Skip to main content

Karamba’s Carwall thwarts mass hacks

Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving. Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation. David Barzilai, the company’s chairman and co-founder, said with tens of millions of l
September 13, 2016 Read time: 2 mins
8519 Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving.  

Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation.
 
David Barzilai, the company’s chairman and co-founder, said with tens of millions of lines of code in car software, it is impossible to guarantee all security bugs are eliminated. Carwall does not stop a hacker exploiting a security bug to transmit malware to a vehicle’s ECUs but it does prevent that malware being activated.

When Carwall detects foreign activity or code on an ECU it sends an alert to the manufacturer and system providers’ details on security bugs the hackers exploited, the code they attempted to run and the function it would execute. According to Barzilai, as the factory settings are definitive, Carwall does not produce false positives.

The software can be installed retrospectively to in-service vehicles by authorised distributers but cannot prevent individual hacks where the hacker can physically connect the vehicle’s CANbus architecture.

Related Content

  • January 9, 2018
    Argus partners with Renesas to secure connected and autonomous vehicles against cyber attacks
    Argus Cyber Security’s Connectivity Protection and Lifespan Protection solution suites have been integrated with Renesas Electronics Corporation’s R-Car H3 Computing Platform, in an agreement which aims to protect infotainment and telematics units in connected and autonomous vehicles against cyber-attacks. The Argus Connectivity Protection is designed with the intention of preventing malware installation, detecting operating system anomalies, isolating suspicious activity and stopping attacks from
  • June 6, 2016
    Securing V2X communications
    Cybersecurity developments are moving fast in the automotive sector, but they’re a significant hurdle for the roll-out of C-ITS applications. Jon Masters reports. In the wake of the high-profile hacking of the Jeep Cherokee and problems like the flaw in the Nissan Leaf’s companion app that could compromise the security of data about recent journeys, initiatives linked to vehicle cybersecurity seem to be moving rapidly.
  • June 2, 2014
    Machine vision makes progress in traffic applications
    Machine Vision technology is easing the burden on hard-pressed control room staff and overloaded communications networks.
  • July 27, 2023
    Kapsch: We need to move quicker towards connectivity
    Connectivity requires a lot of different parties to work together – but it’s the only way to get coverage. Alfredo Escribá, chief technology officer of Kapsch, talks to Adam Hill about the value of ‘orchestrated corridors’