The Cloud Faces Real Threats
Every service connected to the internet is a potential target. The cloud is no exception.
Attackers try to find weaknesses in websites, launch massive floods of fake traffic to knock services offline, and quietly conduct suspicious activity inside compromised accounts.
AWS provides specialized services to counter each of these threats. This guide explains each one in plain language.
---
Think of a Multi-Layer Home Security System
A single lock on your front door is not enough to protect a home. You need multiple layers of protection.
A security filter at the door (AWS WAF): checks every visitor before they can enter and blocks suspicious ones on the spot. A flood barrier (AWS Shield): keeps the house safe even when an enormous wave of water (traffic) crashes in all at once. An AI security camera system (Amazon GuardDuty): watches everything around the house 24/7 and automatically flags unusual patterns.
These three services are the core of AWS threat defense.
---
AWS WAF — A Shield Against Web Attacks
WAF stands for Web Application Firewall. In simple terms, it inspects every request coming into your website and filters out dangerous ones before they can cause harm.
What kinds of attacks does it stop?
SQL injection is when an attacker types special code into a login form instead of a password, trying to trick the database into handing over sensitive information or granting admin access.
XSS (Cross-Site Scripting) is when an attacker sneaks malicious code into a web page so that it runs in the browsers of people who visit the page, stealing their data without them knowing.
AWS WAF is placed in front of Amazon CloudFront, Application Load Balancer, or Amazon API Gateway. You can write your own custom rules or use ready-made AWS Managed Rules.
---
AWS Shield — Defense Against DDoS Attacks
A DDoS (Distributed Denial of Service) attack is when thousands of computers all send requests to one server at the same time, overwhelming it until it crashes. Imagine thousands of people blocking the entrance of a store so that no real customers can get in.
AWS Shield comes in two versions.
Shield Standard is free. It is automatically applied to every AWS customer with no setup required. It protects against the most common types of DDoS attacks.
Shield Advanced is a paid service. It handles larger, more sophisticated attacks. It also includes real-time attack notifications, access to a 24/7 specialist DDoS Response Team (DRT), and a cost protection feature — if a DDoS attack causes your AWS bill to spike, that extra cost can be reimbursed.
---
Amazon GuardDuty — Automatic Threat Detection
GuardDuty continuously watches everything happening in your AWS account and automatically flags suspicious behavior.
What does it analyze? It reads AWS CloudTrail logs (who did what), VPC Flow Logs (network traffic), and DNS logs (which domains were contacted).
What kind of threats does it catch? An account that always logs in from one country suddenly accessing from a suspicious foreign IP. An internal server secretly communicating with a known malicious IP address. Someone trying to export large amounts of data to the outside.
The key point: GuardDuty requires no complex setup and no agent installation. You simply click the "enable" button, and it starts working immediately.
---
Other Useful Services to Know
| Service | What It Does | |---------|-------------| | AWS Network Firewall | Filters network traffic at the VPC (virtual network) level | | AWS Firewall Manager | Manages firewall rules across multiple AWS accounts from one central place | | Amazon Detective | When GuardDuty finds suspicious activity, Detective helps you investigate the root cause |
---
Side-by-Side Comparison
| Service | What It Protects Against | How It Works | |---------|--------------------------|-------------| | AWS WAF | Web attacks (SQL injection, XSS, etc.) | Inspects and filters individual web requests | | AWS Shield | DDoS attacks (massive traffic floods) | Absorbs and disperses malicious traffic | | Amazon GuardDuty | All malicious activity within the account | Analyzes logs and patterns for anomalies |
!AWS WAF, Shield, and GuardDuty compared
Exam Key Points
"Block SQL injection and XSS web attacks" → AWS WAF "DDoS protection, free and automatic for all customers" → AWS Shield Standard "DDoS protection plus 24/7 response team and cost protection" → AWS Shield Advanced "Automatically detect malicious activity using log analysis" → Amazon GuardDuty "Manage firewall rules across multiple accounts centrally" → AWS Firewall Manager Shield Standard is free and auto-applied — you do not need to enable it GuardDuty works immediately after enabling — no agent installation required