Skip to main content

Karamba’s Carwall thwarts mass hacks

Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving. Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation. David Barzilai, the company’s chairman and co-founder, said with tens of millions of l
September 13, 2016 Read time: 2 mins
8519 Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving.  

Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation.
 
David Barzilai, the company’s chairman and co-founder, said with tens of millions of lines of code in car software, it is impossible to guarantee all security bugs are eliminated. Carwall does not stop a hacker exploiting a security bug to transmit malware to a vehicle’s ECUs but it does prevent that malware being activated.

When Carwall detects foreign activity or code on an ECU it sends an alert to the manufacturer and system providers’ details on security bugs the hackers exploited, the code they attempted to run and the function it would execute. According to Barzilai, as the factory settings are definitive, Carwall does not produce false positives.

The software can be installed retrospectively to in-service vehicles by authorised distributers but cannot prevent individual hacks where the hacker can physically connect the vehicle’s CANbus architecture.

For more information on companies in this article

Related Content

  • Wi-SUN: here’s why mesh networking works
    May 10, 2019
    There are several networking options available for smart city planners. Phil Beecher of Wi-SUN Alliance makes the case for wireless mesh networks when it comes to rolling out IoT solutions The Internet of Things (IoT) is growing fast. Connecting thousands of sensors and control systems in bi-directional networks is paving the way for a new generation of smart city and transport infrastructures. For many of these applications, wireless connectivity is essential where cable installation is not practical.
  • Drivers’ union calls on TfL to reconsider preliminary proposals on cab regulations
    February 24, 2016
    GMB, the union for professional drivers, is calling on Transport for London to reconsider some proposals that it put forward as preliminary indications as to how it wishes to proceed on the regulation of cab drivers, which it says waters down protection for passengers and drivers. It claims that mandatory Disclosure and Barring Service (DMS) checks for support staff have been watered down so that they do not apply to office-based staff. GMB consider that operators will be able to substitute office based
  • UK city council deploys fully hosted civil enforcement platform
    September 24, 2015
    Portsmouth City Council in the UK has awarded Videalert a contract to deploy its hosted civil enforcement platform that does not require any hardware or software to be installed on customer premises. The Department for Transport (DfT) Manufacturer Certified hosted solution will enable the council to rapidly introduce unattended enforcement at a number of bus lane locations in the city to reduce the high incidence of contraventions currently committed by motorists and enable the provision of an even bette
  • Cybersecurity isn't infrastructure? Like hell it isn't
    December 9, 2021
    This recent quote by the Mayor LaToya Cantrell of New Orleans is instructive. The transportation industry has made significant strides in awareness of the cyber vulnerabilities of traffic systems. Despite these improvements, we’ve yet to see the majority of DOTs take sufficient cybersecurity actions.