KasperskyOS is a specialized operating system designed for embedded systems with stringent digital security requirements. By design, KasperskyOS significantly reduces the chances of unauthorized functionality and thus mitigates the risk of digital attacks. After a huge undertaking, for the needs of which the cream of Kaspersky's crop of experts had to give their best for 15 years, KasperskyOS is now commercially available to Original Equipment Manufacturers (OEMs), Original Design Manufacturers (ODMs), system integrators and software developers around the world. 
The core applications of the operating system are specifically tailored to the needs of the automotive and telecommunications industries, as well as the needs of critical infrastructure.
KasperskyOS introduces a secure-by-design environment for the ever-growing number of embedded systems and IoT devices that are increasingly under attack. In a modern connected world, where valuable IoT devices are used by consumers, deployed in critical infrastructure, and control many aspects of our daily lives, the demand for a robust security approach is greater than ever.
Based on a new and entirely in-house developed microkernel, it uses established security-oriented development principles such as Separation Kernel, Reference Monitor, Multiple Independent Levels of Security and the Flux Advanced Security Kernel architecture. KasperskyOS was designed based on the requirements of specific industries and thus solves not only security issues, but also addresses the organizational and business challenges associated with securing application development for embedded systems.
The story
Andrey Doukhvalov, Head of Future Technologies and Chief Security Architect at Kaspersky Lab, comments: “The idea behind KasperskyOS emerged 15 years ago, when a small group of experts discussed an approach that would make it impossible to execute undocumented functionality. Further research revealed that such a design is very difficult to implement in the environment of a conventional, general-purpose operating system. To address this, we chose to create our own operating system that follows the universally adopted rules of secure development, but also introduces many unique features, making it not only secure, but also relatively easy to deploy in applications where protection is the main concern.”
Eugene Kaspersky, President and CEO of Kaspersky Lab, comments: “Our operating system was launched when viruses were still the most serious cybersecurity problem – long before sophisticated attacks on industrial systems emerged and long before every aspect of our lives began to be completely dependent on computer systems. Back then, the concept of “security without boundaries” was certainly not on the agenda of the growing IT population. We understood from the beginning that designing our own operating system would be a huge undertaking – a project that would require enormous resources for many years before it could be brought to market. Today we see a clear demand for enhanced security in critical infrastructure, telecommunications and the financial sector, as well as for consumer and industrial IoT devices. At first, it was a risky investment that no other security vendor had the courage to make. But today, thanks to our efforts, we have a product that provides the highest possible level of “immunity” against digital attacks – a product based on principles that can be independently verified.”
The idea
KasperskyOS is designed to allow programs to perform only documented procedures. Developing applications for KasperskyOS requires the creation of “traditional” code, as well as a strict security policy that defines all types of documented functionality. Only what is defined by this policy can be executed, including the functionality of the operating system itself. Such an approach turned out to be very time-consuming during the KasperskyOS development process, but it offers application developers a certain advantage: a security policy can be developed in parallel with the actual functionality. The functionality itself can actually be tested immediately: an error in the code means undocumented behavior, which is blocked by the operating system. Most importantly, the development of a security policy can be tailored to business needs: security can be tailored to the requirements of the application, and not the
Andrey Nikishin, Head of Future Technologies Business Development, comments: “There is no such thing as 100% security, but KasperskyOS guarantees our customers the first 99%. From a technical point of view, in a truly complex environment, attempts to introduce a specific code into our system cannot be successful. Our advantage is that, since any malicious operation is unrecorded by the security policy, being an integral part of any application makes it impossible for the payload to be executed. Therefore, KasperskyOSis immune to today’s typical digital threats.”
Installation flexibility
KasperskyOS is not a general-purpose operating system. It meets the requirements and is designed for embedded devices, and is aimed at three main industries: telecommunications, automotive and industry. In addition, Kaspersky Lab also develops development packages for the financial industry (POS and thin client PS security) and strengthening the security of critical functions for general-purpose Linux-based systems and endpoints in particular. Ease of installation is achieved by three packages that implement specific features of KasperskyOS.
KasperskyOS a basis for building devices such as network routers, IP cameras or IoT controllers. It addresses the needs of the telecommunications industry, critical infrastructure applications and the emerging growth of the Internet of Things.
Kaspersky Secure Hypervisor, at a slightly reduced cost, enables applications to run with tight control over how they communicate with each other. It addresses the needs of telecommunications, the automotive industry, and can also be used for general security purposes, up to the secure operation of endpoints.
Kaspersky Security System integrates security into conventional operating systems, as well as other embedded and real-time operating systems with minimal development overhead.
Availability
KasperskyOS is available to Original Equipment Manufacturers (OEMs), Original Design Manufacturers (ODMs), system integrators and software developers worldwide. Successful projects have already been implemented with Russian system integrator Kraftway (secure network router), SYSGO (enhanced security for the real-time PikeOS operating system with Kaspersky’s security system) and with European system integrator BE.services (integration of KasperskyOS technology into specialized Programmable Logic Controllers). As a unique project, tailored to each customer, KasperskyOS pricing varies depending on requirements. More information about KasperskyOS, Kaspersky Secure Hypervisor and Kaspersky’s security system, as well as contact information for potential customers, is available on a dedicated website. Technical information is available in a detailed article on the dedicated website Securelist.com.
