8.8 million requests per day. The Russian Union of Insurers told how GIS works in the field of OSAGO
Customers: All-Russian Union of Insurers (VSS) Product: Jet CSIRT (Computer Security Incident Response Team) Project date: 2020/01 - 2020/09
Project's budget: 2 billion руб.
|
2022: Operation of the automated information system on OSAGO
In November 2022, the Russian Union of Auto Insurers (RSA) spoke about the work of an automated information system for OSAGO. According to the executive director of the organization, Evgeny Ufimtsev, the platform processes about 8.8 million requests per day, or 3 billion transactions per year.
{{quote 'Five years as the information system of the electronic policy is already being implemented, but, in fact, the new information system AIS 2.0, which has begun to be made over the past three years, has become a global system that allows insurance companies and the Russian Union of Auto Insurers to solve a lot of difficult, important tasks, - he said. }}
As Ufimtsev noted, every day to check KBM requests (bonus-malus coefficient), the system processes 1.8 million requests from different channels, including through companies and services. This greatly loads AIS OSAGO, the developers are forced to fight so that these requests are correct, said the executive director of the RSA.
According to Ufimtsev, part of the load falls on fraudulent requests - fraud (to enrich databases fraudsters) and. DDoS To protect each site service, methods are used and developed that can be divided into two areas: firstly, part of the issued personal data is hidden (for example, the name "Sidorov Ivan Petrovich" is replaced by "C * * * I * * * P * * *"), and secondly, software tools are used to reduce the load on the infrastructure.
{{quote 'In terms of the number of transactions processed, the AIS OSAGO system is at the same level as the largest systems in the country. It allows insurers to effectively combat fraud and copes with various attempts at fraud and DDoS attacks. In the future, insurance unions plan to develop services that will allow insurers to fight insurance fraud even more effectively, "concluded Ufimtsev[1] }}
2020
Creation of an information security system for the updated AIS OSAGO
Information security engineers of Jet Infosystems have created an information security system for the updated AIS OSAGO from scratch "turnkey." The company announced this on October 22, 2020. Increased requirements were imposed on the protection of the infrastructure built for the operation of application software. The fact is that the information system accumulates a large amount of data about car owners: the registration address of a citizen, the brand of the car belonging to him, the list of drivers allowed to drive the car, etc. In the near future, it is planned to integrate it with the traffic police resources to check the availability of policies using traffic cameras. This means that there will be more types of processed information: information about the whereabouts and routes of motorists will be added to them. In addition, in the future of four years, AIS should become the basis for collecting data on all types of insurance.
When choosing protective equipment, the information security service of the Russian Union of Auto Insurers (RSA) and the design team of Jet Infosystems used an integrated approach that takes into account Russian regulatory requirements and the best world practices for building an information security system. For example, to protect the processed personal data for all 152-FZ requirements and taking into account the current cyber threats contained in the Data Bank of FSTEC of Russia, preferences were given to certified domestic information security products.
As a result, the project team implemented a set of solutions to protect the created IT infrastructure and deployed an information security event monitoring subsystem to collect and analyze data from more than 450 security tools and IT landscape elements allocated to ensure the operation of the updated AIS. These sources together generate up to 20 thousand events per second, round-the-clock monitoring of which is provided by the Jet CSIRT Incident Monitoring and Response Center. To correlate events, Jet CSIRT analysts have developed about 90 specialized threat detection scenarios. As a result, after several levels of processing, specialists conduct a deep analysis of about 30 significant events per day and help the information security service of the PCA respond to them.
Also, engineers of the Jet Infosystems provided the possibility of a secure remote connection to the AIS OSAGO and safe integration with the information system for each of the 44 insurance companies that are members of the Russian Union of Auto Insurers.
We are pleased with the result, since we received a comprehensive protection system with a high level of visibility, which helped us to quickly understand the nuances of its operation and seize the initiative for further development, "said Alexander Lazarichev, head of the information security department of the Russian Union of Auto Insurers." - Jet CSIRT promptly informs us of all significant incidents, whether they are unaccounted for actions of administrators, inconsistent configuration changes, dubious technical solutions, potentially dangerous actions of contractors or counterparties in terms of information security. This allows us to take timely response measures and minimize the risks of compromising the infrastructure of such a significant information system for the market. |
The project was a serious challenge for us, since the time frame was strictly limited, and we needed to deploy the protection system in parallel with the software development process. To cope with such a large-scale project on time, we connected a large team to the implementation - about 30 information security specialists, - notes Pavel Volchkov, deputy director of the Information Security Center of Jet Infosystems. - From the very beginning, we built a security system in close cooperation with developers, which made it possible to take into account the architecture of application software and infrastructure platform when fine-tuning security policies. Another interesting feature of the project is that it involves both integration and service areas. |
Personalization of OSAGO tariffs after the launch of a new IT system for 2 billion rubles
On August 24, 2020, a law on the personalization of OSAGO tariffs came into force. This happened a month after the launch of a new IT system for this type of insurance. Read more here.
The new IT system of OSAGO was developed by Epam for 2 billion rubles
On June 28, 2020, the launch of the new automated information system (AIS) of OSAGO took place, and the project developers became known.
According to the Prime agency, citing a statement by the Russian Union of Auto Insurers (RSA), the new IT system cost 2 billion rubles. It was developed by Epam, and Jet Infosystems provided IT infrastructure that was created in six months. "Jet Infosystems" is also responsible for round-the-clock monitoring of information security incidents, analyzing them and helping the information security service of the RSA to respond to them.
AIS has a microservice architecture and is built on. open source software IT infrastructure is based in two data centers and built on. servers Huawei There is also a backup, DPC at the facilities of which productive AIS services can function without reducing productivity and service quality, the PCA said.
It is claimed that the created IT infrastructure has more than 10 times the potential for productivity growth and is able to support the withdrawal of functionality in the future. This will help the RSA to optimize investments, since in the next four years it is planned to create an information system on other insurance products on its basis, the union noted.
With this project, we create a single platform, connecting to which insurance companies will provide better and faster services for car owners, and the Central Bank of the Russian Federation will receive an operational tool to control their work, - said the head of the RSA Igor Yurgens. |
According to him, the innovative model of building an IT infrastructure and the expertise of a team of contractors helped create a solution that supports PCA initiatives to improve the interaction of insurance market participants and increase its transparency[2]
Preparing to start the system
On June 16, 2020, the Russian Union of Auto Insurers (RSA) announced preparations for the launch of a new IT system for OSAGO. It will start working on June 28 and will receive several new technological solutions.
According to RSA President Igor Yurgens, whose words are quoted on the union's website, the insurance community has made unprecedented efforts to launch AIS OSAGO both in terms of financial costs and in terms of implementation terms.
RSA, at the expense of insurers, invests more than 2 billion rubles in the project and launches a unique system for the country in a year, which is an incredibly tight time frame, especially against the background that, with the direct participation of the RSA, the first Russian superservice for Europrotocol, the mobile application "OSAGO Assistant," was launched in parallel, the RSA said in a statement. |
It is noted that the AIS OSAGO project contains a number of the most innovative technological solutions, such main modules as OSAGO contracts and losses, and KBM calculation have already been developed and are being prepared for launch within the project. Their start is scheduled for June 28, 2020, and new blocks are expected to be added in the future. In addition, according to the PCA, it will be possible to extend the system to other types of insurance.
Thus, a unified data model (logic model core) is integrated into the system, on the basis of which data structures specific to specific insurance products are built.
Last year, the principles of decisions of the AIS OSAGO database have already formed the basis for the creation of the information "System for Housing Insurance in Emergency Situations," the operator of which is the All-Russian Union of Insurers (ARIA), Yurgens noted.
He believes that the new IT system - AIS OSAGO - in the future should remain under the jurisdiction of the Russian Union of Auto Insurers.[3]