Skip to main content

Karamba’s Carwall thwarts mass hacks

Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving. Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation. David Barzilai, the company’s chairman and co-founder, said with tens of millions of l
September 13, 2016 Read time: 2 mins
8519 Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving.  

Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation.
 
David Barzilai, the company’s chairman and co-founder, said with tens of millions of lines of code in car software, it is impossible to guarantee all security bugs are eliminated. Carwall does not stop a hacker exploiting a security bug to transmit malware to a vehicle’s ECUs but it does prevent that malware being activated.

When Carwall detects foreign activity or code on an ECU it sends an alert to the manufacturer and system providers’ details on security bugs the hackers exploited, the code they attempted to run and the function it would execute. According to Barzilai, as the factory settings are definitive, Carwall does not produce false positives.

The software can be installed retrospectively to in-service vehicles by authorised distributers but cannot prevent individual hacks where the hacker can physically connect the vehicle’s CANbus architecture.

For more information on companies in this article

Related Content

  • Cooperative infrastructure systems waiting for the go ahead
    February 3, 2012
    Despite much research and technological promise, progress towards cooperative infrastructure system deployment is still slow. Here, Robert Cone and John Miles take a considered look at how and when it might come about. From a systems engineering viewpoint it looks logical and inevitable that vehicles should be communicating between themselves and with the road infrastructure. But seen from a business viewpoint the case is not proven.
  • Quest chooses Samsara to boost fleet safety
    April 5, 2024
    AI dash cams and driver coaching tools will incentivise drivers to create safety culture
  • Ten US automakers commit to automatic braking on new vehicles
    September 14, 2015
    Ten major vehicle manufacturers have committed to making automatic emergency braking (AEB) a standard feature on all new vehicles built, the US Department of Transportation, its National Highway Traffic Safety Administration (NHTSA), and the Insurance Institute for Highway Safety (IIHS) announced today. The announcement, made at the dedication of IIHS's newly expanded Vehicle Research Center, represents a major step toward making crash prevention technologies more widely available to consumers. The ten c
  • Need for standardisation of toll classes
    March 2, 2012
    In a previous article Bob Lees of Idris Technology Ltd looked at the appropriateness of toll classes in relation to all-electronic toll fee collection. Here, he looks at how addressing classification standardisation could avoid downstream aggravation and cost