Read-Only Utility Automates Detailed Audits of UserGate NGFW Firewall Policies
A cybersecurity engineer at Gazprom CPS has created a specialized read-only utility that helps administrators audit complex UserGate NGFW firewall policies without risking any automatic modifications to live configurations.
The project began when manual review of more than 1000 firewall rules and 4500 related objects proved impractical. Temporary rules created for short-term tasks often remained active for years, becoming difficult to evaluate because descriptions were outdated, owners unknown, and hit counts low. The utility addresses this by pulling data exclusively through the UserGate XML-RPC API, normalizing references to zones, IP lists, services, users, and groups, and then running a series of checks that generate an Excel report.
Eleven Targeted Checks Without Automated Changes
The checks are divided into four logical groups. Lifecycle checks identify rules whose last hit was too long ago, rules with very low hit counts despite being enabled, long-disabled rules, and rules that have not been updated for extended periods. Permissive-access checks look for rules using Any source or destination combined with Any services, networks wider than a configured mask threshold, and services that implicitly include management ports such as SSH or RDP when the services list is empty.
Observability checks flag drop and reject rules that have logging disabled, as well as rules that are enabled but currently inactive due to time restrictions. Documentation checks detect empty rule descriptions or descriptions lacking references to change requests or task numbers, and they also identify duplicate rule signatures.
All findings are presented with explanations so administrators can make final decisions. The tool never deletes or alters rules; it only supplies evidence for manual review.
Handling UserGate Data Model Complexities
The utility carefully interprets UserGate semantics. An empty services list means Any, not nothing. Negated lists and empty negated lists are rendered distinctly to avoid false findings. Network lists, URL lists, and certain system objects are resolved through additional API calls, with statistics aggregated across cluster nodes. The entire dataset is saved as a JSON snapshot, allowing repeated analysis with different thresholds without reconnecting to the firewall.
The final deliverable is a multi-sheet Excel workbook containing a summary dashboard, a rules-by-checks matrix with red and green indicators, a main rules sheet with human-readable object names, and separate sheets for each check. Administrators can assign verdicts such as OK, requires attention, false positive, or exception directly on the main sheet; these verdicts propagate via formulas to all other sheets.
The first production run completed in approximately 24 minutes and flagged roughly 39 percent of rules, more than half of which matched multiple checks. The resulting report provides a focused queue for manual investigation rather than requiring sequential review of the entire policy.
Related articles
Secure Personalization of Java Card Applets Using Issuer Security Domain and SCP02
The article explains how to leverage the Issuer Security Domain mechanisms on GlobalPlatform cards to establish secure channels for applet personalization without implementing custom ECDH-based key exchange. It addresses limitations of prior approaches that lacked authentication and required extensive PKI support. The solution uses SCP02 with specific security levels such as C_MAC and C_DECRYPTION to protect commands that store AES-128 keys and personal data on the card. Detailed code walkthroughs cover the applet constructor, process method, mutual authentication via SecureChannel.processSecurity, and unwrap operations for decrypting and verifying APDUs. Practical testing on NXP Java Cards demonstrates installation via FunGP library scripts that allow configurable security levels during mutual authentication. The implementation ensures that secret key updates enforce C_DECRYPTION while personal data writes accept C_MAC, with encrypted reads performed using AES-CBC.
IT Jobs at Major Tech Firms Turn Into Dating Red Flags for Some Women
Working in IT used to be seen as a strong advantage in dating due to high salaries and prestigious employers. However, employees at companies like Palantir and Tesla now report that their jobs trigger uncomfortable conversations about ethics and politics instead of romantic interest. A Palantir engineer named Gary has started hiding his employer after facing sharp reactions from women and even requests from friends to avoid mentioning the company at social events. Tesla employee James encounters questions about his political views simply because of his association with Elon Musk's company. Dating specialist Amy Laurent notes that tech giants face backlash over issues like surveillance, inequality, and AI displacing workers, forcing professionals to present their careers with caveats. The article from Wired highlights how an employer's reputation now overshadows individual values during initial meetings. While IT roles remain attractive in many ways, the automatic boost from big tech brands appears to be fading in personal contexts.
Neuromorphic Chips: Event-Driven Architectures Aim to Cut Energy Use in Always-On AI and Sensor Systems
Modern processors and GPUs excel at massive parallel math yet remain inefficient for continuous sensor streams where little changes most of the time. Neuromorphic chips borrow principles such as local memory, sparse spiking communication and threshold-based activation from biological nervous systems to reduce data movement and idle computation. The approach replaces constant matrix multiplications with asynchronous spikes that propagate only when meaningful events occur, lowering both power and latency for edge devices. Spiking neural networks encode information in the timing and frequency of pulses rather than dense numeric tensors, making them suitable for vibration monitoring, robotic vision and wearable health sensors. Hybrid systems are expected to pair conventional CPUs and NPUs for heavy training workloads with neuromorphic accelerators that stay dormant until events arrive. The architecture does not replace existing accelerators but targets the niche of always-on, battery-constrained perception tasks where conventional von Neumann designs hit the memory wall.
Russia Boosts Digitalization Budget by 58% Using Telecom Operators' Universal Service Fund
The Russian government has significantly increased allocations for digital projects from the universal service reserve funded by telecom operators. In the 2027 draft budget, 16.3 billion rubles are earmarked for digital solutions, up 58% from the previously planned 10.3 billion rubles. The funds will support the national project Data Economy and the state program Information Society, covering state information systems, digital platforms, cloud infrastructure, AI projects, and quantum technologies. The operator contribution rate remains unchanged at 2% of revenue, with no new levies under consideration. Funding for connecting small settlements to the internet stays at 19.3 billion rubles, while allocations from traffic fines for digitalization are being reduced.