AWS Shield Advanced provides more sophisticated automatic mitigations for attacks targeting your applications running on protected EC2, ELB, CloudFront, Global Accelerator, and Route 53 resources. Using advanced routing techniques, Shield Advanced automatically deploys additional mitigation capacity to protect your application against DDoS attacks. For customers with Business or Enterprise support, the SRT also applies manual mitigations for more complex and sophisticated DDoS attacks that might be unique to your application. For application layer attacks, you can use AWS WAF at no additional charge for resources protected by Shield Advanced to set up proactive rules (such as rate-based blocking to automatically block web requests from attacking source IP addresses) or respond immediately to incidents as they happen. You can also engage directly with the SRT to place custom AWS WAF rules on your behalf in response to an application layer DDoS attack. The SRT will diagnose the attack and, with your permission, apply mitigations on your behalf, reducing the amount of time your applications might be impacted by an ongoing DDoS attack.