After subscribing to Identity Verification, you can set monitoring rules to track the stability of the Identity Verification API service and detect abnormal requests. When a stability issue or abnormal request occurs, you can receive alert notifications through channels such as phone calls, SMS messages, or DingTalk. You can also block these abnormal requests.
Step 1: Configure monitoring rules
You can configure two types of monitoring rules: stability rules and security rules. Stability rules primarily monitor performance metrics such as queries per second (QPS). When a threshold is breached, the system sends an alert notification to help you maintain API stability. Security rules monitor for abnormal request patterns, such as API abuse or account theft. When a threshold is breached, the system sends an alert notification and can block the requests.
Log on to the Identity Verification console.
In the left navigation bar, click Security Management.
In the Monitoring Rule Configuration section, select a Rule Type, click + Add in the Rule Settings section, configure the monitoring rule, and then click Save.
You can add a maximum of 15 monitoring rules.
Rule type
Stability Rule
A stability rule helps ensure API stability. If the threshold is breached, the system sends an alert notification via phone, SMS, or DingTalk. Stability rules have the following parameters:
Product Name: The following products are supported. Select a product based on your business requirements.
Two-Factor Identity Verification
Basic Mobile Number Verification
Advanced Mobile Number Verification
Bank Card Verification
Rule: QPS is greater than is selected by default. This means that the system will send an alert notification when the QPS is greater than the threshold.
NoteTo prevent frequent notifications for low call volumes, the following rules apply only when the minimum call volume thresholds are met:
Success rate over the last 5 minutes is less than: The call volume must be greater than 20.
Average response time over the last 5 minutes is greater than: The call volume must be greater than 20.
Hour-over-hour call volume growth over the last hour is greater than: The call volume must be greater than 100.
Hour-over-hour call volume decrease over the last hour is greater than: The call volume must be greater than 100.
Verification consistency rate over the last hour is less than: The call volume must be greater than 100.
Threshold: The QPS monitoring threshold, a positive integer from 1 to 99,999.
NoteAdjusting this threshold does not change the product's default QPS limit. The default limit for the Alibaba Cloud Identity Verification service is 100 QPS. To increase this limit, contact Alibaba Cloud Support.
Action: Defaults to Alert. When the threshold is triggered, the system sends alert notifications through methods such as phone calls, SMS, and DingTalk.
Enable/Disable: When enabled, the rule takes effect.
Security Rules
A security rule monitors repeated abnormal requests to the API service, such as API abuse or account theft. When the monitoring threshold is breached, the system can send timely alert notifications and block the abnormal requests. Security rules have the following parameters:
Select Product: The following products are supported. Select a product.
Two-Factor Identity Verification
Basic Mobile Number Verification
Advanced Mobile Number Verification
Bank Card Verification
Time Period: Supported time periods include 1 minute, 5 minutes, 10 minutes, 30 minutes, and 1 hour.
Duplicate Fields:
For Two-Factor Identity Verification:
ID Card Number
Name+ID Card Number
For Basic and Advanced Mobile Number Verification:
ID Card Number
Mobile Number
ID Card Number+Mobile Number
For Bank Card Verification:
Bank Card Number
Mobile Number
ID Card Number
ID Card Number+Bank Card Number
Bank Card Number+Mobile Number
Bank Card Number+Mobile Number+ID Card Number
Threshold (Times): The request count. Valid values are integers from 1 to 99,999.
Status: Turn on the switch to enable the rule.
Action: Alert is selected by default. When the trigger threshold is reached, the system sends alert notifications through channels such as phone calls, SMS, and DingTalk. If you select Reject Request, when the monitoring threshold is triggered, similar repeated abnormal requests are rejected, and the system returns an error. This action does not affect normal requests.
Example configuration: For the Two-Factor Identity Verification API, if an ID card number is used in more than 20 requests within a 10-minute period, the system sends an alert and rejects further requests using that ID card number. Other valid requests are not affected.
Step 2: Configure alert notifications
Create alert contacts and contact groups
In the Alert Notification Configuration section, click Create Contact & Create Contact Group to go to the Cloud Monitor console.
Create an alert contact.
On the Alert Contacts tab, click Create Contact.
In the Set Alert Contact panel, enter the name, mobile number, email address, and Webhook address, and keep Alert Notification Language at its default value of Automatic.
NoteAutomatic indicates that CloudMonitor automatically uses the language that was set during your Alibaba Cloud account registration for alert notifications.
After you verify that the information is correct, click Confirm.
Create an alert contact group.
On the Alert Contact Group tab, click Create Contact Group.
In the New Contact Group panel, enter a group name, select alert contacts, and then click Confirm.
Add alert contacts to an alert contact group in bulk.
On the Alert Contacts tab, select the alert contacts that you want to add, and then click Add to Alert Contact Group.
In the Confirm Information dialog box, click the target alert contact group, and then click OK.
After creating alert contacts and contact groups, Identity Verification sends monitoring alerts to the specified recipients. Recipients should review these notifications promptly and take appropriate action.
For more information, see Create an alert contact or an alert contact group.
Subscribe to CloudMonitor notifications
In the Alert Notification Configuration section, click Go to Subscription to go to the Cloud Monitor console.
On the Create Subscription Policy page, create a subscription policy. The configuration parameters are described in the following table.
Module
Parameter
Description
Basic information
Name
The name of the subscription policy. Recommended value: Identity Verification exception alerts.
Description
Optional. A description of the policy.
Alert subscription
Subscription type
Select System Event.
Product
Select Real Person Authentication. This is the product category for Identity Verification.
Event type
Real Person Authentication > Exception
Event name
Leave this empty.
Event level
Leave this empty.
Application group
Leave this empty.
Event content
Leave this empty.
Event resource
Leave this empty.
Merge and denoise
Merge content
Leave this empty.
Denoise
To prevent alert fatigue, the system has a default 10-minute suppression period for high-frequency events. You can set a longer period. To receive all alerts without delay, select Trigger immediately, no suppression.
Notification
Notification configuration
Select your required notification recipients.
Custom notification method
You can keep the default settings or configure custom notification methods.
Push and integration
Push channel
Optional.
For more information, see Manage event subscriptions.