Skip to main content

Karamba’s Carwall thwarts mass hacks

Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving. Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation. David Barzilai, the company’s chairman and co-founder, said with tens of millions of l
September 13, 2016 Read time: 2 mins
8519 Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving.  

Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation.
 
David Barzilai, the company’s chairman and co-founder, said with tens of millions of lines of code in car software, it is impossible to guarantee all security bugs are eliminated. Carwall does not stop a hacker exploiting a security bug to transmit malware to a vehicle’s ECUs but it does prevent that malware being activated.

When Carwall detects foreign activity or code on an ECU it sends an alert to the manufacturer and system providers’ details on security bugs the hackers exploited, the code they attempted to run and the function it would execute. According to Barzilai, as the factory settings are definitive, Carwall does not produce false positives.

The software can be installed retrospectively to in-service vehicles by authorised distributers but cannot prevent individual hacks where the hacker can physically connect the vehicle’s CANbus architecture.

For more information on companies in this article

Related Content

  • Communications redundancy increases VMS reliability
    December 17, 2014
    Hybrid communications to variable message signs increase resilience to natural disasters and enable deployment in remote areas, as Alan Allegretto explains. Variable Message Signs (VMSs) are a common sight and a well-proven means to improve public safety on our roads and highways. ITS professionals rank the VMS as second only to interoperable radios as the most important technology to improve effectiveness during emergency incidents and evacuations. Ironically, however, current systems suffer from one criti
  • Gridsmart tackling infrastructure security threat
    June 7, 2018
    A new division, formed by Gridsmart Technologies only three weeks ago, is making its public debut here at ITS America Detroit. Gridsmart Information Security & Threat Intelligence (ISTI) is an industry first-of-its-kind transportation cybersecurity group dedicated to providing vulnerability/threat assessments and tailored security strategies. It will work with private companies, departments of transportation, and others to proactively defend and enhance the resiliency of their technical infrastructure
  • Autonomous car accidents revealed in California
    May 13, 2015
    Associated Press (AP) recently reported that three of Google's self-driving cars have been involved in accidents since September, when California allowed them to begin using public roads. The parts supplier Delphi Automotive had one accident, which an accident report the company provided to AP showed was not its fault. Delphi said at the time the car was being driven by the person the DMV requires behind the wheel during testing. US consumer rights advocate Consumer Watchdog has now called on Google
  • Here: AI has place in ‘privacy by design’
    June 23, 2020
    Artificial intelligence may improve traffic in cities and keep location data private, but Here Technologies shows that it only takes four points of anonymous data to predict your identity.