Customers: Administration of the Yamalo-Nenets Autonomous Area
Contractors: Anlim-IT, Department of information technologies and communications of the Yamalo-Nenets Autonomous Area, Axoft Product: PT Application FirewallProject date: 2020/05 - 2020/10
|
2020: Project completion on protection of web applications of data processing centers
On October 6, 2020 it became known that the Government of the Yamalo-Nenets Autonomous Area completed the project on protection of web applications of data processing centers. For the solution of a task the specialized firewall (web application firewall, WAF) the level of the PT Application Firewall applications from Positive Technologies company was used. Specialists of Anlim-IT integrator were engaged in implementation with direct support of the distributor of IT solutions, Axoft company, and WAF producer – Positive Technologies.
As it was explained, in the Yamalo-Nenets Autonomous Area two data processing centers of the Government of the district on which about 200 web resources are placed, among them – the state information systems, the websites of authorities, local government and municipal authorities are located. For maintenance of working capacity, development of a system and ensuring necessary level of protection of web resources the big staff of IT specialists and also the modern solution for monitoring and blocking of the attacks on web applications was required.
According to Positive Technologies, for October, 2020 the most vulnerable component of network perimeter of the organizations are web resources: unauthorized access of malefactors to the application is possible for 39% of the websites, and the threat of leak of important data is present in 68% of web applications.
The Department of information technologies and communications of the Yamalo-Nenets Autonomous Area (the DIYEW of YaNAO) were faced by a problem of selection and implementation of an optimal solution for information security support of web space of the district. The solution had to conform to several requirements at once: have an opportunity to work in the protected circuit, to reveal the real slozhnosostavny attacks in a big event stream, to conform to requirements of regulatory authorities, and, taking into account demand for information services at visit of web resources, to ensure the continuity of their work and information security of citizens of YaNAO.
For the solution of a task it was offered to use the specialized firewall of level of the PT Application Firewall applications of Positive Technologies company. PT Application Firewall is the certified Firewall (in the system of certification of FSTEC of Russia) and is intended for protection of web applications against the majority of the attacks, including OWASP Top 10 and the attacks using vulnerabilities of zero day.
Together with the DIYEW of YaNAO and State governmental agency "Resources of Yamal" the large volume of works was done. As a result the DIYEW of YaNAO received the tool for tracking and prevention of the attacks, and the built-in mechanisms of correlation PT Application Firewall allowed to reduce manual data processing about the arriving attacks.
Modern technologies considerably simplify and accelerate process of rendering services and providing services to citizens. Informatization of the district allows to be closer to citizens, to strengthen rates of development of economy. The main thing that is necessary - it is to provide trust to technologies which without information security support is impossible. Kirill Albychev, the director of the department of information technologies and communications of the Yamalo-Nenets Autonomous Area noted |
Thanks to professionalism and harmonious work of all participants of process it turned out to avoid a significant amount of false operations and to execute, at first sight, monumental task on information security support of the majority of web resources of the Government of YaNAO. The project allowed to minimize the DIYEW of YaNAO risks of attacks on the part of information infrastructure of the Government of the district, most available to malefactors, and also to secure data of citizens at visit of web resources. Maxim Ovsyannikov, the CEO of Anlim-IT LLC told |
In the Government of the Yamalo-Nenets Autonomous Area spheres of the public and municipal services, health care and education, social protection of the population, interdepartmental interaction, navigation and cartography are automated.