Skip to main content

Karamba’s Carwall thwarts mass hacks

Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving. Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation. David Barzilai, the company’s chairman and co-founder, said with tens of millions of l
September 13, 2016 Read time: 2 mins
8519 Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving.  

Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation.
 
David Barzilai, the company’s chairman and co-founder, said with tens of millions of lines of code in car software, it is impossible to guarantee all security bugs are eliminated. Carwall does not stop a hacker exploiting a security bug to transmit malware to a vehicle’s ECUs but it does prevent that malware being activated.

When Carwall detects foreign activity or code on an ECU it sends an alert to the manufacturer and system providers’ details on security bugs the hackers exploited, the code they attempted to run and the function it would execute. According to Barzilai, as the factory settings are definitive, Carwall does not produce false positives.

The software can be installed retrospectively to in-service vehicles by authorised distributers but cannot prevent individual hacks where the hacker can physically connect the vehicle’s CANbus architecture.

For more information on companies in this article

Related Content

  • ITS & Ethics: yes means yes
    March 4, 2019
    There is an increasing wealth of information available to create personalised transport solutions – and the possibilities are exciting. But, Andrew Bunn warns, ITS companies have a duty to be explicit in explaining what people’s data is going to be used for
  • EU defines and limits scope of tolling concessions
    September 16, 2014
    New regulations are set to standardise the process of awarding concessions across the European Union. In the wake of several inconsistent judgements at the European Court of Justice, the European Commission has approved new legislation that defines a concession. The basic demarcation from a public contract remains the same in that concessions include the right to exploit the work or services provided instead of payment. However, at the point of signing, the regulations impose an all-inclusive threshold of €
  • Kapsch looks to the future
    December 16, 2014
    Colin Sowman reports from a two-day meeting where industry leaders, academics and political advisers presented their thoughts on the future of mobility. Most governments do not dare to introduce tolling systems… they are too frightened.” So said Georg Kapsch in his capacity of chief operating officer of Kapsch TrafficCom, during a forward-looking press event at the company’s headquarters in Vienna.
  • Southampton City Council deploys bus lane enforcement solution
    June 7, 2016
    Southampton City Council in the UK is introducing CCTV enforcement of bus lanes in key areas of the city using Videalert’s DfT Manufacturer Certified hosted solution. The new fixed bus lane cameras will go live on 20 June 2016. The Videalert solution has been procured through Balfour Beatty Living Places (BBLP) which has a ten-year contract to manage all highway infrastructure assets on behalf of Southampton City Council. Videalert’s hosted platform does not require any hardware or software to be i