Skip to main content

Karamba’s Carwall thwarts mass hacks

Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving. Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation. David Barzilai, the company’s chairman and co-founder, said with tens of millions of l
September 13, 2016 Read time: 2 mins
8519 Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving.  

Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation.
 
David Barzilai, the company’s chairman and co-founder, said with tens of millions of lines of code in car software, it is impossible to guarantee all security bugs are eliminated. Carwall does not stop a hacker exploiting a security bug to transmit malware to a vehicle’s ECUs but it does prevent that malware being activated.

When Carwall detects foreign activity or code on an ECU it sends an alert to the manufacturer and system providers’ details on security bugs the hackers exploited, the code they attempted to run and the function it would execute. According to Barzilai, as the factory settings are definitive, Carwall does not produce false positives.

The software can be installed retrospectively to in-service vehicles by authorised distributers but cannot prevent individual hacks where the hacker can physically connect the vehicle’s CANbus architecture.

For more information on companies in this article

Related Content

  • Study finds big differences in toll collection cases
    December 16, 2013
    Examination of Norway’s tolling companies finds much to praise, and some criticisms too, as Torill Eidsheim told delegates at the ASECAP conference. The cost of collecting tolls has a substantial effect on the profitability, or otherwise, of tolling companies and is within the company’s control to a far greater degree than, for instance, traffic volumes. And while it is easy to assume that all tolling companies incur similar collection costs, that is not always the case according to Torill Eidsheim, pres
  • ITS America 2016 San Jose tours programme shows the present and future of ITS
    May 27, 2016
    The major theme of Thursday, June 16, at ITS America 2016 San Jose will be a series of tours that exemplify intelligent transportation at work today and with an eye to the future. The Interstate 80 Integrated Corridor Mobility Project Tour will take in one of the most complex integrated Active Traffic Management systems in the country. This tour includes a stop at the Caltrans TMC in Oakland for an overview of system operations
  • Major growth predicted for OEM embedded telematics
    September 5, 2014
    According to a new research report by Berg Insight, shipments of OEM embedded telematics systems worldwide are forecasted to grow from 8.4 million units in 2013 at a compound annual growth rate (CAGR) of 30.6 per cent to reach 54.5 million units in 2020. Moreover, Berg Insight forecasts that the number of cars sold worldwide equipped with head-units featuring handset-based telematics capabilities will grow from 7 million in 2013 to 68.5 million in 2020.
  • More than 20 million connected cars with built-in software-based security by 2020
    February 14, 2014
    The findings of ABI Research’s Automotive Safety & Autonomous Driving and Cybersecurity Research Services indicate that while traditional safety telematics services such as eCall, bCall, stolen vehicle tracking, and diagnostics aimed at the physical protection of vehicles, drivers and passengers are becoming main stream, awareness is growing about the threat of cyber-attacks and their impact on the physical integrity of persons, especially with vehicle-to-vehicle communication and autonomous vehicles. This