An autonomous security product to protect connected vehicles and IoT devices from cyberattacks
XGuard Integrity (formerly Carwall)
“Karamba XGuard CFI” received the Best of Show Award – Jury Special Prize (Security Category) at Interop Tokyo 2019.
Karamba XGuard CFI customized the CFI functionality—a core feature of XGuard Integrity—for IoT operating systems. Unlike conventional CFI products that validate only function calls, it also verifies the integrity of function returns (return addresses), providing robust protection against in memory attacks.
In recent years, the number of devices connected to the Internet has continued to increase. Connected cars—vehicles that communicate with external systems via the Internet—have attracted particular attention. While connectivity improves convenience, it has also raised growing concerns about security and safety. For conventional IT systems, one of the greatest security risks is information leakage. In the case of connected cars, however, one of the most serious risks is the potential loss of human life. As a result, security requirements for these devices are much more stringent than those for ordinary IT equipment.Karamba Security’s XGuard Integrity is an autonomous security solution that hardens the software execution environment of electronic control units (ECUs) and detects and blocks attacks targeting them.
Rather than fixing security bugs in the code itself, XGuard Integrity prevents attacks that exploit such bugs by allowing only predefined software behavior during the manufacturing process of IoT devices.
・ Verifies the functional flow of code running in memory to protect against in-memory attacks
・Inspects program execution to ensure that it conforms to configurations defined during manufacturing
・Controls Internet connectivity of electronic control units to prevent structural security weaknesses
・Controls input from external devices to prevent malware infections originating from peripheral devices
Features of XGuard Integrity
-
Protection Against In-Memory Attacks
When automatically generating security policies for control units based on manufacturing-time settings, XGuard Integrity builds a call graph that maps the relationships between all function calls.
At runtime, the executing binary is inspected against this call graph to verify that the actual call sequence does not deviate from the expected behaviour defined at manufacturing time.
Because any in-memory attack used by an attacker to abuse a process will inevitably cause the process to diverge from the expected call graph, XGuard Integrity can detect and stop such attacks.
-
Allows Only Predefined Code to Run
XGuard Integrity automatically generates a whitelist of permitted programs and scripts and prevents the execution of applications that are not included on the whitelist. With this capability, even if a hacker drops malware into flash storage, the malware is recognized as unauthorized when it attempts to execute because it is not included on the whitelist, and its execution is blocked.
-
Automatic Policy Generation
When an image file is generated for ECU code, XGuard Integrity is automatically installed on the ECU operating system and subsequently operates autonomously. The Management Console displays automatically generated policies and also allows policies to be customized as needed.
-
Runtime Protection and Incident Reporting
XGuard Integrity continuously monitors all code execution and decides in real time whether to allow or block code at runtime.
If an attacker attempts to run external code or launches in-memory attacks against various functions, the product detects and blocks these actions, and generates a report containing detailed contextual information about the attack.
This provides both protection and forensic data to help identify vulnerabilities, enabling rapid response and remediation. -
Minimal Performance Impact
XGuard Integrity is designed with optimal performance in mind.
Even while enforcing security policies, it uses only about 1–2% of CPU resources.
Security Products
- Next-Generation Firewall
- Targeted Attack Protection
- Cloud Security / Virtualization
- Mobile / Endpoint Security
- Email Security
- Anti-Phishing
(BEC etc.) - Application Security
- Server Security
- Sandbox
- File Sanitization
- Log Analysis
- Server Monitoring
- Encryption
- Security Policy
- Industrial Control System Security
- Connected Car Security
- WAAP
- Browser Security
- Cloud Backup
- SASE
- ASM
- Vulnerability Management
- Security for AI