No more typing reviews! Try our Samantha, our new voice AI agent.

AWS Shield vs Arbor DDoS comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 5, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Arbor DDoS
Ranking in Distributed Denial-of-Service (DDoS) Protection
3rd
Average Rating
8.8
Reviews Sentiment
6.9
Number of Reviews
57
Ranking in other categories
No ranking in other categories
AWS Shield
Ranking in Distributed Denial-of-Service (DDoS) Protection
10th
Average Rating
8.6
Reviews Sentiment
6.8
Number of Reviews
10
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of September 2026, in the Distributed Denial-of-Service (DDoS) Protection category, the mindshare of Arbor DDoS is 5.7%, down from 11.7% compared to the previous year. The mindshare of AWS Shield is 3.0%, down from 5.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Distributed Denial-of-Service (DDoS) Protection Mindshare Distribution
ProductMindshare (%)
Arbor DDoS5.7%
AWS Shield3.0%
Other91.3%
Distributed Denial-of-Service (DDoS) Protection
 

Featured Reviews

reviewer1331304 - PeerSpot reviewer
Director Of Research And Development at a comms service provider with 11-50 employees
Automated threat intelligence and flow-based mitigation have improved our DDoS defense
A very useful feature in Arbor DDoS is its ability to send flow spec announcements to routers. For example, if it is clear that a Layer 3 or Layer 4 attack is occurring and the attack pattern is identified through source and destination IP addresses and ports, you can generate flow spec filters. These filters are transferred through BGP to border routers, which automatically build filters, mitigating the attack even at the network's boundary and preventing it from reaching the TMS. This allows the TMS to focus on other tasks. This is a highly effective feature that can mitigate huge volumetric attacks; for example, we experienced a 32-gigabit attack, and all those 32 gigabits were dropped by our border routers, not by Arbor DDoS itself. The flow spec announcement was generated by Arbor DDoS, and as far as I know, the same technology is used by Radware, but it comes under a different feature and a different license. At the time, we were told that flow spec mitigation was an additional very expensive license to purchase from Radware, while Radware included everything in one package.
Pranav Telang - PeerSpot reviewer
DGM at Airtel Digital
Has enabled multi-layered threat mitigation but still lacks deeper visibility for advanced application attacks
AWS Shield has limited coverage as it only protects against common and high-volume network and transport layer attacks, such as SYN floods. It does not provide inherent protection against more sophisticated layer 7 attacks such as HTTP floods. In such cases, integration with WAF is necessary, which results in additional costs for customers. To protect layer 7, layer 4, and layer 3, customers must implement both solutions. The service also has difficulties with static detection thresholds, which may not be sensitive enough to detect smaller application-specific attacks. While AWS Shield is a key security service, AWS should enhance their expert support with 24/7 response for complex attacks, which is currently limited.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The AI capabilities and anomaly detection using machine learning modules like isolation forests and auto-encoders are the most effective in mitigating DDoS attacks."
"The most valuable feature is mitigation, which can blackhole the IP."
"Without Arbor, we'd probably be around 75 to 80 percent uptime."
"It's very flexible and we can easily deploy it to our network. It's very user-friendly. We can do everything via the web interface and troubleshoot easily from the CLI. It's not complicated."
"The solution is easy to use."
"The artificial intelligence feature is most appreciated. This solution can lower the throughput and clear the traffic, which is something really important for us. It also provides good protection. It is user-friendly, and its integration has also been really fast. We have many critical applications, and it was easy to integrate Arbor DDoS with our website, mobile application, and web banking."
"The solution provides good protection against volumetric DDoS attacks."
"It provides packet capture and we can block or whitelist whichever IPs we need to. Whatever traffic we want to block - and we get IPs from internal teams and from national teams - we block at the Arbor level only, because if it gets to the firewall then firewall bandwidth will be taken."
"The product is easy to use."
"AWS Shield is aligned with the web application firewall (WAF), and they work seamlessly together, primarily working with Elastic Load Balancer, CloudFront, and Route 53 for CDN and DNS services protection."
"The solution operates smoothly at its baseline level, and we do not encounter any issues at that level."
"The product has a good mechanism to analyze trends and trigger events."
"It is quite scalable, and we have not faced any issues with its scalability."
"I recommend AWS Shield because it has proven helpful in tracking DDoS attacks within both my past and present environments, and without AWS Shield, a business could face potential losses, as this tool helps in identifying and mitigating fake traffic that disrupts applications, ultimately supporting business continuity."
"It is integrated with AWS. So, it gives you a good first step."
"If most of your internet presence from your application side is in AWS, AWS Shield is a great option."
 

Cons

"I would also like more visibility into their bad actor feeds, their fingerprint feeds. We try to be good stewards of the internet, so if there are attacks, or bad actors within our networks, if there were an easier way for us to find them, we could stop them from doing their malicious activity, and at the same time save money."
"Cloud signaling integration with third-party DDoS solution provider. Currently, it supports only its DDoS APS box."
"I have observed that the SNMP traps aspect that sends information to third-party solutions needs improvement."
"Sometimes it is not able to filter traffic adequately because of the hybrid approach."
"The following areas need improvement: opening and tracking support tickets, online support resources, software upgrades/updates and replacement media, and event management guidelines."
"I think Arbor DDoS needs improvement in areas where competitors like S5, Redver, or NETSCOUT offer web application firewall functionality or dedicated web application firewall devices. Arbor lacks these features, which is a significant disadvantage. Yes, I would like to see these features introduced in Arbor as well. Regarding real-time detection capabilities, Arbor DDoS works very well. We and our customers are very satisfied with its performance. However, it would benefit from adding Web Application Firewall (WAF) capabilities to reach a larger customer base."
"New versions are sometimes released before the bugs are worked out."
"The product could have end-to-end platform visibility."
"AWS Shield has limited coverage as it only protects against common and high-volume network and transport layer attacks, such as SYN floods."
"The management of it is a bit hard. If you don't engineer it on the front side, it is hard to go back in and change it."
"The product is expensive."
"The management of it is a bit hard. If you don't engineer it on the front side, it is hard to go back in and change it. It could be improved in terms of architecture requirements and then ongoing support requirements as a secondary component to it. People tend to set up things like this, and they just expect it to work without the care and feeding that needs to go back into it either from an application team or a network environment team."
"Perhaps the time required to detect anomalies can be reduced. Presently, it takes some time to determine whether a situation is normal or abnormal."
"We end up having to pay extra for features that AWS adds that we don't need."
"The product needs to improve its logs and reports to make it read better."
"The product should give users more flexibility to customize their security policies according to their requirements."
 

Pricing and Cost Advice

"The solution's pricing is based on a licensing model that is expensive when compared to other tools."
"I'm a technical guy. But I know it's expensive compared to its competitors. After you have the on-premise solution, for your solution to be effective you have to subscribe to an "upper level," so there's another cost. There is also a subscription to cloud services, which is another cost."
"As far as I know, they are the best in this sector, in DDoS protection. They know it, I know, because their service prices are too high. They provide cloud DDoS protection for ISPs, but that is also too expensive."
"I don't know about the pricing details as our company's service provider offers us the solution as an inbuilt feature within the internet bandwidth they provide us."
"The price of this solution is a little high in the African market, it should be lower."
"The solution is a bit costly if you're a small organization, but I think it's worth the price that they are charging."
"Arbor is striking a good balance between pricing and what they deliver."
"The price is a little high."
"The tool's pricing is good."
"It depends on your subscription level and the volume that you're spending with AWS. So, it is very relative to the consumption alignment in your subscription level. It is a well-constructed, scalable pricing option, but it is relative to how much you're spending on AWS. Because the more you spend, typically, the more you get off on services like this. I find it to be comparable to other solutions."
"The tool is cheap."
"The cost depends on traffic each month, so on average, it costs us between US$200 and US$300 per month."
"We pay $3000 per month for the solution."
report
Use our free recommendation engine to learn which Distributed Denial-of-Service (DDoS) Protection solutions are best for your needs.
912,788 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
15%
Comms Service Provider
12%
Outsourcing Company
10%
Manufacturing Company
6%
Comms Service Provider
17%
Computer Software Company
9%
Financial Services Firm
8%
Construction Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business26
Midsize Enterprise14
Large Enterprise29
By reviewers
Company SizeCount
Small Business3
Midsize Enterprise1
Large Enterprise7
 

Questions from the Community

Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
I would say if it’s an ISP that will build a scrubbing center, Netscout/Arbor is a good solution. In all other solutions, Imperva is a great choice.
Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Arbor would be the best bid, apart from Arbor, Palo Alto and Fortinet have good solutions. As this is an ISP, I would prefer Arbor.
What is your experience regarding pricing and costs for Arbor DDoS?
The prices for Arbor DDoS are expensive. The licensing is subscription-based. From our sales department, they discuss that prices are very high.
What is your experience regarding pricing and costs for AWS Shield?
The pricing structure for AWS Shield is fair, yet it depends on the specific protections chosen. Enabling Shield Advanced on multiple services such as CloudFront, network load balancer, or Route 53...
What needs improvement with AWS Shield?
Services always benefit from improvements, including AWS Shield. With respect to the Web Application Firewall, current rule-based setups may not be adequately defined or classified. Enhancement of ...
What is your primary use case for AWS Shield?
What do you use it for? How do you use it?
 

Comparisons

 

Also Known As

Arbor Networks SP, Arbor Networks TMS, Arbor Cloud for ENT
No data available
 

Overview

 

Sample Customers

Xtel Communications
netflix, dow jones, mapbox, pearson, rovio, youview, moviestar planet, asurion, payplug, hour of code
Find out what your peers are saying about AWS Shield vs. Arbor DDoS and other solutions. Updated: August 2026.
912,788 professionals have used our research since 2012.