YD/T 4600-2023
Technical requirements for big data risk control systems for Internet businesses (English Version)

Standard No.
YD/T 4600-2023
Language
Chinese, Available in English version
Release Date
2023
Published By
Professional Standard - Post and Telecommunication  CN  /  YD
Latest
YD/T 4600-2023
 

Introduction

Standard Background and Evolution Analysis

With the increasing professionalization of the Internet black industry chain, the traditional manual risk control model has been unable to cope with new threats such as false registration, database collision attacks, activity cheating, etc. This standard was jointly formulated by leading companies such as Alibaba and China Mobile, marking that my country's Internet risk control has entered a new stage of intelligence and standardization.


System Architecture Analysis

Architecture LevelCore FunctionsTechnical Implementation
Data LayerMulti-source Data Collection/Encrypted StorageDistributed Database, Feature Encryption
Core Technology LayerFive Major Recognition EnginesMachine Learning Algorithms, Relationship Graphs
Platform Technology LayerRule/Model ManagementVisual Configuration, Real-time Computing

Core Function Requirements

1.

  • Device fingerprint recognition: Multi-dimensional device portraits such as IMEI/MAC
  • Behavior sequence analysis: Keyboard keystroke pattern + browsing trajectory modeling
  • Relationship network mining: Account/device/IP association map

2. Comparison of typical application scenarios

ScenarioRisk characteristicsPrevention and control measures
False registrationCentralized registration of mobile phone numbers in the cat poolDevice abnormal behavior detection
Activity fraudFrequent requests from the same IPTraffic baseline analysis

Security and compliance points

According to GB/T 35273's requirements for personal information protection:

  1. Sensitive data storage requires AES-256 encryption
  2. Log audit retention ≥180 days
  3. Implement the principle of least privilege

Implementation suggestions

Construction path planning

Phase-based implementation: basic data governance→rule engine construction→AI model iteration

Performance evaluation indicators

  • Risk identification accuracy ≥95%
  • False interception rate ≤0.5%
  • Response delay <200ms

YD/T 4600-2023 Referenced Document

  • GB/T 35273-2017 Information security technology—Personal information security specification

YD/T 4600-2023 history

  • 2023 YD/T 4600-2023 Technical requirements for big data risk control systems for Internet businesses
Technical requirements for big data risk control systems for Internet businesses

Topics on standards and specifications

Standard and Specification




Copyright ©2026 All Rights Reserved
Update: Sun, 07 Jun 2026 06:50:55 +0000