Habr•October 9, 2026•🇷🇺Translated from Russian

Digital Twins Enable Pre-Deployment Testing and Post-Change Control in Complex Multi-Vendor Networks

UserGate and Hadal Project specialists have outlined a practical framework that links physical laboratories, emulation, and mathematical simulation to verify network modifications before they reach production and to monitor their effects afterward.

After a minor software update, IPsec tunnels to all remote branches failed despite passing standard vendor validation and showing normal monitoring metrics. The incident illustrates the limits of traditional change management in large, living networks that combine multiple vendors, legacy configurations, and ongoing releases.

The authors identify three primary sources of complexity: multi-vendor heterogeneity that creates unexpected interactions at integration points, historical configuration debt accumulated over years, and continuous change from patches, node additions, and policy updates. Manual lab testing with spare hardware covers only a fraction of these variables and cannot scale to the full production topology.

The proposed solution separates testing into three distinct classes. Software testing validates new releases and firmware on real hardware for ASIC behavior and performance. Change testing examines specific configuration modifications such as routing policy adjustments or firewall rule updates. Change control continuously compares the live network state against expected policies using simulation models.

Physical laboratories deliver maximum accuracy for critical devices but are limited in scale. Emulation with uInfraTwin creates virtual replicas of network segments using actual operating-system images, supports traffic generators including TRex, IXIA, and Xinertel, and allows rapid iteration of test scenarios. Simulation platforms such as Batfish, Cisco WAE, Juniper WANDL, Hadal, Forward Networks, and IP Fabric build mathematical models that answer reachability, policy drift, and path questions across tens of thousands of devices.

The combined digital-twin workflow consists of three stages: automated network archaeology that inventories assets, topologies, and business-service mappings; pre-deployment staging that runs functional and load tests on selected segments; and post-deployment verification that detects configuration drift and unintended connectivity between security zones.

When simulation identifies an anomaly, the affected segment and its current configurations are transferred to the emulator for safe reproduction and fix validation, closing the feedback loop between production observation and controlled testing.

Related articles

Habr•Other

Hash Functions Part 1: Core Properties, Security Requirements and Practical Applications

The article provides a detailed introduction to hash functions, explaining how they map arbitrary-length input to fixed-length output while satisfying three fundamental security properties. It covers preimage resistance, second preimage resistance, and collision resistance, along with the avalanche effect that makes even minor input changes produce unrecognizable output. The text explains why a 256-bit digest is required to achieve 128-bit collision resistance, referencing the birthday paradox and its implications for MD5 and SHA-1. Practical guidance includes using OpenSSL for hashing, applying hashes in commitment schemes, enforcing subresource integrity on web pages, and securely storing passwords with Argon2 and bcrypt. The post emphasizes that hash functions alone do not guarantee integrity without proper transmission of the digest and announces a follow-up on SHA-2 and SHA-3 internals.

AntiMalware•Other

Positive Technologies Releases MaxPatrol SIEM 28.0 with Major Resource Optimizations and AI Enhancements

Positive Technologies has launched MaxPatrol SIEM 28.0, enabling security operations centers to process significantly more security events without requiring additional hardware. Internal tests show the new version consumes up to 26% less CPU and 52% less RAM compared to the previous release. Optimized components for event processing and data storage now allow the system to handle 40,000 events per second instead of 20,000 on comparable servers. The architecture has been refined so that unnecessary roles can be omitted when MaxPatrol SIEM operates independently from other platform products such as MaxPatrol VM. The behavioral analysis module MaxPatrol BAD received the new HackTracker component, which detects attackers by behavior patterns rather than only by tools, and now supports Unix event analysis with linked activity chains. The PT Naira AI assistant has been simplified for easier configuration, helping analysts write normalization rules, explain events, and search documentation, with claims of reducing investigation time by up to 50% and rule creation effort by up to 90%. Analysts also benefit from added context in correlation rule cards, quick navigation links, and a native dark theme.

Habr•Other

macOS User Investigates Claude Regional Block via Logs and Restores Work Site Access with Targeted WireGuard Routes

A detailed case study describes how a macOS user analyzed Claude application logs after experiencing regional unavailability errors while using WireGuard VPN. The investigation covered ~/Library/Logs/Claude/ files containing markers like app-unavailable-in-region and region_unavailable, cross-referenced with tunnel activity dates from August to October 2026. No direct evidence linked the VPN to the account block, as tunnel logs were overwritten and system journals returned Operation not permitted errors. The user then addressed a secondary issue where WireGuard blocked access to work services including amoCRM, TGBooster, and Geekjob. Custom host routes were added via route add commands to direct specific IPv4 addresses through the local gateway while keeping Claude traffic in the tunnel. A launchd-based PF kill switch was tested for tunnel failure protection but caused a full internet outage on October 5 due to anchor and hook conflicts, leading to its rollback. By October 8, work sites functioned under VPN with verified routes, though persistent kill switch protection remained unresolved.

Habr•Other

Publishing Internal APIs from DMZ Without Direct LAN Connections: Five Tested Architectures

When an API gateway resides in the DMZ but security policies forbid outbound connections into the LAN, organizations must adopt alternative patterns to expose internal services synchronously. The article examines five production-ready approaches built on the NEOMSA APIM platform, ranging from custom request-reply logic over Kafka to zero-code solutions using ActiveMQ Artemis and experimental reverse HTTP in HAProxy. Each pattern is evaluated against criteria such as the need for DMZ-to-LAN firewall rules, volume of custom code, support for streaming responses, and measured performance. Load tests on the Artemis-based bridge reached 50 requests per second with a 95th percentile latency of approximately 100 ms, while the Kafka implementation required roughly 2,500 lines of Java to emulate missing reply semantics. The analysis highlights trade-offs in operational complexity, vendor support implications, and security posture, particularly the benefit of preventing any outbound initiation from the DMZ.