Skip to main content

Karamba’s Carwall thwarts mass hacks

Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving. Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation. David Barzilai, the company’s chairman and co-founder, said with tens of millions of l
September 13, 2016 Read time: 2 mins
8519 Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving.  

Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation.
 
David Barzilai, the company’s chairman and co-founder, said with tens of millions of lines of code in car software, it is impossible to guarantee all security bugs are eliminated. Carwall does not stop a hacker exploiting a security bug to transmit malware to a vehicle’s ECUs but it does prevent that malware being activated.

When Carwall detects foreign activity or code on an ECU it sends an alert to the manufacturer and system providers’ details on security bugs the hackers exploited, the code they attempted to run and the function it would execute. According to Barzilai, as the factory settings are definitive, Carwall does not produce false positives.

The software can be installed retrospectively to in-service vehicles by authorised distributers but cannot prevent individual hacks where the hacker can physically connect the vehicle’s CANbus architecture.

Related Content

  • May 25, 2018
    Here Technologies releases OTA technology for connected and self-driving cars
    Amsterdam’s Here Technologies claims its over-the-air (OTA) solution will help keep connected and self-driving vehicles safe with less cost to automakers and car owners. OTA Connect is intended to ensure data, software and firmware can be transferred between the cloud and a car securely to update vehicle functions. Ralf Herrtwich, senior vice president automotive at Here, says the device allows automakers to update vehicles remotely. Drivers can also purchase upgrades and features more conveniently.
  • November 20, 2013
    Bluetooth and Wi-Fi offer new options for travel time measurements
    New trials show Bluetooth and Wi-Fi signals can be reliably used for measuring travel times and at a lower cost than an ANPR system, but which is the better proposition depends on many factors. Measuring travel times has traditionally relied automatic number plate (or licence plate) recognition (ANPR/ALPR) cameras capturing the progress of vehicles travelling along a pre-defined route. Such systems also have the benefit of being able to count passing traffic and have become a vital tool in dealing with c
  • August 24, 2015
    Japan looking at technology to prevent hacking of self-driving cars
    According to the Japan Times, Japan’s Internal Affairs and Communications Ministry is concerned about the possibility that a cyber attack on self-driving car systems might lead to traffic accidents. It has drawn up guidelines in a bid to defend against the hacking of a proposed next-generation driving support system that aims to help accelerate the development of autonomous driving cars. The ITS (Intelligent Transport Systems) Connect Promotion Consortium, which is made up of automakers and electronics-m
  • April 9, 2014
    The bus to IP access control has left the station
    David Lenot examines how mass transit agencies can benefit from IP access control and the features required to ensure a sound investment. With millions of commuters relying on their services daily, mass transit agencies are faced with the unfortunate reality that their operations are susceptible to threats. A single incidence of unauthorised access to restricted areas and buildings could be the catalyst to damaged property, endangered lives or other unfortunate events. Unlike an international airport