against SQL injection?" | WAF (không phải Shield) |
Nhớ
Phân biệt
| Scenario | Service |
|---|---|
| Block DDoS attacks | Shield |
| Block SQL injection | WAF |
| Block specific IPs | WAF or Security Group |
| Manage across multiple accounts | Firewall Manager |