🟡 Medium | Source: AWS Security Blog
AWS is integrating its new WAF Anti-DDoS managed rule group into Shield Advanced, providing automated, purpose-built protection against HTTP request flood attacks at the application layer. Launched in June 2025, this rule group is designed to detect and block DDoS traffic that closely mimics legitimate user behaviour. The change affects how Shield Advanced customers manage application-layer protections and requires preparation to avoid disruption.
Security Architect’s Take: Review your existing Shield Advanced application-layer protections and WAF rule configurations before the integration takes effect — specifically check for any custom rate-based rules that may conflict with or duplicate the new Anti-DDoS managed rule group, and test in count mode before switching to block to avoid false positives on legitimate traffic.
Original advisory: AWS Shield Advanced is embracing the AWS WAF Anti-DDoS managed rule group: What changes and how to prepare