No more typing reviews! Try our Samantha, our new voice AI agent.

AWS Shield vs Imperva Application Security Platform comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Mar 22, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cloudflare
Sponsored
Ranking in Distributed Denial-of-Service (DDoS) Protection
3rd
Average Rating
8.6
Reviews Sentiment
7.0
Number of Reviews
79
Ranking in other categories
CDN (1st), WAN Optimization (4th), Managed DNS (1st), Domain Name System (DNS) Security (5th), Cloud Security Posture Management (CSPM) (18th)
AWS Shield
Ranking in Distributed Denial-of-Service (DDoS) Protection
5th
Average Rating
8.6
Reviews Sentiment
6.8
Number of Reviews
11
Ranking in other categories
No ranking in other categories
Imperva Application Securit...
Ranking in Distributed Denial-of-Service (DDoS) Protection
4th
Average Rating
8.6
Reviews Sentiment
7.0
Number of Reviews
144
Ranking in other categories
CDN (2nd), Web Application Firewall (WAF) (1st), Bot Management (1st), API Security (2nd)
 

Mindshare comparison

As of May 2026, in the Distributed Denial-of-Service (DDoS) Protection category, the mindshare of Cloudflare is 14.0%, down from 19.1% compared to the previous year. The mindshare of AWS Shield is 3.2%, down from 6.6% compared to the previous year. The mindshare of Imperva Application Security Platform is 8.5%, up from 7.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Distributed Denial-of-Service (DDoS) Protection Mindshare Distribution
ProductMindshare (%)
Cloudflare14.0%
Imperva Application Security Platform8.5%
AWS Shield3.2%
Other74.3%
Distributed Denial-of-Service (DDoS) Protection
 

Featured Reviews

M.A. Faisal - PeerSpot reviewer
General Manager at bKash Limited
Advanced protection has secured critical web workloads and provides clear traffic visibility
From a security perspective, there remains a security loophole, as some browsers in the market can bypass the Turnstile solution, which requires approximately 40 seconds to do so. From a performance perspective, this is acceptable. We also tried Google reCAPTCHA, and that can also be bypassed. From a security perspective, I would say neither solution is completely secured. Regarding uptime, we have faced a couple of incidents due to Cloudflare in recent years, so I cannot say we receive 100% uptime for our region. We sometimes face challenges, including downtime and other issues. As a result, we are not receiving 100% uptime from Cloudflare's solution. Since most of our customers are in this region, we need alternatives. We need something more competitive than Cloudflare. Unfortunately, in Bangladesh, Cloudflare has three points of presence already, and we cannot find any other solution provider in Bangladesh as an alternative, which presents another challenge. Competitor solutions have more attack signatures, which ensure better security compared to Cloudflare's predefined configurations. Customers do not have options to modify any configuration parameters in Cloudflare, whereas other competitor solutions, such as F5 Distributed Cloud, allow customers to tune configurations according to their requirements. Cloudflare could improve in this area. Additionally, regarding visibility, Cloudflare has static visibility, but they could adopt dynamic graph features for their customers.
reviewer2767527 - PeerSpot reviewer
Lead Architect at a comms service provider with 1,001-5,000 employees
Has enabled multi-layered threat mitigation but still lacks deeper visibility for advanced application attacks
AWS Shield has limited coverage as it only protects against common and high-volume network and transport layer attacks, such as SYN floods. It does not provide inherent protection against more sophisticated layer 7 attacks such as HTTP floods. In such cases, integration with WAF is necessary, which results in additional costs for customers. To protect layer 7, layer 4, and layer 3, customers must implement both solutions. The service also has difficulties with static detection thresholds, which may not be sensitive enough to detect smaller application-specific attacks. While AWS Shield is a key security service, AWS should enhance their expert support with 24/7 response for complex attacks, which is currently limited.
ST
Senior Cybersecurity Consultant at Cyberoutcome Limited
Strong policies and bot defenses have secured critical APIs and have reduced attack noise
From my research regarding the IAM space that Imperva Application Security Platform is trying to look into, I believe they still need to do a lot of modeling and modification to make sure that also helps. There are several competitors in the IAM space, so Imperva would do well if they can do some basic modeling and modifications from my own personal research and my own experience in the IAM space. Alternatively, they could actually just focus on trying to be stronger in the web application space and the database activity monitoring space.The main reason it is not a perfect ten is regarding support. At times, having to reach the support team takes eight hours to ten hours maximum. There are times when clients could have urgent issues to attend to. The support team could do more by having a faster response rate.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Smaller businesses have seen great ROI due to the low investment and strong performance."
"Its most significant benefit to date is the speed with which it refreshes DNS records on the internet once you change it. If you are changing a website or registering a new record, it is very quick."
"It is a fast and secure DNS."
"It's very user-friendly."
"It is easier to configure and develop documentation to see how we have configured firewalls."
"CloudFlare's caching brings the load speed down from 4.32 seconds to 2.45 seconds."
"The overall experience with Cloudflare is positive, with a rating of eight out of ten."
"Cloudflare is a security SaaS provider that provides security and protects us from any application layer attack."
"It is integrated with AWS. So, it gives you a good first step."
"If most of your internet presence from your application side is in AWS, AWS Shield is a great option."
"It is quite scalable, and we have not faced any issues with its scalability."
"AWS Shield is aligned with the web application firewall (WAF), and they work seamlessly together, primarily working with Elastic Load Balancer, CloudFront, and Route 53 for CDN and DNS services protection."
"We have integrated the tool with Active Directory. The most important feature is that it's transparent and doesn't degrade the performance of our solution. Additionally, it's easy to configure, which is crucial for us. It's easy to use and set up and stops attacks on our servers. We haven't encountered any attack problems because the solution stops them in real-time. AWS Shield specifically focuses on defending against denial-of-service attacks, making it a great solution for that type of threat."
"The solution operates smoothly at its baseline level, and we do not encounter any issues at that level."
"The product is easy to use."
"AWS Shield offers numerous protection features that are crucial at the application layer, safeguarding users from distributed denial of service attacks, man-in-the-middle assaults, and hacker orchestrations."
"The dashboard is good and user-friendly."
"The solution can be configured in just a couple of minutes."
"Imperva Application Security Platform positively impacts us because we have a critical website, so by placing a WAF of Imperva's quality, it allows us to have visibility and granular control over the various attacks that can occur on the website."
"I would encourage people to implement Imperva Incapsula, as it is a very mature, easy to use, and reliable solution."
"Incapsula has provided heightened visibility and awareness at management level on the actual threat landscape; it paves the way for easier approval for security-related implementations and projects."
"The availability of our sites, thanks to the load balance functionality, has improved, and it enables the site to be available all the time, despite people trying to attack it."
"Very intuitive and granular configuration - It does not require much time, or advanced knowledge, for configuration and maintenance."
"There are quite a few useful Imperva Incapsula features. For example, one of them is the reports. The graphics are very good and it's easy to configure. The whole process is very fast and reliable too. They have good tech support as well."
 

Cons

"The solution could use more analytics on the backend to give us more insights into everything. More reports would be helpful."
"The product support needs to be accessible from more places, a wider area of coverage."
"I have found CloudFlare's support to be unresponsive at times, and not very helpful with providing technical details for issues that we have reported over the years."
"The installation was complex until I learned what I had to learn."
"For the free and Pro plans, Cloudflare could use a simple bot to provide information to users. This would improve support, especially for less advanced users who utilize the free components."
"It would be helpful if the solution could continue evolving to compete with the other solutions on the market."
"An integrated SSO feature would be useful for Cloudflare DNS."
"Eventually, things go sideways and require fixes when it would have been easier to prevent the issue initially."
"The time taken to detect anomalies must be reduced."
"The product is expensive."
"There is an area for improvement regarding health checks. AWS Shield does not come with its own health check functionality."
"The management of it is a bit hard. If you don't engineer it on the front side, it is hard to go back in and change it. It could be improved in terms of architecture requirements and then ongoing support requirements as a secondary component to it. People tend to set up things like this, and they just expect it to work without the care and feeding that needs to go back into it either from an application team or a network environment team."
"Perhaps the time required to detect anomalies can be reduced. Presently, it takes some time to determine whether a situation is normal or abnormal."
"Perhaps the time required to detect anomalies can be reduced."
"The management of it is a bit hard. If you don't engineer it on the front side, it is hard to go back in and change it."
"The product should give users more flexibility to customize their security policies according to their requirements."
"Scalability-wise, it is not so scalable as the solution is quite straightforward."
"Imperva Web Application Firewall could improve the API integration. It was complex for us. Additionally, The onboarding could be better."
"The product's customization capabilities are a bit problematic, requiring support cases for backend modifications."
"I would like to improve the tool's turnaround time in terms of support."
"An improvement for Imperva WAF would be to reduce the number of false positives and create more strong use cases based on AI/ML or behavioral analytics."
"We had an issue when securing the web applications for DDoS protection."
"It would be useful if the solution used more intelligence in attack protection. For example, firewalls are to be dependent on the configuration, but if they could have some data science around it the solution would be even better. The profiling of the traffic, and making decisions surrounding that should be intelligence-based, instead of being based on the configuration of the firewall itself."
"There's always room for improvement. Occasionally, there might be false-positive alerts."
 

Pricing and Cost Advice

"I think the pricing is competitive. I think as far as licensing is concerned it's pretty straightforward because it's based on domain. It's just that sometimes domains could be tricky with some customers."
"The cost primarily depends on the size of the organization."
"Cloudflare's pricing is not much higher and is good for middle-level organizations."
"The product's pricing is cheap."
"I believe their performance has improved, but I'd like to refrain from discussing the pricing aspect related to the cloud. The pricing, in my opinion, could be simplified, and I think they should consider reevaluating the pricing for support, as it can be quite high. At times, this cost can make it challenging to choose CARFAGuard or opt for the support."
"I give the price a five out of ten."
"When you compare Cloudflare DNS to other solutions, such as Akamai, the price is reasonable."
"For Cloudflare, I recommend it heavily for small businesses with revenue under a couple of million dollars. Onboarding is easy, and they even have a free plan. This makes it simple for businesses in the $100,000-$500,000 range to try it out and see its value, allowing them to scale up their infrastructure as needed."
"It depends on your subscription level and the volume that you're spending with AWS. So, it is very relative to the consumption alignment in your subscription level. It is a well-constructed, scalable pricing option, but it is relative to how much you're spending on AWS. Because the more you spend, typically, the more you get off on services like this. I find it to be comparable to other solutions."
"The tool is cheap."
"The cost depends on traffic each month, so on average, it costs us between US$200 and US$300 per month."
"The tool's pricing is good."
"We pay $3000 per month for the solution."
"It is expensive."
"There is a license or subscription renewal that our customers pay."
"It is a very expensive solution. The price is very high. A lot of customers tell us that they would love to use Imperva more. I have some customers who have 50 websites, but they have only 10 websites on Imperva because of the price. They would love to have all their websites running through Imperva, but they can't. They have to choose the more critical websites to protect because the price is very high. It is a very good product, but it is too expensive. If you buy a plan for 20 megabytes and you don't consume all of your 20 megabytes, it is okay, but if you consume more, you are charged for the superior traffic."
"The tool is expensive."
"On a scale from one to ten, where one is cheap and ten is expensive, I rate the solution's pricing a five out of ten."
"​Although the pricing can be a little high, it is worth the protection and security that it offers.​"
"I rate the product price a four on a scale of one to ten, where one is a low price, and ten is a high price."
"Everybody complains about the price of this solution."
report
Use our free recommendation engine to learn which Distributed Denial-of-Service (DDoS) Protection solutions are best for your needs.
893,221 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
10%
Comms Service Provider
10%
Computer Software Company
8%
Manufacturing Company
8%
Comms Service Provider
16%
Computer Software Company
9%
Financial Services Firm
8%
Manufacturing Company
6%
Financial Services Firm
13%
Manufacturing Company
8%
Computer Software Company
7%
Comms Service Provider
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business46
Midsize Enterprise11
Large Enterprise26
By reviewers
Company SizeCount
Small Business3
Midsize Enterprise1
Large Enterprise7
By reviewers
Company SizeCount
Small Business88
Midsize Enterprise25
Large Enterprise69
 

Questions from the Community

Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Cloudflare. We are moving from Akamai prolexic to Cloudflare. Cloudflare anycast network outperforms Akamai static GR...
Which would you choose - Cloudflare DNS or Quad9?
Cloudflare DNS is a very fast, very reliable public DNS resolver. It is an enterprise-grade authoritative DNS service...
What is your experience regarding pricing and costs for Cloudflare?
The tool's pricing is moderate. I rate the product’s pricing a five out of ten, where one is cheap, and ten is expens...
What is your experience regarding pricing and costs for AWS Shield?
The pricing structure for AWS Shield is fair, yet it depends on the specific protections chosen. Enabling Shield Adva...
What needs improvement with AWS Shield?
Services always benefit from improvements, including AWS Shield. With respect to the Web Application Firewall, curren...
What is your primary use case for AWS Shield?
What do you use it for? How do you use it?
Which Web Application Firewall (WAF) would you recommend? R&S or Imperva?
Imperva is a strong choice, given their security focus and ongoing R&D into the product in areas such as bot mana...
What is your experience regarding pricing and costs for Imperva DDoS?
The pricing, setup costs, and licensing of Imperva DDoS are reasonable for the amount of technical capabilities provi...
What needs improvement with Imperva DDoS?
I would like to see improvements in the pooling of threats and attacks, possibly to enlarge the scale of indicators o...
 

Also Known As

Cloudflare DNS
No data available
Imperva Bot Management, Imperva Web Application Firewall, Imperva API Security
 

Overview

 

Sample Customers

Trusted by over 9,000,000 Internet Applications and APIs, including Nasdaq, Zendesk, Crunchbase, Steve Madden, OkCupid, Cisco, Quizlet, Discord and more.
netflix, dow jones, mapbox, pearson, rovio, youview, moviestar planet, asurion, payplug, hour of code
Hitachi, BNZ, Bitstamp, Moz, InnoGames, BTCChina, Wix, LivePerson, Zillow and more.
Find out what your peers are saying about AWS Shield vs. Imperva Application Security Platform and other solutions. Updated: April 2026.
893,221 professionals have used our research since 2012.