Skip to main content

Karamba’s Carwall thwarts mass hacks

Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving. Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation. David Barzilai, the company’s chairman and co-founder, said with tens of millions of l
September 13, 2016 Read time: 2 mins
8519 Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving.  

Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation.
 
David Barzilai, the company’s chairman and co-founder, said with tens of millions of lines of code in car software, it is impossible to guarantee all security bugs are eliminated. Carwall does not stop a hacker exploiting a security bug to transmit malware to a vehicle’s ECUs but it does prevent that malware being activated.

When Carwall detects foreign activity or code on an ECU it sends an alert to the manufacturer and system providers’ details on security bugs the hackers exploited, the code they attempted to run and the function it would execute. According to Barzilai, as the factory settings are definitive, Carwall does not produce false positives.

The software can be installed retrospectively to in-service vehicles by authorised distributers but cannot prevent individual hacks where the hacker can physically connect the vehicle’s CANbus architecture.

For more information on companies in this article

Related Content

  • Ertico weaves tunnel visions into the ‘big picture’
    April 7, 2017
    As he takes the wheel at Ertico - ITS Europe, Jacob Bangsgaard talks to ITS International about the challenges and opportunities facing the organisation and the ITS industry. Ertico - ITS Europe’s new CEO, Jacob Bangsgaard, is no stranger to the organisation having spent five years there before moving to the FIA (Federation Internationale de l’Automobile) in 2006. Four years later he became director general of the FIA’s Region I (EMEA), which represents more than 100 mobility clubs, and in 2012 he joined Er
  • Ertico weaves tunnel visions into the ‘big picture’
    April 7, 2017
    As he takes the wheel at Ertico - ITS Europe, Jacob Bangsgaard talks to ITS International about the challenges and opportunities facing the organisation and the ITS industry. Ertico - ITS Europe’s new CEO, Jacob Bangsgaard, is no stranger to the organisation having spent five years there before moving to the FIA (Federation Internationale de l’Automobile) in 2006. Four years later he became director general of the FIA’s Region I (EMEA), which represents more than 100 mobility clubs, and in 2012 he joined Er
  • SwRI investigates cybersecurity weaknesses in transportation management systems
    November 6, 2017
    Southwest Research Institute (SwRI), in San Antonio, has been awarded a $750,000 (£573,000) contract from the Transportation Research Board to help state and local agencies address cyber-attack risks on current transportation systems and those posed by future connected vehicles. Cyber security firm, Praetorian will support SwRI by conducting a security audit of traffic management systems and develop a web-based guide to help transportation agencies learn how to safeguard equipment.
  • Assessing the potential of in-vehicle enforcement systems
    December 4, 2012
    Jason Barnes considers the social and ethical ramifications of using in-vehicle safety technologies to fulfil enforcement functions. Although policy documents often imply close correlation between enforcement, compliance and safety – in part, as a counter to accusations that enforcement is rather more concerned with revenue generation – there is a noticeable reluctance among policy makers and auto manufacturers to exploit in-vehicle safety systems for enforcement applications. From a technical perspective t