AWS Shield Advanced Adopts WAF Anti-DDoS Managed Rule Group
This post details how AWS Shield Advanced is integrating the AWS WAF Anti-DDoS managed rule group as its default application-layer protection, replacing the existing automatic mitigation feature. This change aims to improve DDoS attack detection and mitigation speed by profiling traffic and learning baselines more rapidly, responding within seconds. The new rule group offers configurable sensitivity, lower capacity unit consumption, and improved cost visibility, with a phased rollout scheduled from July 2026 to January 2027, after which the legacy mitigation will be sunset. Eligible Shield Advanced subscribers and other AWS WAF users can utilize this new capability.
- →AWS Shield Advanced to use WAF Anti-DDoS managed rule group
- →New mitigation capabilities and configuration options
- →Improved resource utilization and cost benefits
- →Enhanced visibility and labeling
- →Phased rollout and migration plan
Enhancements (2) ›
- New mitigation capabilities and configuration options
The Anti-DDoS managed rule group introduces a Challenge action alongside existing Block and Count options, leveraging AMR labels to determine suspicion levels. It allows for silent browser challenges and supports excluding specific workload paths. Sensitivity is configurable independently for Block and Challenge actions across Low, Medium, and High settings.
- Improved resource utilization and cost benefits
The new rule group requires significantly less capacity (50 WCUs) compared to the previous protection (150 WCUs), freeing up capacity for other rules. During active mitigation, blocked DDoS requests are excluded from monthly billing for AWS WAF request fees, Anti-DDoS managed rule group fees, and Shield Advanced charges.
Notes (4) ›
- AWS Shield Advanced to use WAF Anti-DDoS managed rule group
AWS Shield Advanced is adopting the AWS WAF Anti-DDoS managed rule group for application-layer (L7) DDoS protection. This new rule group offers enhanced traffic profiling, learning normal traffic baselines in minutes and reacting to attacks within seconds, unlike the previous system that required longer baselining periods. It will become the default and eventually the only application-layer protection option for Shield Advanced.
- Enhanced visibility and labeling
A dedicated dashboard is now available in the AWS Management Console for AWS WAF, displaying live DDoS events, match metrics, and top traffic drivers. All inspected requests are labeled with event detection, suspicion levels, and specific rule matches, enabling custom logic in AWS WAF rules.
- Phased rollout and migration plan
The integration is occurring in five phases, beginning with the rule group deployment in Count mode (July 27–August 7, 2026), followed by a free evaluation period (July 27–September 30, 2026). An auto-upgrade for eligible web ACLs starts October 1, 2026, with guided migration options available until December 31, 2026. The legacy Shield Advanced application-layer automatic mitigation will be sunset on January 1, 2027.
- Comparison with legacy mitigation
The Anti-DDoS managed rule group offers faster detection and mitigation, works per web ACL, and provides configurable sensitivity, unlike the resource-specific Shield Advanced automatic mitigation which lacked sensitivity controls and had a longer baseline period.
https://aws.amazon.com/blogs/security/aws-shield-advanced-is-embracing-the-aws-waf-anti-ddos-managed-rule-group-what-changes-and-how-to-prepare/
Related releases
- Terraform AWS Provider v6.60.0 Adds New Resources and Fixes Bugs Terraform AWS Provider Releases ·
- Amazon S3 enhances access denied errors with specific policy ARNs AWS What's New ·
- OpenAI Daybreak Red and Blue Cyber Defense Models Now on Amazon Bedrock AWS What's New ·
- AppFolio Transforms Data Streaming with Amazon MSK Express Brokers AWS Big Data Blog ·
- AWS IAM Role Manager Automates Service Role Setup AWS What's New ·
- Amazon Quick Integrates Microsoft Purview for Data Loss Prevention AWS What's New ·