The document provides best practices for improving the resiliency of applications on AWS against DDoS attacks, including using AWS Shield Standard, AWS Shield Advanced, Amazon CloudFront, Amazon Route 53, Elastic Load Balancing, Amazon API Gateway, Amazon VPC, and Amazon EC2 with Auto Scaling. It describes infrastructure layer attacks like UDP reflection attacks and SYN floods, and application layer attacks. It outlines mitigation techniques and a reference architecture using various AWS services.