Try our new research platform with insights from 80,000+ expert users

AWS Shield vs Arbor DDoS comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 5, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cloudflare
Sponsored
Ranking in Distributed Denial-of-Service (DDoS) Protection
1st
Average Rating
8.4
Reviews Sentiment
7.1
Number of Reviews
71
Ranking in other categories
CDN (1st), Managed DNS (1st), Cloud Security Posture Management (CSPM) (14th)
Arbor DDoS
Ranking in Distributed Denial-of-Service (DDoS) Protection
2nd
Average Rating
8.6
Reviews Sentiment
7.0
Number of Reviews
49
Ranking in other categories
No ranking in other categories
AWS Shield
Ranking in Distributed Denial-of-Service (DDoS) Protection
6th
Average Rating
8.4
Reviews Sentiment
7.5
Number of Reviews
7
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of January 2025, in the Distributed Denial-of-Service (DDoS) Protection category, the mindshare of Cloudflare is 18.8%, down from 19.2% compared to the previous year. The mindshare of Arbor DDoS is 14.5%, up from 12.8% compared to the previous year. The mindshare of AWS Shield is 7.0%, down from 7.4% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Distributed Denial-of-Service (DDoS) Protection
 

Featured Reviews

Spencer Malmad - PeerSpot reviewer
It's easy to set up because you point the DNS to it, and it's working in under 15 minutes
Cloudflare is highly scalable. Cloudflare is a system with a web portal that the end users like me see. It's a console where we can adjust the DNS, caching, and security features all in that console. Cloudflare owns thousands of servers across the world that cache the data. It's a powerful solution. When clients sign up for Cloudflare, they're getting this monster content delivery network, security, and a web application firewall in one. It's all rolled into one, and it's massive. Unless you have your website hosted on a massive hosting provider, there's no way that you can deliver the amount of data that Cloudflare can provide to the end users. If you have static content, there's no way that you can ever match what Cloudflare can do. Obviously, there are competitors to Cloudflare that do the same, but I'm saying other types of solutions. Let's say you go with F5. Great, that's on-prem. That's in your colo. You can't deliver as much data to the internet as you can with a CDN. You don't have to spend $20,000 on a net scaler, F5, or whatever Cisco's selling now. You don't have to buy that. You pay them $50 a month or $150 a month. It's totally worth it because even in five years, you'll never get the performance value, not just the actual ROI. You have to consider how much throughput you can get with Cloudflare.
Tushar Sail - PeerSpot reviewer
A critical solution for security, as it includes features that can automatically detect and prevent DDoS attacks
Arbor DDoS offers security features that automatically detect and prevent DDoS attacks. When a DDoS attack is detected targeting a specific IP, the Arbor device immediately becomes in line with the traffic and actively works to prevent the attack. This auto feature is one of the best aspects of Arbor DDoS, as it ensures timely and effective protection against such attacks.
Manikandan-R - PeerSpot reviewer
Solution provides essential protection with good support and a simple setup
I have noticed a pattern developing in approximately five minutes. If it were possible to provide these patterns with historical data spanning six months, three months, or two months directly from the console, it would be extremely beneficial. It would allow for easy inquiries and facilitate the retrieval of relevant parts without having to manually check logs or examine movements. Instead, if all historical data were available, I could consult six months' worth of identified patterns efficiently through AWS without relying on external sources. This solution is particularly suitable for startups or medium-sized startups. I would rate the overall solution eight out of ten.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"What I like best about Cloudflare is that my company can use it to trace and manage applications and monitor traffic. The solution tells you if there's a spike in traffic. Cloudflare also sends you a link to check your equipment and deployment and track it through peering, so it's a valuable tool."
"The solution is very good at mitigating threats."
"When using services like Heroku, Cloudflare is very useful for CNAME flattening. I also use it for their end-to-end SSL with TLS authentication on nginx for securing servers."
"I get a lot of value from Cloudflare's API because it enables you to build a separate environment inside the solution. You can create a domain for performing test requests before you move to the production environment and connect various domains."
"We're using dynamic components to build flexible pages to create and manage Git merge requests for code and reviews."
"I rate its stability a ten out of ten."
"Centralized, full-featured DNS."
"The tool is user-friendly."
"Arbor DDoS offers security features that automatically detect and prevent DDoS attacks."
"Arbor DDoS's best feature is that we can put the certificates in, and it will look at layer seven and the encrypted traffic and do the required signaling."
"The technical support of Arbor DDoS is good."
"We use almost all the features of Arbor DDoS, but it really depends on the customer’s requirements, so I can’t specify exactly which features we use. However, many customers appreciate the basic DDoS protection, especially those without specific protection needs. For example, financial companies benefit from the cloud DDoS protection. It’s a straightforward solution that effectively meets their needs."
"The solution looks into volumetric attacks and gets them resolved."
"Valuable features include simple and centralized management of user access and capabilities, as well as Web 2.0 interactive attack alerting, traffic visualization, and mitigation service control."
"I like all the features together as a whole."
"Reporting is quite good. There are several pages of reporting on DDoS attacks, and you can find all the details that you need."
"It is integrated with AWS. So, it gives you a good first step."
"The solution's ease of use is the most valuable feature."
"We have integrated the tool with Active Directory. The most important feature is that it's transparent and doesn't degrade the performance of our solution. Additionally, it's easy to configure, which is crucial for us. It's easy to use and set up and stops attacks on our servers. We haven't encountered any attack problems because the solution stops them in real-time. AWS Shield specifically focuses on defending against denial-of-service attacks, making it a great solution for that type of threat."
"The solution operates smoothly at its baseline level, and we do not encounter any issues at that level."
"It is quite scalable, and we have not faced any issues with its scalability."
"The product is easy to use."
"The product has a good mechanism to analyze trends and trigger events."
"I am impressed with the product's multiple features like security."
 

Cons

"Cloudflare doesn't have a reverse lookup. We can only do a DNS lookup to get the IP address from the hostname. It doesn't work if you want to look up the hostname from an IPA address."
"The analytics, basically the dashboard, doesn't have much to it."
"Cloudflare should add more documentation and pricing to the cloud version."
"Cloudflare's console should be made more user-friendly."
"The timing aspect can lead to it being considered overpriced. This is a particular concern we have with Cloudflare, as they may struggle with accurately detecting the client."
"They lack a good way to manage DNS as a company, since everything is relegated to single account logins until you get to the higher levels. They have come out with a paid feature to remedy this, but I have not had a chance to fully review it yet to know if it fixes the access problem."
"I believe they currently have this feature, but there will most likely be integration with APIs so we can control some features through API."
"DNS Management."
"The product could have end-to-end platform visibility."
"There should be an automatic way to configure it to monitor traffic and decide which is an attack and which is not. In Arbor, you need to tweak and set all parameters manually, whereas in Check Point DDoS Protector, you can select the lowest parameters, and over the weeks, Check Point DDoS Protector will learn the traffic and you can then tighten some of the parameters to decide which traffic is regular and which is malicious."
"An improvement would be to provide information on how pricing is done on different customer levels."
"Arbor's SSL decryption is confusing and needs external cards to be installed in the devices. This is not the best solution from an architectural point of view for protecting HTTPS and every other protocol that is SSL encrypted."
"There is definitely room for improvement in third-party intelligence and integrations."
"They should improve the reporting section and make it a little bit more detailed. I would like to have much better and more detailed reports."
"I think Arbor DDoS needs improvement in areas where competitors like S5, Redver, or NETSCOUT offer web application firewall functionality or dedicated web application firewall devices. Arbor lacks these features, which is a significant disadvantage. Yes, I would like to see these features introduced in Arbor as well. Regarding real-time detection capabilities, Arbor DDoS works very well. We and our customers are very satisfied with its performance. However, it would benefit from adding Web Application Firewall (WAF) capabilities to reach a larger customer base."
"Sometimes it blocks legitimate traffic. If a legitimate user is trying to access the server continuously, the product suspects that this is a DoS traffic file. That is a case where it needs to improve. It needs machine-learning."
"Perhaps the time required to detect anomalies can be reduced."
"The time taken to detect anomalies must be reduced."
"We end up having to pay extra for features that AWS adds that we don't need."
"The product needs to improve its logs and reports to make it read better."
"Perhaps the time required to detect anomalies can be reduced. Presently, it takes some time to determine whether a situation is normal or abnormal."
"The product is expensive."
"The product should give users more flexibility to customize their security policies according to their requirements."
"The management of it is a bit hard. If you don't engineer it on the front side, it is hard to go back in and change it. It could be improved in terms of architecture requirements and then ongoing support requirements as a secondary component to it. People tend to set up things like this, and they just expect it to work without the care and feeding that needs to go back into it either from an application team or a network environment team."
 

Pricing and Cost Advice

"The pricing depends on the usage, but the cheapest would be around 5,000 USD a month."
"Cloudflare's pricing is not much higher and is good for middle-level organizations."
"It's a premium model. You can start at zero and work your way up to the enterprise model, which has a very high pricing level."
"I give the price a five out of ten."
"The tool is a premium product, so it is very expensive."
"I think the pricing is competitive. I think as far as licensing is concerned it's pretty straightforward because it's based on domain. It's just that sometimes domains could be tricky with some customers."
"The solution has many features but there are ones that you need to pay for. Sometimes you have to find out which is available for free and which you have to pay for."
"We are using the free version."
"The solution's pricing is based on a licensing model that is expensive when compared to other tools."
"Arbor is striking a good balance between pricing and what they deliver."
"We do not use the Arbor Cloud DDoS solution because it is too costly."
"As far as I know, they are the best in this sector, in DDoS protection. They know it, I know, because their service prices are too high. They provide cloud DDoS protection for ISPs, but that is also too expensive."
"The licensing of a complete Arbor solution, including fire-walling and unified site management, can get expensive."
"The solution is a bit costly if you're a small organization, but I think it's worth the price that they are charging."
"Arbor's products are very expensive. Their competitors are cheap when compared with Arbor."
"Pricing is slightly on the higher side."
"The tool's pricing is good."
"The cost depends on traffic each month, so on average, it costs us between US$200 and US$300 per month."
"We pay $3000 per month for the solution."
"It depends on your subscription level and the volume that you're spending with AWS. So, it is very relative to the consumption alignment in your subscription level. It is a well-constructed, scalable pricing option, but it is relative to how much you're spending on AWS. Because the more you spend, typically, the more you get off on services like this. I find it to be comparable to other solutions."
"The tool is cheap."
report
Use our free recommendation engine to learn which Distributed Denial-of-Service (DDoS) Protection solutions are best for your needs.
831,997 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
24%
Computer Software Company
13%
Comms Service Provider
8%
Financial Services Firm
7%
Financial Services Firm
17%
Computer Software Company
14%
Comms Service Provider
9%
Government
6%
Computer Software Company
16%
Financial Services Firm
16%
Comms Service Provider
8%
Insurance Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Cloudflare. We are moving from Akamai prolexic to Cloudflare. Cloudflare anycast network outperforms Akamai static GR...
Which would you choose - Cloudflare DNS or Quad9?
Cloudflare DNS is a very fast, very reliable public DNS resolver. It is an enterprise-grade authoritative DNS service...
What do you like most about Cloudflare?
Cloudflare offers CDN and DDoS protection. We have the front end, API, and database in how you structure applications.
Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
I would say if it’s an ISP that will build a scrubbing center, Netscout/Arbor is a good solution. In all other soluti...
Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Arbor would be the best bid, apart from Arbor, Palo Alto and Fortinet have good solutions. As this is an ISP, I would...
What do you like most about Arbor DDoS?
The quality of the technical support provided by Arbor DDoS is premium.
What do you like most about AWS Shield?
We have integrated the tool with Active Directory. The most important feature is that it's transparent and doesn't de...
What needs improvement with AWS Shield?
The time taken to detect anomalies must be reduced. The tool has a few parameters based on which it tries to understa...
 

Comparisons

 

Also Known As

Cloudflare DNS
Arbor Networks SP, Arbor Networks TMS, Arbor Cloud for ENT
No data available
 

Overview

 

Sample Customers

Trusted by over 9,000,000 Internet Applications and APIs, including Nasdaq, Zendesk, Crunchbase, Steve Madden, OkCupid, Cisco, Quizlet, Discord and more.
Xtel Communications
netflix, dow jones, mapbox, pearson, rovio, youview, moviestar planet, asurion, payplug, hour of code
Find out what your peers are saying about AWS Shield vs. Arbor DDoS and other solutions. Updated: January 2025.
831,997 professionals have used our research since 2012.