Security management

更新时间:
复制 MD 格式

After subscribing to Identity Verification, you can set monitoring rules to track the stability of the Identity Verification API service and detect abnormal requests. When a stability issue or abnormal request occurs, you can receive alert notifications through channels such as phone calls, SMS messages, or DingTalk. You can also block these abnormal requests.

Step 1: Configure monitoring rules

You can configure two types of monitoring rules: stability rules and security rules. Stability rules primarily monitor performance metrics such as queries per second (QPS). When a threshold is breached, the system sends an alert notification to help you maintain API stability. Security rules monitor for abnormal request patterns, such as API abuse or account theft. When a threshold is breached, the system sends an alert notification and can block the requests.

  1. Log on to the Identity Verification console.

  2. In the left navigation bar, click Security Management.

  3. In the Monitoring Rule Configuration section, select a Rule Type, click + Add in the Rule Settings section, configure the monitoring rule, and then click Save.

    You can add a maximum of 15 monitoring rules.

    Rule type

    Stability Rule

    A stability rule helps ensure API stability. If the threshold is breached, the system sends an alert notification via phone, SMS, or DingTalk. Stability rules have the following parameters:

    • Product Name: The following products are supported. Select a product based on your business requirements.

      • Two-Factor Identity Verification

      • Basic Mobile Number Verification

      • Advanced Mobile Number Verification

      • Bank Card Verification

    • Rule: QPS is greater than is selected by default. This means that the system will send an alert notification when the QPS is greater than the threshold.

      Note

      To prevent frequent notifications for low call volumes, the following rules apply only when the minimum call volume thresholds are met:

      • Success rate over the last 5 minutes is less than: The call volume must be greater than 20.

      • Average response time over the last 5 minutes is greater than: The call volume must be greater than 20.

      • Hour-over-hour call volume growth over the last hour is greater than: The call volume must be greater than 100.

      • Hour-over-hour call volume decrease over the last hour is greater than: The call volume must be greater than 100.

      • Verification consistency rate over the last hour is less than: The call volume must be greater than 100.

    • Threshold: The QPS monitoring threshold, a positive integer from 1 to 99,999.

      Note

      Adjusting this threshold does not change the product's default QPS limit. The default limit for the Alibaba Cloud Identity Verification service is 100 QPS. To increase this limit, contact Alibaba Cloud Support.

    • Action: Defaults to Alert. When the threshold is triggered, the system sends alert notifications through methods such as phone calls, SMS, and DingTalk.

    • Enable/Disable: When enabled, the rule takes effect.

    Security Rules

    A security rule monitors repeated abnormal requests to the API service, such as API abuse or account theft. When the monitoring threshold is breached, the system can send timely alert notifications and block the abnormal requests. Security rules have the following parameters:

    • Select Product: The following products are supported. Select a product.

      • Two-Factor Identity Verification

      • Basic Mobile Number Verification

      • Advanced Mobile Number Verification

      • Bank Card Verification

    • Time Period: Supported time periods include 1 minute, 5 minutes, 10 minutes, 30 minutes, and 1 hour.

    • Duplicate Fields:

      • For Two-Factor Identity Verification:

        • ID Card Number

        • Name+ID Card Number

      • For Basic and Advanced Mobile Number Verification:

        • ID Card Number

        • Mobile Number

        • ID Card Number+Mobile Number

      • For Bank Card Verification:

        • Bank Card Number

        • Mobile Number

        • ID Card Number

        • ID Card Number+Bank Card Number

        • Bank Card Number+Mobile Number

        • Bank Card Number+Mobile Number+ID Card Number

    • Threshold (Times): The request count. Valid values are integers from 1 to 99,999.

    • Status: Turn on the switch to enable the rule.

    • Action: Alert is selected by default. When the trigger threshold is reached, the system sends alert notifications through channels such as phone calls, SMS, and DingTalk. If you select Reject Request, when the monitoring threshold is triggered, similar repeated abnormal requests are rejected, and the system returns an error. This action does not affect normal requests.

    Example configuration: For the Two-Factor Identity Verification API, if an ID card number is used in more than 20 requests within a 10-minute period, the system sends an alert and rejects further requests using that ID card number. Other valid requests are not affected.

Step 2: Configure alert notifications

Create alert contacts and contact groups

  1. In the Alert Notification Configuration section, click Create Contact & Create Contact Group to go to the Cloud Monitor console.

  2. Create an alert contact.

    1. On the Alert Contacts tab, click Create Contact.

    2. In the Set Alert Contact panel, enter the name, mobile number, email address, and Webhook address, and keep Alert Notification Language at its default value of Automatic.

      Note

      Automatic indicates that CloudMonitor automatically uses the language that was set during your Alibaba Cloud account registration for alert notifications.

    3. After you verify that the information is correct, click Confirm.

  3. Create an alert contact group.

    1. On the Alert Contact Group tab, click Create Contact Group.

    2. In the New Contact Group panel, enter a group name, select alert contacts, and then click Confirm.

  4. Add alert contacts to an alert contact group in bulk.

    1. On the Alert Contacts tab, select the alert contacts that you want to add, and then click Add to Alert Contact Group.

    2. In the Confirm Information dialog box, click the target alert contact group, and then click OK.

After creating alert contacts and contact groups, Identity Verification sends monitoring alerts to the specified recipients. Recipients should review these notifications promptly and take appropriate action.

Subscribe to CloudMonitor notifications

  1. In the Alert Notification Configuration section, click Go to Subscription to go to the Cloud Monitor console.

  2. On the Create Subscription Policy page, create a subscription policy. The configuration parameters are described in the following table.

    Module

    Parameter

    Description

    Basic information

    Name

    The name of the subscription policy. Recommended value: Identity Verification exception alerts.

    Description

    Optional. A description of the policy.

    Alert subscription

    Subscription type

    Select System Event.

    Product

    Select Real Person Authentication. This is the product category for Identity Verification.

    Event type

    Real Person Authentication > Exception

    Event name

    Leave this empty.

    Event level

    Leave this empty.

    Application group

    Leave this empty.

    Event content

    Leave this empty.

    Event resource

    Leave this empty.

    Merge and denoise

    Merge content

    Leave this empty.

    Denoise

    To prevent alert fatigue, the system has a default 10-minute suppression period for high-frequency events. You can set a longer period. To receive all alerts without delay, select Trigger immediately, no suppression.

    Notification

    Notification configuration

    Select your required notification recipients.

    Custom notification method

    You can keep the default settings or configure custom notification methods.

    Push and integration

    Push channel

    Optional.

Note

For more information, see Manage event subscriptions.