No more typing reviews! Try our Samantha, our new voice AI agent.

AWS Shield vs Arbor DDoS comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 5, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Arbor DDoS
Ranking in Distributed Denial-of-Service (DDoS) Protection
3rd
Average Rating
8.8
Reviews Sentiment
6.9
Number of Reviews
57
Ranking in other categories
No ranking in other categories
AWS Shield
Ranking in Distributed Denial-of-Service (DDoS) Protection
10th
Average Rating
8.6
Reviews Sentiment
6.8
Number of Reviews
10
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of September 2026, in the Distributed Denial-of-Service (DDoS) Protection category, the mindshare of Arbor DDoS is 5.7%, down from 11.7% compared to the previous year. The mindshare of AWS Shield is 3.0%, down from 5.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Distributed Denial-of-Service (DDoS) Protection Mindshare Distribution
ProductMindshare (%)
Arbor DDoS5.7%
AWS Shield3.0%
Other91.3%
Distributed Denial-of-Service (DDoS) Protection
 

Featured Reviews

reviewer1331304 - PeerSpot reviewer
Director Of Research And Development at a comms service provider with 11-50 employees
Automated threat intelligence and flow-based mitigation have improved our DDoS defense
A very useful feature in Arbor DDoS is its ability to send flow spec announcements to routers. For example, if it is clear that a Layer 3 or Layer 4 attack is occurring and the attack pattern is identified through source and destination IP addresses and ports, you can generate flow spec filters. These filters are transferred through BGP to border routers, which automatically build filters, mitigating the attack even at the network's boundary and preventing it from reaching the TMS. This allows the TMS to focus on other tasks. This is a highly effective feature that can mitigate huge volumetric attacks; for example, we experienced a 32-gigabit attack, and all those 32 gigabits were dropped by our border routers, not by Arbor DDoS itself. The flow spec announcement was generated by Arbor DDoS, and as far as I know, the same technology is used by Radware, but it comes under a different feature and a different license. At the time, we were told that flow spec mitigation was an additional very expensive license to purchase from Radware, while Radware included everything in one package.
Pranav Telang - PeerSpot reviewer
DGM at Airtel Digital
Has enabled multi-layered threat mitigation but still lacks deeper visibility for advanced application attacks
AWS Shield has limited coverage as it only protects against common and high-volume network and transport layer attacks, such as SYN floods. It does not provide inherent protection against more sophisticated layer 7 attacks such as HTTP floods. In such cases, integration with WAF is necessary, which results in additional costs for customers. To protect layer 7, layer 4, and layer 3, customers must implement both solutions. The service also has difficulties with static detection thresholds, which may not be sensitive enough to detect smaller application-specific attacks. While AWS Shield is a key security service, AWS should enhance their expert support with 24/7 response for complex attacks, which is currently limited.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"I highly recommend Arbor DDoS to others."
"The auto-mitigation, that signaling feature, where it automatically raises an alarm that a line is under attack, is important. The upstream service provider will then do something to reduce the load on our internet lines. The fact that it's automated means I don't have to sit and always be looking at threats coming through. It does it almost automatically, without any intervention by me."
"With Arbor, when we see DDoS attacks, it is fully mitigating the attacks."
"The feature I find most valuable is the packet capture, which beautifully shows the communication between the client and the server, identifying potential malicious activity."
"It's very user-friendly."
"Arbor DDoS's best feature is that we can put the certificates in, and it will look at layer seven and the encrypted traffic and do the required signaling."
"It provides packet capture and we can block or whitelist whichever IPs we need to. Whatever traffic we want to block - and we get IPs from internal teams and from national teams - we block at the Arbor level only, because if it gets to the firewall then firewall bandwidth will be taken."
"The stateless device format means that the box is very strong for preventing DDoS attacks."
"We have integrated the tool with Active Directory. The most important feature is that it's transparent and doesn't degrade the performance of our solution. Additionally, it's easy to configure, which is crucial for us. It's easy to use and set up and stops attacks on our servers. We haven't encountered any attack problems because the solution stops them in real-time. AWS Shield specifically focuses on defending against denial-of-service attacks, making it a great solution for that type of threat."
"The automatic detection and mitigation of DDoS attacks in the product operates in real-time and provides satisfactory results."
"I am impressed with the product's multiple features like security."
"The solution's ease of use is the most valuable feature."
"It is integrated with AWS. So, it gives you a good first step."
"If most of your internet presence from your application side is in AWS, AWS Shield is a great option."
"The product has a good mechanism to analyze trends and trigger events."
"AWS Shield is aligned with the web application firewall (WAF), and they work seamlessly together, primarily working with Elastic Load Balancer, CloudFront, and Route 53 for CDN and DNS services protection."
 

Cons

"On the main page there are alerts that we are unable to clear, even though the issue has been resolved."
"Arbor DDoS has some difficult pricing rules. For many different small features, we have to pay additional fees for every small feature."
"I would also like more visibility into their bad actor feeds, their fingerprint feeds. We try to be good stewards of the internet, so if there are attacks, or bad actors within our networks, if there were an easier way for us to find them, we could stop them from doing their malicious activity, and at the same time save money."
"There are some price issues with scalability, but technically speaking, the solution is fully scalable."
"The product could have end-to-end platform visibility."
"There is definitely room for improvement in third-party intelligence and integrations."
"A small improvement could be a better reporting system."
"Based on my experience and feedback from colleagues, Arbor can make better use of the product because you have to spend a lot of time finding information in a huge number of papers."
"The management of it is a bit hard. If you don't engineer it on the front side, it is hard to go back in and change it. It could be improved in terms of architecture requirements and then ongoing support requirements as a secondary component to it. People tend to set up things like this, and they just expect it to work without the care and feeding that needs to go back into it either from an application team or a network environment team."
"The product needs to improve its logs and reports to make it read better."
"There is an area for improvement regarding health checks. AWS Shield does not come with its own health check functionality."
"AWS Shield has limited coverage as it only protects against common and high-volume network and transport layer attacks, such as SYN floods."
"The product is expensive."
"We end up having to pay extra for features that AWS adds that we don't need."
"The product should give users more flexibility to customize their security policies according to their requirements."
"AWS Shield Standard requires improvement, particularly regarding its dashboard since it currently provides limited coverage against comprehensive DDoS attacks."
 

Pricing and Cost Advice

"The price of Arbor DDoS depends on many parameters. It depends on the physical capacity of the environment, and it is not a straight-line price. It's fairly competitive in the market on the price."
"Arbor's products are very expensive. Their competitors are cheap when compared with Arbor."
"We do not use the Arbor Cloud DDoS solution because it is too costly."
"You need to find a way to get a good offering from Arbor by negotiating a price. That is the challenge."
"The solution's pricing is based on a licensing model that is expensive when compared to other tools."
"Pricing is slightly on the higher side."
"Arbor is striking a good balance between pricing and what they deliver."
"Start with a small license. Measure your bandwidth requirements."
"We pay $3000 per month for the solution."
"The tool is cheap."
"The tool's pricing is good."
"The cost depends on traffic each month, so on average, it costs us between US$200 and US$300 per month."
"It depends on your subscription level and the volume that you're spending with AWS. So, it is very relative to the consumption alignment in your subscription level. It is a well-constructed, scalable pricing option, but it is relative to how much you're spending on AWS. Because the more you spend, typically, the more you get off on services like this. I find it to be comparable to other solutions."
report
Use our free recommendation engine to learn which Distributed Denial-of-Service (DDoS) Protection solutions are best for your needs.
914,262 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
14%
Comms Service Provider
12%
Outsourcing Company
11%
Construction Company
6%
Comms Service Provider
18%
Computer Software Company
9%
Construction Company
7%
Financial Services Firm
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business26
Midsize Enterprise14
Large Enterprise29
By reviewers
Company SizeCount
Small Business3
Midsize Enterprise1
Large Enterprise7
 

Questions from the Community

Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
I would say if it’s an ISP that will build a scrubbing center, Netscout/Arbor is a good solution. In all other solutions, Imperva is a great choice.
Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Arbor would be the best bid, apart from Arbor, Palo Alto and Fortinet have good solutions. As this is an ISP, I would prefer Arbor.
What is your experience regarding pricing and costs for Arbor DDoS?
The prices for Arbor DDoS are expensive. The licensing is subscription-based. From our sales department, they discuss that prices are very high.
What is your experience regarding pricing and costs for AWS Shield?
The pricing structure for AWS Shield is fair, yet it depends on the specific protections chosen. Enabling Shield Advanced on multiple services such as CloudFront, network load balancer, or Route 53...
What needs improvement with AWS Shield?
Services always benefit from improvements, including AWS Shield. With respect to the Web Application Firewall, current rule-based setups may not be adequately defined or classified. Enhancement of ...
What is your primary use case for AWS Shield?
What do you use it for? How do you use it?
 

Comparisons

 

Also Known As

Arbor Networks SP, Arbor Networks TMS, Arbor Cloud for ENT
No data available
 

Overview

 

Sample Customers

Xtel Communications
netflix, dow jones, mapbox, pearson, rovio, youview, moviestar planet, asurion, payplug, hour of code
Find out what your peers are saying about AWS Shield vs. Arbor DDoS and other solutions. Updated: September 2026.
914,262 professionals have used our research since 2012.