Skip to main content

Karamba’s Carwall thwarts mass hacks

Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving. Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation. David Barzilai, the company’s chairman and co-founder, said with tens of millions of l
September 13, 2016 Read time: 2 mins
8519 Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving.  

Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation.
 
David Barzilai, the company’s chairman and co-founder, said with tens of millions of lines of code in car software, it is impossible to guarantee all security bugs are eliminated. Carwall does not stop a hacker exploiting a security bug to transmit malware to a vehicle’s ECUs but it does prevent that malware being activated.

When Carwall detects foreign activity or code on an ECU it sends an alert to the manufacturer and system providers’ details on security bugs the hackers exploited, the code they attempted to run and the function it would execute. According to Barzilai, as the factory settings are definitive, Carwall does not produce false positives.

The software can be installed retrospectively to in-service vehicles by authorised distributers but cannot prevent individual hacks where the hacker can physically connect the vehicle’s CANbus architecture.

Related Content

  • October 7, 2013
    ANPR shockwaves emanate from Royston ruling
    Colin Sowman looks at how a ruling regarding ANPR cameras in a small English town could have wide-reaching implications. Superficially it was an easy decision: the local council and traders wanted, and were prepared to fund, automatic number plate recognition (ANPR) cameras installed to deter crime in Royston, a small town (population 17,000) in rural England.
  • October 26, 2017
    Applied Information’s app gets Marietta connected
    Must the benefits of connected vehicle technology wait for a generation of new or retrofitted vehicles? The US city of Marietta is about to find out. Can connected vehicle functionality be delivered via a smartphone? Well, in Marietta, Georgia, they are about to answer that question. The city is testing a smartphone app which warns motorists of nearby cyclists and pedestrians, approaching first responders, wrong-way driving, entering active school zones and much more.
  • October 28, 2016
    New solutions for catching texting drivers
    Many countries have laws prohibiting texting while driving but enforcement is proving difficult – David Crawford looks at some new approaches being tried by authorities. Finding definitive solutions – technological, regulatory and educational - to the potentially lethal practice of people driving while using mobile phones is proving elusive, while the stakes grow higher.
  • April 5, 2017
    Autonomous vehicles will not prevent half of real-world crashes
    Alan Thomas of CAVT looks at the reality behind the safety claims fuelling the drive towards autonomous vehicles