Skip to main content

Karamba’s Carwall thwarts mass hacks

Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving. Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation. David Barzilai, the company’s chairman and co-founder, said with tens of millions of l
September 13, 2016 Read time: 2 mins
8519 Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving.  

Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation.
 
David Barzilai, the company’s chairman and co-founder, said with tens of millions of lines of code in car software, it is impossible to guarantee all security bugs are eliminated. Carwall does not stop a hacker exploiting a security bug to transmit malware to a vehicle’s ECUs but it does prevent that malware being activated.

When Carwall detects foreign activity or code on an ECU it sends an alert to the manufacturer and system providers’ details on security bugs the hackers exploited, the code they attempted to run and the function it would execute. According to Barzilai, as the factory settings are definitive, Carwall does not produce false positives.

The software can be installed retrospectively to in-service vehicles by authorised distributers but cannot prevent individual hacks where the hacker can physically connect the vehicle’s CANbus architecture.

For more information on companies in this article

Related Content

  • Shaking up the taxi market with smarter ride requests
    February 24, 2016
    Timothy Compston looks at the rise of Uber and ride request mobile apps. There is little doubt that the advent of Uber has come as major shock to established taxi operators and has caused regulators, cities and DOTs to rethink current regulations so they can keep pace with the changing dynamics of the marketplace.
  • European ITS Directive: From Minority Report to majority rapport
    December 1, 2023
    A 21-year old movie by Steven Spielberg appears to predict a C-ITS Day 3 use case. Richard Lax of Kapsch TrafficCom looks at the new European ITS Directive and idly wonders whether the great Hollywood movie director was once a European Commission intern in DG Move…
  • Vendor's eye view of US economic stimulus programme
    March 12, 2012
    Pete Goldin explores the impact of the US economic stimulus programme on the ITS industry from the ITS vendor perspective
  • The weighty problem of truck routing enforcement
    March 17, 2015
    The growing impact of heavy commercial vehicles on urban and interurban highway infrastructures around the world is driving the need for reliable route access restriction and monitoring. The support role of enforcement is proving fertile ground for ITS development. Bridges are especially vulnerable – and critical in terms of travel delays. The US state of Oregon’s Department of Transportation (ODOT) operates what it claims is one of the country’s most aggressive truck route restriction enforcement programme