Skip to main content

Karamba’s Carwall thwarts mass hacks

Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving. Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation. David Barzilai, the company’s chairman and co-founder, said with tens of millions of l
September 13, 2016 Read time: 2 mins
8519 Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving.  

Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation.
 
David Barzilai, the company’s chairman and co-founder, said with tens of millions of lines of code in car software, it is impossible to guarantee all security bugs are eliminated. Carwall does not stop a hacker exploiting a security bug to transmit malware to a vehicle’s ECUs but it does prevent that malware being activated.

When Carwall detects foreign activity or code on an ECU it sends an alert to the manufacturer and system providers’ details on security bugs the hackers exploited, the code they attempted to run and the function it would execute. According to Barzilai, as the factory settings are definitive, Carwall does not produce false positives.

The software can be installed retrospectively to in-service vehicles by authorised distributers but cannot prevent individual hacks where the hacker can physically connect the vehicle’s CANbus architecture.

For more information on companies in this article

Related Content

  • ComNet introduces Port Guardian physical port lockout
    March 13, 2018
    US communications networking equipment manufacturer ComNet has added the Port Guardian cyber-security features to its latest generation of self-managed switches which can physically disconnect a port if unauthorised access is detected. Port Guardian covers situations where network access is attempted by disconnecting an IP addressable device connected to the network. When Port Guardian senses intrusion, a notification is sent and the effected port is physically locked out, preventing access and thwarting
  • The benefits of combining enforcement and traffic management
    February 27, 2013
    Jason Barnes considers how combining enforcement equipment with other traffic management technologies might benefit our future – if only the will were really in place to do so. During the ITS World Congress in Vienna in October last year, Navtech Radar and Vysion­ics ITS announced a strategic partnership that would combine the expertise of Navtech in millimetre-wave wide-area surveillance technology with Vysionics’ machine vision-based automatic number plate recognition (ANPR) and average speed measurement
  • Island Radar: safely crossing continents
    August 6, 2020
    There is a safety flashpoint wherever roads cross over railways. Island Radar is using well-established traffic technology to keep all parties safe from harm.
  • Kenya to introduce microchip-fitted number plates
    November 17, 2014
    Shem Oirere looks at Kenya’s plans to introduce a new generation of vehicle registration plates fitted with microchip technology by the end of this year. In a move to improve driving standards and prevent fraud, the authorities in Kenya are planning the introduction of a new numberplate system which will incorporate microchip technology.