All Products
Search
Document Center

Edge Security Acceleration:Best practices for the finance industry

Last Updated:Apr 07, 2024

Background information

The digitalization of traditional financial services, such as banking, securities, and insurance, and the rise of Internet finance promote the rapid development of online financial services, such as online banking, mobile payment, and online securities trading. Online finance has a wide user coverage, frequent transactions, a huge number of page views, and high security requirements. To increase customer retention and preempt the market in the mobile Internet era, financial enterprises must provide fast, stable, and secure user services.

Alibaba Cloud Dynamic Route for CDN (DCDN) provides more than 3,200 edge nodes around the world. Alibaba Cloud DCDN adopts advanced technologies, such as separated dynamic and static content acceleration, HTTPS transmission, IP Application Accelerator (IPA), IPv6, and content protection, to ensure the security and high availability of financial businesses and improve the performance of online financial services.

Architecture

Online financial services have high security requirements. The core of online financial services is to ensure security during data distribution and provide low latency and high reliability services. For financial enterprises with international businesses, Alibaba Cloud DCDN provides high-quality network links to improve the efficiency of international data transmission. You can access DCDN without modifying the business logic.

Scenarios

Financial services security
  • Requirements: Financial cybercrime increases with the digitalization of financial services. Financial platforms are prone to DDoS attacks, data theft, crawler threats, and service attacks. A single attack may cause huge financial losses. The scale of attack and defense drills and attack technologies are constantly increasing. Therefore, efficient management of these drills is considered a priority in network security construction.
  • Benefits: Alibaba Cloud DCDN provides multiple security features, such as Web Application Firewall (WAF), HTTPS transmission, hotlink protection, tamper-proofing, and access control on distributed edge nodes, and builds a comprehensive security system on edge nodes. This system improves network security and defense capabilities and helps the defenders of attack and defense drills to carry out defense work.
Online business experience
  • Requirements: Diversified financial services, such as financial news and information, financial markets, and member centers, involve transfer of many static large files and back-to-origin API requests. This poses challenges to the performance and stability of network transmission links.
  • Benefits: Alibaba Cloud DCDN provides technologies, such as intelligent routing and transmission protocol optimization, to automatically avoid links with network jitter and congestion and select the optimal route to deliver resources to ensure network experience of financial users.
Three data centers across two regions
  • Requirements: Origin servers for financial services often adopt the architecture of three data centers across two regions. If an origin server fails, services must be quickly switched to another available origin server to ensure service continuity and stability.
  • Benefits: Alibaba Cloud DCDN can distribute back-to-origin requests to multiple origin servers to implement remote disaster recovery. Requests can be distributed among multiple origin servers based on different dimensions, such as priority, weight, and performance of the origin server. If an origin server fails, services can be switched to another available origin server to ensure service continuity and stability.
Collaborative office
  • Requirements: Financial enterprises often require data access between headquarters and multiple branches in scenarios such as SSL-VPN and cloud desktop. Data access is greatly affected by network links, especially if the branches are distributed across geographical locations or are located outside China.
  • Benefits: Alibaba Cloud DCDN provides more than 3,200 edge nodes around the world to help build a global fast, reliable, intelligent, and secure network. DCDN uses IPA to improve the efficiency of collaborative services that use non-standard protocols, such as cloud desktop.
IPv6 services
  • Requirements: The origin server requires a large amount of workloads to migrate to IPv6. The requirements for metrics, such as DNS support, latency, availability, and security, are difficult to meet.
  • Benefits: Alibaba Cloud DCDN provides a one-stop IPv6 solution to meet the requirements for low latency, high availability, and security. You can use Alibaba Cloud DCDN IPv6 solutions to migrate IPv6 and enhance IPv6 service capabilities.

Customer benefits

  • Security compliance

    A sound data security mechanism ensures the security of data throughout its lifecycle.

  • User experience

    The distribution of numerous edge nodes around the world provides better experience for Internet users and enterprise employees.

  • Service availability

    The elastic scale-out architecture, load balancing mechanism, and real-time monitoring for origin servers help build a highly available network architecture.

  • Easy access

    You can quickly access Alibaba Cloud DCDN by using simple interface configurations without modifying your business logic.

Quick start

You can access DCDN by following the procedure.

FeatureDescriptionReferences
Quick access to DCDNQuickly activate DCDN to accelerate content delivery.
  1. Activate DCDN

  2. Add a domain name

  3. Configure acceleration rules

  4. Add a CNAME record for a domain name

Dynamic and static content deliveryIntelligently identify static and dynamic content. Static content such as images, JavaScript Style Sheets (JSS) files, and CSS files is cached on DCDN POPs. Users can directly retrieve the cached static content from the nearest DCDN POPs. Requests for dynamic content, such as POST requests, are redirected to the origin server over an optimal route selected based on intelligent routing.Configure static file types
IP Application AcceleratorProvide services to non-standard HTTP protocol users, especially those using Layer 4 proprietary protocols. IP Application Accelerator (IPA) accelerates network transmission, reduces access latency, and improves service availability.Add a domain name to IPA
Security protection

Web Application Firewall (WAF) protects web servers against vulnerabilities, such as domain hijacking, website vulnerabilities, and data leaks.

Bot traffic management protects your business from malicious traffic or crawlers.

WAF protection (old version)

Configure bot traffic management

HTTPS settingsHTTPS is an HTTP channel that is designed to ensure data security. HTTPS secure acceleration is used to encrypt HTTPS requests between clients and Alibaba Cloud DCDN nodes. HTTPS ensures data security during transmission.

What is HTTPS secure acceleration?

Configure an SSL certificate

IPv6After you enable IPv6, IPv6-enabled clients send requests to DCDN over IPv6. In this case, DCDN also carries the IPv6 information of the clients in back-to-origin requests. Enable IPv6
More acceleration regionsGlobal and Global (Excluding the Chinese Mainland) are supported. Requests can be scheduled to POPs that are nearest to the users.

References