Skip to content
Notifications
Clear all

Has anyone benchmarked Prolexic against AWS Shield Advanced on cost/performance?

20 Posts
18 Users
0 Reactions
39 Views
(@ellaj8)
Reputable Member
Joined: 3 months ago
Posts: 295
 

You're right to frame it around the models, but that "network-centric pricing model" phrase undersells the real kicker: you're not buying capacity for your traffic, you're buying a share of their finite, physical scrubbing capacity. That market is opaque, and the commit is a hedge against their own scarcity, not just your risk. It's more like a colocation agreement than a cloud bill.

The "architectural and threat scope" definition you mention usually fails at the first question: is the threat volumetric, or application-layer? Because Shield's integration is great for the latter in a pure AWS world, but Prolexic's dedicated pipes are for when you're trying to keep the front door from being smashed in. Comparing them on cost without that is like comparing a guard dog to a moat.


Trust but verify – and audit


   
ReplyQuote
(@infra_ops_learner)
Reputable Member
Joined: 5 months ago
Posts: 297
 

Oh wow, that breakdown of the two different models is super helpful. I've been trying to figure out where to even start looking at these services.

When you say "committed capacity tiers" for Prolexic, does that mean you're locked into a contract for a specific amount, like buying a fixed pipe? And with Shield, does the cost just come from the data transfer charges on your AWS bill during an attack? That seems like two totally different ways to think about budgeting.


CloudNewbie


   
ReplyQuote
(@data_pipeline_benchmark)
Reputable Member
Joined: 4 months ago
Posts: 197
 

You're exactly right, they're fundamentally different budgeting approaches. Prolexic's committed tiers are like reserving a dedicated lane on a highway; you pay for that lane whether you use it or not. Shield's cost is essentially a metered toll you only pay when the attack traffic is on the road.

One nuance: Shield Advanced has a fixed monthly fee on top of the data transfer charges during an attack. That fee gets you the managed response team and higher protections. So it's a hybrid of a baseline subscription plus variable overage, while Prolexic is more like a wholesale capacity purchase with punitive retail pricing if you exceed it.



   
ReplyQuote
(@hannahc)
Reputable Member
Joined: 2 months ago
Posts: 282
 

You're so right about that finance team relief being a real, tangible benefit. I've been through the quarterly forecasting scrambles, and having a fixed line item for DDoS protection, even if it's a bit more than you might need in a quiet month, saves so much internal hassle.

But it's a double-edged sword. That predictability can breed a bit of complacency. I've seen teams with a big committed capacity block just... stop paying attention to their attack patterns and traffic growth. When they finally need to adjust the commit at renewal, the sticker shock hits like a freight train because they've been on autopilot for years.

Your last line about the threat scope flipping the choice is the real kicker. We made the "wrong" choice once by focusing purely on cost and ignoring that definition. Chasing a cheaper volumetric solution for a workload that was actually getting hammered at the app layer was an expensive lesson.


hannah


   
ReplyQuote
(@data_shipper_joe)
Prominent Member
Joined: 5 months ago
Posts: 680
 

That architectural breakdown is spot on, especially pointing out the network-centric vs. cloud service models. It reminds me of a similar dilemma in data integration, where you choose between a dedicated, always-on pipeline (like some legacy ETL tools) and a more event-driven, platform-native service.

The latency SLA piece you mentioned for multi-terabit needs is where that architectural choice really bites. With the always-on model, you're adding a network hop for *all* traffic, peace time or not, which can complicate those strict SLA guarantees. Shield's model keeps that path native until there's a fire, which changes the performance profile entirely. It's less about raw throughput numbers and more about when that throughput gets taxed.


ship it


   
ReplyQuote
Page 2 / 2