API Gateway provides a number of ways to protect your API from certain threats, like malicious users or spikes in traffic.
You can protect your API using strategies like generating SSL certificates, configuring a web application firewall, setting throttling targets, and only allowing access to your API from a Virtual Private Cloud (VPC).
In this section you can learn how to enable these capabilities using API Gateway.
https://docs.aws.amazon.com/apigateway/latest/developerguide/rest-api-protect.html