Skip to main content

Karamba’s Carwall thwarts mass hacks

Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving. Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation. David Barzilai, the company’s chairman and co-founder, said with tens of millions of l
September 13, 2016 Read time: 2 mins
8519 Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving.  

Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation.
 
David Barzilai, the company’s chairman and co-founder, said with tens of millions of lines of code in car software, it is impossible to guarantee all security bugs are eliminated. Carwall does not stop a hacker exploiting a security bug to transmit malware to a vehicle’s ECUs but it does prevent that malware being activated.

When Carwall detects foreign activity or code on an ECU it sends an alert to the manufacturer and system providers’ details on security bugs the hackers exploited, the code they attempted to run and the function it would execute. According to Barzilai, as the factory settings are definitive, Carwall does not produce false positives.

The software can be installed retrospectively to in-service vehicles by authorised distributers but cannot prevent individual hacks where the hacker can physically connect the vehicle’s CANbus architecture.

Related Content

  • July 16, 2012
    Adopting universal technology platforms for tolling
    Dave Marples of Technolution argues that the continuing development of tolling-specific onboard equipment is leading us up a blind alley. We should, he says, be looking to realise universal platforms with universal application. The near-future automobile contains information systems of a sophistication to rival a jet airliner of only a few years ago, yet is 'piloted' by a considerably less well-trained individual of highly variable mental and physical capacity, and operated in a hostile, unpredictable and p
  • March 2, 2016
    Study reveals major concerns over the security of connected cars
    New research has revealed that half of British drivers (49 per cent) are concerned about the safety of the connected car, with automotive manufacturers also admitting there could be a security lag of up to three years before systems catch up with cyber threats. The report, commissioned by Veracode and carried out by the International Data Corporation (IDC), revealed half of drivers are concerned about the security of driver-aid applications, such as adaptive cruise control, self-parking, and collision av
  • January 26, 2012
    Increasing road safety with automated driver assistance systems
    Jon Masters looks at how drivers will be trained to use the increasing number of advanced driver assistance systems being incorporated into modern cars
  • July 24, 2018
    ‘Only 20% of people’ would put their child inside an AV, says Fujitsu
    Only 20% of people would be prepared to put their child inside an autonomous vehicle (AV), according to research from Fujitsu. People are more anxious about adopting digital services in travel than they are in other areas of their lives, according to Russell Goodenough, the company’s managing director of business and transport. Just 40% of people would put their trust in an AV - and the transport sector is falling behind in the race to digitisation, the company says. Speaking at a media forum in Lo