
Balance of Security and Performance
Minimal ECU performance impact by considering EEA and ECU integration.
Modular and Configurable
AUTOSAR compatible. Enabling adequate features and configurations to meet different vehicles and service levels.
Ahead of Threats
Deploy virtual patches or IPS rules to prevent and intercept an exploit.
Frictionless IDPS for ECU Hardening
Stay ahead of trending cyberattacks and future regulatory changes with VicOne's Intrusion Detect & Protect System (IDPS) - xCarbon. Designed for hardened security, this robust software-based security agent includes critical software that can be config for critical ECU components such as in-vehicle infotainment system (IVI), telematics box (TCU), and gateways while balancing security and performance. Additionally, in-vehicle network communications are heavily guarded, monitored, and analyzed through Controller Area Network (CAN) anomaly detection and Ethernet intrusion detection, thus providing timely alerts for when threats arise.
xCarbon is 100% AUTOSAR IDS protocol compatible. It provides superior detection in the vehicle, allowing SOC's to quickly understand the nature of the attack. This contrasts with agentless solutions, which are unable to identify details on the attacks occurring on the vehicle side. Additionally, the agent performs real-time protection to timely mitigate attacks by execute pre-defined rules or up-to-date commands from VSOC.
A Dynamic and Intelligent Detection and Response for Your Vehicle
VicOne's xCarbon (IDPS) encompasses multiple software components that uses known intrusion signatures to detect and analyze traffic, while proactively filtering malicious packets and blocking offending IPs. Detection logs and telemetry data are gathered from the vehicle and optimized before being sent to VicOne's xNexus and other VSOC for analysis; with AUTOSAR IDS protocol compatible.
Advanced System Protection
- Approved Application Listings. Rule-based application control ensuring the integrity of authorized applications
- System Exploit Prevention. Analyzes and pinpoints unusual system activity to prevent vulnerability exploitation and privilege escalation
Next-Gen Ethernet Firewall
- Ethernet intrusion detection. Signature-based intrusion detection identifying suspicious events through deep packet inspection
- Virtual patch. Prevent attacks targeting known vulnerabilities with predefined signatures
- Domain/IP filtering. Detect connections to malicious domain names and IP addresses
CAN Anomaly Detection
- Malicious CAN message detection. Distinguish the system behavior against the normal behavior to detect malicious activity
Intelligent Sensor
- Telemetry Data Collection. Automated process used to collect system activities and critical events for off-board analysis and data forensics, while also protecting the ECU
Secure Log Service
- Securely maintain log records over extended periods of time and upload to the cloud with an encrypted connection
Stay Atop Vulnerabilities
xCarbon is designed to protect against known and unknown vulnerabilities, but if an exploit does arise, the Virtual Patch and IPS rules acts as a safety measure by implementing layers of security policies and rules that prevent and intercept an exploit from taking network paths to and from a vulnerability.
- Virtual Patch
- Intrusion Prevention System (IPS) Rules


VicOne customers protected ahead of patch

Vulnerability Introduced
Vulnerability Discovered
Vulnerability Privately Disclosed
Virtual Patch Created
Patch Available
Vulnerability Publicly Disclosed
Patch Installed


Other security vendors' customers at risk
Comprehensive Detection Enabled By Automotive Security Foresight
Not all data are equal and VicOne ensures that the right technique is deployed at the right time. Along each step of the data collection, from executing IDPS Rules, to machine learning and threat expert rules, these detection techniques progressively analyzes and filters out the threats for maximum detection and protection without false positives. Aside from broad protection, this results is an overall reduction of bandwidth which can further be investigated and blocked if malicious.
Other Features
Lockdown and Monitor mode
Lockdown the ECU and monitor for suspicious activities
Configurable Policy
Author flexible policies that can be used across your entire fleet
Automotive Security Foresight
Leverages Automotive Security Foresight (ASF) to provide up to the date protection against potential threats
Use Case
Protecting a Telematics Control Unit From Remote Attacks
Blog
Shifting Lanes: Riding Taiwan’s First Self-Driving Bus
Taiwan’s first self-driving bus hit the road in 2020. Although it was only a trial run, it showed tremendous promise and highlighted potential threats for autonomous vehicle technologies in the not-so-distant future.
Driven Toward Safety: Updates on the UN R155 Enforcement
The enforcement of the UN Regulation No. R155 (UN R155) in July 2022 entails cybersecurity requirements that are binding in all UNECE member countries. To comply with and stay updated on the latest security requirements, OEMs and Tier 1 suppliers must rely on comprehensive cybersecurity solutions.
VicOne Among CRN’s List of Coolest Cybersecurity Products in 2022
CRN® names VicOne as one of the top 11 coolest cybersecurity tools and products of 2022, highlighting the growing market for cybersecurity in the world of connected cars..