Skip to main content

Karamba’s Carwall thwarts mass hacks

Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving. Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation. David Barzilai, the company’s chairman and co-founder, said with tens of millions of l
September 13, 2016 Read time: 2 mins
8519 Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving.  

Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation.
 
David Barzilai, the company’s chairman and co-founder, said with tens of millions of lines of code in car software, it is impossible to guarantee all security bugs are eliminated. Carwall does not stop a hacker exploiting a security bug to transmit malware to a vehicle’s ECUs but it does prevent that malware being activated.

When Carwall detects foreign activity or code on an ECU it sends an alert to the manufacturer and system providers’ details on security bugs the hackers exploited, the code they attempted to run and the function it would execute. According to Barzilai, as the factory settings are definitive, Carwall does not produce false positives.

The software can be installed retrospectively to in-service vehicles by authorised distributers but cannot prevent individual hacks where the hacker can physically connect the vehicle’s CANbus architecture.

For more information on companies in this article

Related Content

  • Connected Signals offers cities free C2X
    June 15, 2016
    Connected Signals is offering city authorities the ability of providing C2X connectivity at around 80% of their signalised intersections within three months for less than it would cost to instrument a single junction using dedicated short range communications (DSRC). In fact the company is offering to provide the equipment, known as V2If (Vehicle to Infrastructure for Free), free of charge to city authorities.
  • Calculating the cost of stellar solutions
    August 10, 2016
    The increasing availability and accuracy of global navigation satellite system (GNSS) is opening up low-cost options in many areas as David Crawford finds out. Boosting commercialisation of European global navigation satellite system (EGNSS) technologies for ITS initially depends heavily on demonstrating competitive and cost/benefit advantages obtainable from the deployment of EGNOS (the current European Geostationary Navigation Overlay Service), and ultimately the EU’s Galileo constellation (see box). So,
  • Bespoke ITS is helping to reduced collisions on America’s rural roads
    October 22, 2014
    David Crawford cherrypicks conference and award highlights Almost 30% of all US citizens live in rural areas or very small communities, and 34 of the 50 states exceed this level in their own populations, with the proportions rising as high as 85%. And although rural routes carry only 35% of all traffic, the accidents that occur on them account for some 54% of all US road traffic accident deaths.
  • US university investigates smart car tyres
    January 15, 2016
    Researchers at Virginia Tech, Penn State University, and 12 industry partners are collaborating on a US$1.2 million National Science Foundation-funded project to integrate sensors into car tyres, with the aim of providing information on the vehicle’s speed and road conditions. Saied Taheri, an associate professor of mechanical engineering in Virginia Tech’s College of Engineering and the director of the Center for Tire Research (CenTiRe), is the project’s lead investigator. Taheri has been working for