Alibaba Cloud Fraud Detection protects data through encryption, isolation, and leak prevention. HTTPS with SSL/TLS secures data in transit, server-side encryption protects data at rest, and Resource Access Management (RAM)-based access control isolates data between users. Real-time monitoring and log auditing help prevent data leaks.
Data encryption
Data transmission encryption
Fraud Detection encrypts data in transit over HTTPS with SSL and TLS, preventing data from being stolen or tampered with.
-
Technical implementation: Data is encrypted with a 256-bit key to meet sensitive data transmission requirements.
-
User controllability: Enabled by default. No additional configuration is required.
Static data protection
Static data protection secures stored data primarily through encryption.
-
Server-side data encryption: Fraud Detection permanently stores API operation call records, including the call time, called operation, and number of calls. The records are encrypted at rest to prevent data leaks.
-
Client-side data encryption: Client-side data encryption is not applicable.
Data isolation
Data isolation among different users
Fraud Detection enforces strict data isolation between users through RAM-based access control, ensuring that only authorized personnel can access sensitive data.
-
Access control: Fraud Detection supports RAM-based access control. You can assign permissions to RAM users through the RAM console or API operations and create custom policies for finer-grained control.
-
Data isolation: Fraud Detection provides a data isolation mechanism that ensures each user's operations do not affect other users' data and helps prevent unauthorized access.
Data leak prevention
Abnormal behavior detection and alerting
Fraud Detection provides end-to-end risk control across device terminals, account registration, account logon, and marketing, helping enterprises prevent large-scale risks.
-
Real-time monitoring: Fraud Detection calculates metrics, models, and policy rules on real-time requests and traffic, returning results in real time.
-
Log audit: Fraud Detection integrates with ActionTrail to monitor and record operations on your Alibaba Cloud account, including access to cloud services through the Alibaba Cloud Management Console, API operations, and SDKs.
Backup and disaster recovery
Data backup
Fraud Detection permanently stores API operation call records to help restore data and locate the causes of failures. You can query call records from the previous year.
-
Backup method: API operation call records are backed up automatically. No manual operations are required.
-
Backup cycle: You can query API operation call records from the previous year.
Data restoration
Data restoration mechanism
Fraud Detection uses a comprehensive backup mechanism to quickly restore data from backup records in case of issues such as data loss.
-
Restoration method: Data can be located and restored by querying backed-up API operation call records.
-
Restoration time range: Data from the previous year can be restored.
Impacts and recommendations
Resource overheads and costs
Enabling security mechanisms such as data encryption and isolation may increase CPU utilization and incur additional costs. For example, SSL/TLS-based transmission encryption may increase read and write latencies.
-
Recommendations: We recommend that you perform related operations during off-peak hours to minimize the impact on normal workloads.
Dependent storage services
Fraud Detection relies on Alibaba Cloud storage services such as Object Storage Service (OSS) and ApsaraDB RDS for data storage and backup.
-
Dependent services:
-
OSS
-
ApsaraDB RDS
-