AWS Security Blog

Tag: DDoS attacks

AWS Shield Advanced is embracing the AWS WAF Anti-DDoS managed rule group: What changes and how to prepare

Application-layer distributed denial of service (DDoS) attacks are difficult to detect because they closely resemble legitimate traffic. HTTP request floods are now among the most common vectors targeting web applications, using valid-looking requests that blend in with normal user activity. In June 2025, AWS launched the AWS WAF Anti-DDoS managed rule group, built specifically for […]

How to customize your response to layer 7 DDoS attacks using AWS WAF Anti-DDoS AMR

Over the first half of this year, AWS WAF introduced new application-layer protections to address the growing trend of short-lived, high-throughput Layer 7 (L7) distributed denial of service (DDoS) attacks. These protections are provided through the AWS WAF Anti-DDoS AWS Managed Rules (Anti-DDoS AMR) rule group. While the default configuration is effective for most workloads, […]

Now You Can Monitor DDoS Attack Trends with AWS Shield Advanced

July 29, 2025: AWS Shield Advanced has expanded its DDoS protection suite by introducing Automatic Application Layer DDoS Mitigation, along with new capabilities like protection groups and mitigation metrics to improve and monitor DDoS attack detection and mitigation. These enhancements build upon the original Global Threat Environment Dashboard, providing users with more comprehensive tools to […]