Security Products

Comprehensive Security Throughout the IoT Product Lifecycle—from Development and Testing to Operation Karamba's Total IoT Security


KarambaTotaIoTSecurity.png Karamba's Total IoT Security is a comprehensive security solution that can be applied seamlessly throughout the entire lifecycle of IoT products. It combines three components: (1) XGuard Protect, an autonomous security product that protects embedded software in devices from cyberattacks; (2) Vcode, a secure development platform that visualizes risks by analyzing code vulnerabilities; and (3) XGuard Monitor, which enables large-scale IoT security monitoring. For IoT devices and transportation vehicles that are already in operation, the XGuard Monitor agent can be added when firmware2 is updated using OTA1 functionality. This enables security monitoring without modifying the firmware itself. As a result, EDR-based monitoring of attacks over the network becomes possible, providing effective security measures for existing IoT devices and vehicles in operation, which were previously difficult to protect.

*1 OOTA (Over The Air): A function for sending and receiving data over wireless communication when updating software and performing similar operations.
*2 Firmware: Software used to control hardware.


Main Functions and Features

  1. XGuard Protect
    • Automatically strengthens the security of connected systems through embedded runtime integrity protection.
    • Defends against a wide range of attacks, including droppers that use files or scripts, as well as fileless attacks that exploit memory vulnerabilities such as buffer overflows.
    • Prevents attacks that exploit zero-day and other vulnerabilities while minimizing false positives through Control Flow Integrity (CFI) and application whitelisting
    • The runtime layer complements static code analysis and defends mission-critical connected systems such as network equipment against advanced attacks.
  2. Vcode
    • Visualizes security issues by performing binary analysis on IoT device firmware.
    • Proposes prioritized remediation measures based on platform-specific information.
    • Manages security posture and progress, and performs compliance verification using checklists, with the results output as reports.
    • Easily integrates with Continuous Integration / Continuous Delivery (CI/CD) pipelines.
    • Can be installed as a virtual machine in both on-premises and cloud environments (image file provided).
  3. XGuard Monitor
    • Collects OS, applications, and network events via an agent and uses AI-driven correlation analysis to detect early indicators of failures and threats.
    • Minimizes event noise and reduces throughput by more than 90%, enabling support for millions of deployed devices.
    • Detects and analyzes a wide range of threats by comparing IoT device behavior with predefined policies, historical baselines, and profiles of similar devices.
    • Integrates logs and events with leading SOC platforms through well-defined APIs.
    • Delivered as a cloud-based SaaS solution.
    • By adding an agent to the target device, security monitoring can be implemented without modifying the firmware.