No more typing reviews! Try our Samantha, our new voice AI agent.

AWS Shield vs Imperva Application Security Platform comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Mar 22, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cloudflare
Sponsored
Ranking in Distributed Denial-of-Service (DDoS) Protection
3rd
Average Rating
8.6
Reviews Sentiment
7.0
Number of Reviews
79
Ranking in other categories
CDN (1st), WAN Optimization (4th), Managed DNS (1st), Domain Name System (DNS) Security (5th), Cloud Security Posture Management (CSPM) (17th)
AWS Shield
Ranking in Distributed Denial-of-Service (DDoS) Protection
5th
Average Rating
8.6
Reviews Sentiment
6.8
Number of Reviews
11
Ranking in other categories
No ranking in other categories
Imperva Application Securit...
Ranking in Distributed Denial-of-Service (DDoS) Protection
4th
Average Rating
8.6
Reviews Sentiment
7.0
Number of Reviews
142
Ranking in other categories
CDN (3rd), Web Application Firewall (WAF) (3rd), Bot Management (1st), API Security (2nd)
 

Mindshare comparison

As of April 2026, in the Distributed Denial-of-Service (DDoS) Protection category, the mindshare of Cloudflare is 14.9%, down from 18.8% compared to the previous year. The mindshare of AWS Shield is 3.5%, down from 6.6% compared to the previous year. The mindshare of Imperva Application Security Platform is 8.3%, up from 7.7% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Distributed Denial-of-Service (DDoS) Protection Mindshare Distribution
ProductMindshare (%)
Cloudflare14.9%
Imperva Application Security Platform8.3%
AWS Shield3.5%
Other73.3%
Distributed Denial-of-Service (DDoS) Protection
 

Featured Reviews

M.A. Faisal - PeerSpot reviewer
General Manager at bKash Limited
Advanced protection has secured critical web workloads and provides clear traffic visibility
From a security perspective, there remains a security loophole, as some browsers in the market can bypass the Turnstile solution, which requires approximately 40 seconds to do so. From a performance perspective, this is acceptable. We also tried Google reCAPTCHA, and that can also be bypassed. From a security perspective, I would say neither solution is completely secured. Regarding uptime, we have faced a couple of incidents due to Cloudflare in recent years, so I cannot say we receive 100% uptime for our region. We sometimes face challenges, including downtime and other issues. As a result, we are not receiving 100% uptime from Cloudflare's solution. Since most of our customers are in this region, we need alternatives. We need something more competitive than Cloudflare. Unfortunately, in Bangladesh, Cloudflare has three points of presence already, and we cannot find any other solution provider in Bangladesh as an alternative, which presents another challenge. Competitor solutions have more attack signatures, which ensure better security compared to Cloudflare's predefined configurations. Customers do not have options to modify any configuration parameters in Cloudflare, whereas other competitor solutions, such as F5 Distributed Cloud, allow customers to tune configurations according to their requirements. Cloudflare could improve in this area. Additionally, regarding visibility, Cloudflare has static visibility, but they could adopt dynamic graph features for their customers.
reviewer2767527 - PeerSpot reviewer
Lead Architect at a comms service provider with 1,001-5,000 employees
Has enabled multi-layered threat mitigation but still lacks deeper visibility for advanced application attacks
AWS Shield has limited coverage as it only protects against common and high-volume network and transport layer attacks, such as SYN floods. It does not provide inherent protection against more sophisticated layer 7 attacks such as HTTP floods. In such cases, integration with WAF is necessary, which results in additional costs for customers. To protect layer 7, layer 4, and layer 3, customers must implement both solutions. The service also has difficulties with static detection thresholds, which may not be sensitive enough to detect smaller application-specific attacks. While AWS Shield is a key security service, AWS should enhance their expert support with 24/7 response for complex attacks, which is currently limited.
ST
Senior Cybersecurity Consultant at Cyberoutcome Limited
Strong policies and bot defenses have secured critical APIs and have reduced attack noise
From my research regarding the IAM space that Imperva Application Security Platform is trying to look into, I believe they still need to do a lot of modeling and modification to make sure that also helps. There are several competitors in the IAM space, so Imperva would do well if they can do some basic modeling and modifications from my own personal research and my own experience in the IAM space. Alternatively, they could actually just focus on trying to be stronger in the web application space and the database activity monitoring space.The main reason it is not a perfect ten is regarding support. At times, having to reach the support team takes eight hours to ten hours maximum. There are times when clients could have urgent issues to attend to. The support team could do more by having a faster response rate.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The initial setup is extremely easy but will require access to your Domain Name Servers."
"Cloudflare is easier to manage than the solutions provided by these vendors, and the user experience is much more straightforward and appeals to a lot of developers."
"The most valuable feature is its usability."
"Using the CDN of Cloudflare improved the speed significantly, reducing the page loading times to appropriate levels."
"The solution is a great fit for customers who want unlimited bandwidth."
"Many websites require an SSL certificate because they sell stuff and want SSL. Cloudflare comes with an SSL certificate built in. It's automatic. You sign yourself up for Cloudflare, and an SSL certificate automatically protects your website. You don't necessarily need a certificate if you have a connection between your website and your host, the server, Cloudflare, and the host."
"CloudFlare provides an answer to a variety of issues, so it gives you very high value for your money."
"It's a great product because it's scalable, has great coverage, and is mature with good defenses against DDoS attacks."
"AWS Shield offers numerous protection features that are crucial at the application layer, safeguarding users from distributed denial of service attacks, man-in-the-middle assaults, and hacker orchestrations."
"AWS Shield is aligned with the web application firewall (WAF), and they work seamlessly together, primarily working with Elastic Load Balancer, CloudFront, and Route 53 for CDN and DNS services protection."
"We have integrated the tool with Active Directory. The most important feature is that it's transparent and doesn't degrade the performance of our solution. Additionally, it's easy to configure, which is crucial for us. It's easy to use and set up and stops attacks on our servers. We haven't encountered any attack problems because the solution stops them in real-time. AWS Shield specifically focuses on defending against denial-of-service attacks, making it a great solution for that type of threat."
"The solution's ease of use is the most valuable feature."
"If most of your internet presence from your application side is in AWS, AWS Shield is a great option."
"I am impressed with the product's multiple features like security."
"It is quite scalable, and we have not faced any issues with its scalability."
"I recommend AWS Shield because it has proven helpful in tracking DDoS attacks within both my past and present environments, and without AWS Shield, a business could face potential losses, as this tool helps in identifying and mitigating fake traffic that disrupts applications, ultimately supporting business continuity."
"The most valuable features of the Imperva Web Application Firewall are performance and flexibility. We can extend or customize the box itself."
"Imperva DDoS is fairly stable, and its availability is quite high."
"The solution is really stable; it's a product that I can stand by and recommend because I know it's going to work for the customer."
"One good thing about Imperva Web Application Firewall is it can be on the cloud and also it can be on-premise."
"Protection is the best solution since it has profile functionality."
"The solution is very affordable; it's based on the average traffic utilization, not the DDoS traffic, so if you're being DDoSed, you don't pay extra for the absorption of the DDoS traffic."
"Very intuitive and granular configuration - It does not require much time, or advanced knowledge, for configuration and maintenance."
"Imperva Web Application Firewall is a highly stable solution and is very mature."
 

Cons

"I would like Cloudflare to offer a dedicated account manager for large enterprise clients like us."
"Eventually, things go sideways and require fixes when it would have been easier to prevent the issue initially."
"If they improve on the placement of their data centers, it would be better. I'm living in a remote area. I would like to connect to them without any kind of lag."
"It would be beneficial for us if Cloudflare could offer a scrubbing solution. This would involve taking a snapshot of my website and keeping it live during a DDoS attack, ensuring uninterrupted service for our users. DDoS attacks are typically short in duration, and having Cloudflare maintain the site's availability from its secure network would enhance the overall user experience. I would appreciate it if Cloudflare could consider implementing this feature. Many organizations already utilize similar capabilities in their CDN platforms, where a static snapshot of the web page is displayed during DDoS attacks. In terms of features, Cloudflare needs to enhance its resilience and stay more focused on adopting new technologies. For instance, solutions like F5 XC Box, Access Solution, and Distributed Cloud Solution have impressive features, and Cloudflare should strive to match and exceed those capabilities. There's a need for improvement in areas like AI-based DDoS attacks and Layer 7 WAF features. Cloudflare should prioritize enhancements in areas such as behavioral DDoS and protection against SQL injection attacks, considering the prevalent trend of public exposure to the internet for business reasons. Overall, Cloudflare needs to invest more in advancing its feature set."
"Access to the solution's dashboards is not intended for a service company. You are practically blind, and to validate a problem, you must view the customer's screen."
"We have noticed multiple instances where Cloudflare falsely indicates that our servers are down, even when there is no actual load on them. This makes it challenging for us to identify the exact issue."
"The timing aspect can lead to it being considered overpriced. This is a particular concern we have with Cloudflare, as they may struggle with accurately detecting the client."
"The Always Online feature has room for improvement. It seems to work sometimes and not others even with the pro version."
"AWS Shield has limited coverage as it only protects against common and high-volume network and transport layer attacks, such as SYN floods."
"The product needs to improve its logs and reports to make it read better."
"We end up having to pay extra for features that AWS adds that we don't need."
"AWS Shield Standard requires improvement, particularly regarding its dashboard since it currently provides limited coverage against comprehensive DDoS attacks."
"The management of it is a bit hard. If you don't engineer it on the front side, it is hard to go back in and change it. It could be improved in terms of architecture requirements and then ongoing support requirements as a secondary component to it. People tend to set up things like this, and they just expect it to work without the care and feeding that needs to go back into it either from an application team or a network environment team."
"The network has been experiencing frustrating performance issues today, which is not typical for Nigeria."
"The product is expensive."
"Perhaps the time required to detect anomalies can be reduced."
"Imperva Web Application Firewall is a good system, but we found that the visibility of the diverse-path server, e.g. where the traffic is coming from, the different IPs, etc., needs improvement."
"There could be some limitations that from the converged infrastructure perspective: when you want to converge with everything and you want Imperva to get there easily because it's not a cloud component. For example, when you want to build servers and you're using OneView to manage your software-defined networks, implementing Imperva right away is not that simple. But if you're doing just a simple cloud infrastructure with servers in there, you're good to go. Also, we are not able, with Imperva, to block by signatures. Imperva by itself needs to be complemented with another service to do URL filtering."
"Imperva DDoS does not provide version control."
"I am not sure if this application has a policy where you can create your custom policy and run it as our firewall. We should have some ability to also create some custom policy, then run it as a firewall."
"HTML minification could be improved. The actual HTML minification does not provide the maximum HTML minification nor provides the best result."
"We had an issue when securing the web applications for DDoS protection."
"Imperva Web Application Firewall could improve the API integration. It was complex for us."
"The cost could be lower; our end clients need to have a high budget to purchase this solution."
 

Pricing and Cost Advice

"I think the pricing is competitive. I think as far as licensing is concerned it's pretty straightforward because it's based on domain. It's just that sometimes domains could be tricky with some customers."
"The product's pricing is minimal compared to other products."
"The cost primarily depends on the size of the organization."
"In terms of licensing costs, we don't pay for licensing for Cloudflare. We only establish communication, then for peering, Cloudflare takes care of the cross-connection in different data centers."
"The solution is expensive when compared to other products but offers unlimited bandwidth."
"The tool is a premium product, so it is very expensive."
"The pricing for the service is reasonable, neither excessively cheap nor prohibitively expensive. It aligns well with the value of their solution."
"When you compare Cloudflare DNS to other solutions, such as Akamai, the price is reasonable."
"We pay $3000 per month for the solution."
"It depends on your subscription level and the volume that you're spending with AWS. So, it is very relative to the consumption alignment in your subscription level. It is a well-constructed, scalable pricing option, but it is relative to how much you're spending on AWS. Because the more you spend, typically, the more you get off on services like this. I find it to be comparable to other solutions."
"The tool is cheap."
"The tool's pricing is good."
"The cost depends on traffic each month, so on average, it costs us between US$200 and US$300 per month."
"Imperva Web Application Firewall price is higher compared to other solutions. However, everything is included in the price."
"Licensing can range from one to twenty thousand dollars annually. Additionally, some features, including software support, require an annual subscription as well."
"It is very costly, but the return on investment is very high. Its cost was around $70,000, and we got it back in just six months."
"Imperva Web Application Firewall is expensive."
"The tool's pricing is good."
"The solution's price is high for small companies."
"Imperva charges us based on bandwidth, which is better than other vendors that charge us according to data transfer."
"The license is on a yearly basis."
report
Use our free recommendation engine to learn which Distributed Denial-of-Service (DDoS) Protection solutions are best for your needs.
889,855 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
10%
Comms Service Provider
10%
Computer Software Company
9%
Manufacturing Company
8%
Comms Service Provider
13%
Computer Software Company
9%
Financial Services Firm
9%
Manufacturing Company
6%
Financial Services Firm
13%
Manufacturing Company
8%
Computer Software Company
8%
Comms Service Provider
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business46
Midsize Enterprise10
Large Enterprise26
By reviewers
Company SizeCount
Small Business3
Midsize Enterprise1
Large Enterprise7
By reviewers
Company SizeCount
Small Business87
Midsize Enterprise25
Large Enterprise66
 

Questions from the Community

Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Cloudflare. We are moving from Akamai prolexic to Cloudflare. Cloudflare anycast network outperforms Akamai static GR...
Which would you choose - Cloudflare DNS or Quad9?
Cloudflare DNS is a very fast, very reliable public DNS resolver. It is an enterprise-grade authoritative DNS service...
What is your experience regarding pricing and costs for Cloudflare?
The tool's pricing is moderate. I rate the product’s pricing a five out of ten, where one is cheap, and ten is expens...
What do you like most about AWS Shield?
We have integrated the tool with Active Directory. The most important feature is that it's transparent and doesn't de...
What is your experience regarding pricing and costs for AWS Shield?
The pricing structure for AWS Shield is fair, yet it depends on the specific protections chosen. Enabling Shield Adva...
What needs improvement with AWS Shield?
Services always benefit from improvements, including AWS Shield. With respect to the Web Application Firewall, curren...
Which Web Application Firewall (WAF) would you recommend? R&S or Imperva?
Imperva is a strong choice, given their security focus and ongoing R&D into the product in areas such as bot mana...
What is your experience regarding pricing and costs for Imperva DDoS?
The pricing, setup costs, and licensing of Imperva DDoS are reasonable for the amount of technical capabilities provi...
What needs improvement with Imperva DDoS?
I would like to see improvements in the pooling of threats and attacks, possibly to enlarge the scale of indicators o...
 

Also Known As

Cloudflare DNS
No data available
Imperva Bot Management, Imperva Web Application Firewall, Imperva API Security
 

Overview

 

Sample Customers

Trusted by over 9,000,000 Internet Applications and APIs, including Nasdaq, Zendesk, Crunchbase, Steve Madden, OkCupid, Cisco, Quizlet, Discord and more.
netflix, dow jones, mapbox, pearson, rovio, youview, moviestar planet, asurion, payplug, hour of code
Hitachi, BNZ, Bitstamp, Moz, InnoGames, BTCChina, Wix, LivePerson, Zillow and more.
Find out what your peers are saying about AWS Shield vs. Imperva Application Security Platform and other solutions. Updated: April 2026.
889,855 professionals have used our research since 2012.