AWS Shield Advanced is incorporating the AWS WAF Anti-DDoS managed rule group to bolster its application-layer (L7) distributed denial of service (DDoS) protection. This new rule group will become the default and, over time, the exclusive method for L7 protection within Shield Advanced.
Starting July 27, AWS Shield Advanced will begin adding the Anti-DDoS managed rule group to eligible web access control lists (ACLs) in Count mode. This phased rollout is designed to occur without interrupting existing traffic or L7 automatic mitigation and WAF rules.
Application-layer DDoS attacks, such as HTTP request floods, are challenging to detect because they mimic legitimate user traffic. The Anti-DDoS managed rule group is specifically designed to address these attacks by profiling traffic, establishing baselines rapidly, and reacting to attacks within seconds.
The new rule group builds upon the existing capabilities of Shield Advanced automatic mitigation, offering quicker response times and eliminating the need for manual health check configurations.
A key feature of the Anti-DDoS managed rule group is the addition of a Challenge action, complementing the existing Block and Count actions. This Challenge action uses AMR labels to assess the suspicion level of requests. One implementation is a silent browser challenge, which verifies traffic in the background without interrupting legitimate users.
Users can also exclude specific workload paths from the Challenge action, allowing them to fall back to Block mitigations. The sensitivity for both Block and Challenge actions is configurable to Low, Medium, or High, and can be tuned independently to balance attack mitigation with avoiding legitimate request drops.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
AWS Shield Advanced is integrating the AWS WAF Anti-DDoS managed rule group as its default and eventually sole application-layer DDoS protection. This change, starting July 27, enhances detection and mitigation of HTTP request floods by profiling traffic and reacting within seconds, improving upon existing automatic mitigations.