Skip to main content

Karamba’s Carwall thwarts mass hacks

Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving. Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation. David Barzilai, the company’s chairman and co-founder, said with tens of millions of l
September 13, 2016 Read time: 2 mins
8519 Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving.  

Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation.
 
David Barzilai, the company’s chairman and co-founder, said with tens of millions of lines of code in car software, it is impossible to guarantee all security bugs are eliminated. Carwall does not stop a hacker exploiting a security bug to transmit malware to a vehicle’s ECUs but it does prevent that malware being activated.

When Carwall detects foreign activity or code on an ECU it sends an alert to the manufacturer and system providers’ details on security bugs the hackers exploited, the code they attempted to run and the function it would execute. According to Barzilai, as the factory settings are definitive, Carwall does not produce false positives.

The software can be installed retrospectively to in-service vehicles by authorised distributers but cannot prevent individual hacks where the hacker can physically connect the vehicle’s CANbus architecture.

Related Content

  • February 23, 2021
    CVs vulnerable to ‘low skill’ cyberattacks: report
    17% of potential attack scenarios on connected vehicles identified as high-risk, finds Trend Micro 
  • December 5, 2013
    Vehicle manufacturers and local authorities seek satnav solutions
    The increasing capability of satellite navigation is helping vehicle manufacturers and local authorities as well as individual drivers and fleets. In comparison to the physical ITS infrastructure in towns and cities and on motorways and highways, satellite navigation (satnav) systems have come a long way in a short time. Many (if not the majority) individual drivers and fleets use or have access to a satnav and now the vehicle manufacturers and even local authorities are beginning to utilise satnav derived
  • July 20, 2023
    Demand-responsive transport keeps things flexible
    Mobility needs change: Elena Ziller of OpenMove explains why demand-responsive transport is emerging as a hot mobility trend – and why it’s not without challenges
  • March 5, 2018
    Arilou develops central management hub for automotive ethernet
    Arilou Information Security Technologies (Arilou) has released central management technology with the intention of enabling dynamic and secure control of in-vehicle communication networks for connected and autonomous vehicles equipped with Ethernet networks. The supplier of cyber security solutions aims to set a standard for Ethernet integration as well as provide security for connected cars of the future. Called the Ethernet Security Hub, the tool aims to allow complete, real-time management of the