Skip to main content

Karamba’s Carwall thwarts mass hacks

Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving. Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation. David Barzilai, the company’s chairman and co-founder, said with tens of millions of l
September 13, 2016 Read time: 2 mins
8519 Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving.  

Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation.
 
David Barzilai, the company’s chairman and co-founder, said with tens of millions of lines of code in car software, it is impossible to guarantee all security bugs are eliminated. Carwall does not stop a hacker exploiting a security bug to transmit malware to a vehicle’s ECUs but it does prevent that malware being activated.

When Carwall detects foreign activity or code on an ECU it sends an alert to the manufacturer and system providers’ details on security bugs the hackers exploited, the code they attempted to run and the function it would execute. According to Barzilai, as the factory settings are definitive, Carwall does not produce false positives.

The software can be installed retrospectively to in-service vehicles by authorised distributers but cannot prevent individual hacks where the hacker can physically connect the vehicle’s CANbus architecture.

For more information on companies in this article

Related Content

  • Ford targets fully autonomous vehicle in 2021
    August 17, 2016
    Ford has announced its intention to have a high-volume, fully autonomous vehicle in commercial operation in 2021. The new vehicle will be a Society of Automotive Engineers-rated level 4-capable vehicle without a steering wheel or gas and brake pedals. It is being specifically designed for commercial mobility services, such as ride sharing and ride hailing, and will be available in high volumes. SAE level 4 is one level below full automation and is defined as ‘mode-specific performance by an automated
  • VW faces first legal test case over emissions in Germany
    January 6, 2017
    German consumer rights champion myRight filed the first legal test case against Volkswagen (VW) in Germany on Tuesday, raising pressure on the carmaker to compensate customers in Europe over the emissions scandal, according to Reuters. VW has pledged billions to compensate US owners of its diesel-powered cars, but has so far rejected any compensation for the 8.5 million affected vehicles in Europe where different legal rules weaken the chances of affected customers winning a pay-out. Instead, VW is in
  • DSRC? ‘It’s become a faith-based thing’
    March 2, 2021
    The US FCC’s decision on 5.9GHz led to Applied Information offering DSRC buybacks to DoTs. Bryan Mulligan tells Adam Hill that we now just need to get on and roll out CV technology...
  • DSRC holds the key to tomorrow's transportation
    June 15, 2016
    Dedicated Short-Range Communication (DSRC) technologies are poised to revolutionise transportation system planning, management and operations. But will widespread US adoption take five years, or twenty? As Ben Pierce of Battelle explains, the answer depends largely on which roadmap the ITS community chooses to follow for deployment.