Skip to main content

Karamba’s Carwall thwarts mass hacks

Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving. Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation. David Barzilai, the company’s chairman and co-founder, said with tens of millions of l
September 13, 2016 Read time: 2 mins
8519 Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving.  

Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation.
 
David Barzilai, the company’s chairman and co-founder, said with tens of millions of lines of code in car software, it is impossible to guarantee all security bugs are eliminated. Carwall does not stop a hacker exploiting a security bug to transmit malware to a vehicle’s ECUs but it does prevent that malware being activated.

When Carwall detects foreign activity or code on an ECU it sends an alert to the manufacturer and system providers’ details on security bugs the hackers exploited, the code they attempted to run and the function it would execute. According to Barzilai, as the factory settings are definitive, Carwall does not produce false positives.

The software can be installed retrospectively to in-service vehicles by authorised distributers but cannot prevent individual hacks where the hacker can physically connect the vehicle’s CANbus architecture.

Related Content

  • October 8, 2018
    Blockchain: the next big thing for ITS? Really?
    Everyone’s heard of blockchain – but most people are less sure about what it really is, and how it might be used in transportation. Andrew Williams peers into cyberspace to find some answers. A growing number of organisations in the ITS industry are exploring how blockchain technology could be used for ITS and mobility applications. So, what exactly is blockchain technology? What are the key current and potential applications in the mobility and ITS sector? And what practical benefits might it bring?
  • January 7, 2013
    Need for secure approach to connected vehicle technology
    Accidental or malicious issue of false messages to connected vehicles could result in dire consequences, so secure systems of authentication and certification are likely to be necessary, write Paul Avery and Sandra Dykes. Connectivity among vehicles in urban traffic systems will provide opportunity for beneficial impacts such as congestion reduction and greater safety. However, it also creates security risks with the potential for targeted disruption. Security algorithms, protocols and procedures must take
  • November 4, 2014
    Oberthur Technologies secures web payments with Dynamic CVV/CVC
    Card-not-present (CNP) fraud could be all but eliminated thanks to a revolutionary card security innovation set to be rolled out by Oberthur Technologies (OT) next year. OT has developed a dynamic back-of-card security CVC/CVV code that changes every hour on an e-paper panel.
  • December 8, 2016
    Data handling important for autonomous vehicles
    Data handling is becoming an ever-greater part of transportation and never more so than with autonomous vehicles, as Andrew Bardin Williams hears from some big names.