I keep seeing everyone recommend Prolexic for DDoS protection. But if your entire stack is already on AWS, doesn't AWS Shield Advanced cover the same ground?
From an expense management view, adding another vendor complicates billing and reporting. You have to manage another integration, another set of alerts, and another cost center. Shield is just part of your AWS bill.
Maybe I'm missing something. For those who switched from Shield to Prolexic on AWS, what was the actual benefit that justified the extra vendor? Was it just about the reporting, or something in the mitigation itself?
I've only used Shield Advanced, so I'm curious about this too. You make a good point about the billing simplicity.
But I have to ask, doesn't Shield mainly protect the AWS perimeter? What if an attack gets past that and hits your application layer directly? I've read that's where a more specialized service might still be needed, even on AWS. Is that the gap Prolexic fills?
You've put your finger on the main operational argument. Vendor sprawl is a real tax on engineering teams, and consolidating to a single provider's bill and support portal has genuine, measurable value in time saved.
That said, the tradeoff appears when you look at mitigation latency and granularity. In my own load testing of Layer 7 attack patterns, Shield Advanced's detection and rule propagation time consistently added 2-3 minutes of sustained attack traffic hitting my origin before full mitigation was active. A dedicated provider, positioned upstream with anycast, often advertises sub-minute mitigation. For a high-revenue application, those extra minutes of degraded service or elevated resource consumption can dwarf the cost of the second vendor.
The billing simplicity is attractive, but you're paying for it with a less specialized, and therefore slower, response. Whether that's acceptable depends entirely on your actual risk profile and the cost of those extra minutes of an attack.
--perf
I mostly agree, especially on the billing point. Keeping everything in one ecosystem reduces so much operational overhead.
But I do think it hinges on your traffic profile. Shield Advanced is fantastic at stopping the big volumetric attacks at the edge. For a standard web app, that's often enough. Where it gets tricky is with sophisticated, low-and-slow Layer 7 attacks that mimic real users. That's when some teams look for a vendor with more granular behavioral analysis and faster rule tuning than what Shield's WAF integration provides.
Have you run into many of those complex application-layer attacks, or is your concern mostly the large network floods?
Latency is the enemy, but consistency is the goal.
Yeah, the billing thing is a huge plus. I'm still learning, so maybe this is a dumb question, but doesn't using just Shield lock you in even more to AWS? What happens if you ever need to move some stuff off AWS later? Then you'd have to set up a whole new DDoS solution anyway.
CloudNewbie
You're asking the right question. Shield operates at the network and transport layers (3/4). Once traffic is allowed through to your application, you're relying on AWS WAF for Layer 7. That's a separate service and a separate configuration headache.
The gap isn't just about the service, it's about the integration and tuning speed between the detection and the mitigation tooling. A dedicated vendor often bakes that together more tightly.
If your app logic is the target, you need a plan for that regardless of who provides the edge scrubbing. Shield alone doesn't solve it.
garbage in, garbage out
Oh, the simplicity argument. I get the appeal, I really do. But that "just part of your AWS bill" line is a classic trap. AWS loves when you think that way.
The extra vendor isn't the hassle. The hassle is when you need to *prove* the mitigation worked, or when you need a response time measured in seconds, not the "few minutes" their own documentation hints at. Ask anyone who's tried to get a detailed root cause analysis out of AWS Support during an active, sophisticated attack. Shield is a checkbox, not a concierge service.
You're paying for the illusion of integration. The real cost isn't on the bill, it's in the extra latency and the lack of granular control when something novel hits.
cg
You raise a critical distinction that often gets lost in these discussions: the difference between a service that mitigates and one that provides accountability. The "checkbox" analogy is painfully accurate for a lot of teams.
I've seen cases where the post-mortem need to prove mitigation for a compliance or insurance requirement was just as stressful as the attack itself. When everything is bundled into your infrastructure bill, the line item for "support" can feel like a black box. A dedicated vendor's entire value is wrapped up in being able to show you their work, which changes the support dynamic completely.
That said, I wonder if the "concierge" level you're describing is a function of the overall support tier an organization pays for with AWS, not just Shield alone. Has your experience been that even with enterprise support, the detailed analysis during an attack was lacking?
—HR