Skip to main content

Karamba’s Carwall thwarts mass hacks

Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving. Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation. David Barzilai, the company’s chairman and co-founder, said with tens of millions of l
September 13, 2016 Read time: 2 mins
8519 Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving.  

Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation.
 
David Barzilai, the company’s chairman and co-founder, said with tens of millions of lines of code in car software, it is impossible to guarantee all security bugs are eliminated. Carwall does not stop a hacker exploiting a security bug to transmit malware to a vehicle’s ECUs but it does prevent that malware being activated.

When Carwall detects foreign activity or code on an ECU it sends an alert to the manufacturer and system providers’ details on security bugs the hackers exploited, the code they attempted to run and the function it would execute. According to Barzilai, as the factory settings are definitive, Carwall does not produce false positives.

The software can be installed retrospectively to in-service vehicles by authorised distributers but cannot prevent individual hacks where the hacker can physically connect the vehicle’s CANbus architecture.

For more information on companies in this article

Related Content

  • PennDOT 511 traveller information system to be privatised
    January 11, 2013
    The Pennsylvania Department of Transport (PennDOT) 511 system, 511PA, and the Pennsylvania Turnpike’s Roadway Information Program (TRIP), are to be privatised, following approval by the Pennsylvania Public Private Transportation Partnership (P3) Board of a project soliciting private sector proposals to manage and operate the systems. In operation since 2009, 511PA provides traffic-delay warnings, weather forecasts, average traffic speeds on urban interstates and access to more than 670 traffic cameras. The
  • US eyes European model for Illinois toll road upgrade
    May 30, 2014
    David Crawford welcomes the adoption of European-style ITS technology by the US. The Jane Addams Memorial Tollway in Illinois, US is well on the way towards becoming a ‘smart traffic corridor’, taking full advantage of active traffic management (ATM or ‘managed lanes’) technology that originated in Europe. It is one of the first American toll roads to do so; preliminary work began in 2014 and will continue through to 2016. Jane Addams is one of four toll roads operated by the publicly-owned Illinois State T
  • Bosch’s Perfectly Keyless turns the smartphone into a car key
    November 15, 2017
    Bosch aims to end the ritual hunt for car keys with its Perfectly Keyless digital vehicle access system for vehicles equipped with suitable proximity sensors and control system. Drivers download an app onto their smartphone and connect the car to the app; the smartphone generates a one-off security key that fits the vehicle’s ‘digital lock’. The system then uses a wireless connection to the on-board sensors to measure how far away the smartphone is, and to identify the security key.
  • Safelane automates work zone perimeter guarding
    June 12, 2015
    The safety of workers during road closures and working alongside, or above, live lanes is becoming an automated process. Ten workers suffered major injuries while working on or near motorways and major A roads in England in 2013, and between 2009 and 2013 eight had been killed. It was against that background that the first commercial application Safelane, the automated traffic management system designed to detect work zone incursions, was carried out during the temporary closure of a motorway.