Skip to main content

Karamba’s Carwall thwarts mass hacks

Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving. Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation. David Barzilai, the company’s chairman and co-founder, said with tens of millions of l
September 13, 2016 Read time: 2 mins
8519 Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving.  

Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation.
 
David Barzilai, the company’s chairman and co-founder, said with tens of millions of lines of code in car software, it is impossible to guarantee all security bugs are eliminated. Carwall does not stop a hacker exploiting a security bug to transmit malware to a vehicle’s ECUs but it does prevent that malware being activated.

When Carwall detects foreign activity or code on an ECU it sends an alert to the manufacturer and system providers’ details on security bugs the hackers exploited, the code they attempted to run and the function it would execute. According to Barzilai, as the factory settings are definitive, Carwall does not produce false positives.

The software can be installed retrospectively to in-service vehicles by authorised distributers but cannot prevent individual hacks where the hacker can physically connect the vehicle’s CANbus architecture.

For more information on companies in this article

Related Content

  • Connected Vehicles test vehicle to vehicle applications
    January 19, 2012
    In the US, the ITS Joint Program Office is about to conduct a series of Driver Clinics intended to gauge public reaction to Connected Vehicle safety technologies and applications. Starting in August, the US Department of Transportation (USDOT) will test Vehicle-to-Vehicle (V2V) applications with everyday drivers in what it describes as 'normal operational scenarios'. These Driver Clinics are being carried out at six locations across the US and together with the subsequent model deployment beginning in 2012,
  • Major setback for California's high speed train
    November 28, 2013
    The future of the California high speed rail project hangs in the balance as a result of two rulings handed down by Sacramento Superior Court Judge Michael Kenny on 25 November. "The judge's ruling will prevent the [California High-Speed Rail] Authority from spending bond measure funds for construction until the funding plan is brought into compliance," said Michael Brady, co- lead attorney on the case, but because that would require finding at least US$25 billion in extra funds, Brady believes complianc
  • Germany is Mad for Vitronic
    April 30, 2025
    Managed Automated Driving project takes place in German city of Brunswick
  • IP technology the route to efficient multi-agency control rooms
    February 1, 2012
    As IP-based technology makes its presence felt in the control room sector, it makes for greater economies of scale and also offers a migration path for many other traffic management technologies. So says Barco's Guy Van Wijmeersch. Efficient control room collaboration and decision-making is only possible if operators and decision-makers have easy and timely access to information. In many cases, that information also needs to be accessible to multiple users at the same time. This is certainly so in the case