Skip to main content

Karamba’s Carwall thwarts mass hacks

Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving. Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation. David Barzilai, the company’s chairman and co-founder, said with tens of millions of l
September 13, 2016 Read time: 2 mins
8519 Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving.  

Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation.
 
David Barzilai, the company’s chairman and co-founder, said with tens of millions of lines of code in car software, it is impossible to guarantee all security bugs are eliminated. Carwall does not stop a hacker exploiting a security bug to transmit malware to a vehicle’s ECUs but it does prevent that malware being activated.

When Carwall detects foreign activity or code on an ECU it sends an alert to the manufacturer and system providers’ details on security bugs the hackers exploited, the code they attempted to run and the function it would execute. According to Barzilai, as the factory settings are definitive, Carwall does not produce false positives.

The software can be installed retrospectively to in-service vehicles by authorised distributers but cannot prevent individual hacks where the hacker can physically connect the vehicle’s CANbus architecture.

Related Content

  • January 19, 2012
    ITS industry needs more effort to get to the future
    Eric Sampson, visiting professor at Newcastle University and City University London and ambassador for ITS-UK, provides a retrospective on the last couple of decades and takes a look at what the ITS industry still needs to do to get to where it needs to be
  • April 20, 2017
    Increased automation is already improving road safety
    Richard Cuerden considers how many of the technologies developed as part of a move toward autonomous vehicles are already being deployed as ADAS improve road safety. The drive to create autonomous vehicles has caused a re-evaluation of what is needed to safely navigate today’s roads and the development of systems that can replace the driver in many scenarios. However, many manufacturers are not waiting for ‘tomorrow’ and are already incorporating these systems in their new cars as Advanced Driver Assistanc
  • December 21, 2017
    Communications hold key to expanding ITS wireless network expansion
    Wireless transmission of data and control information is making smarter traffic management easier and cheaper to install. It has long been known that connectivity is the key to improving traffic management and many cost-benefit studies prove that investment in new technology can be justified in terms of reduced congestion, shorter travel times, improved safety and air quality. However, many authorities’ cap-ex budgets only cover urgent matters, not improvements, making it difficult, if not impossible to
  • January 26, 2018
    Jenoptik uses sensor fusion to avoid monitoring confusion
    Jenoptik’s Uwe Urban looks at the advantages of ‘sensor fusion’ for the ITS sector. When considering the ideal sensing and monitoring system to enable the ITS sector to deliver improvements in mobility and road safety, for general policing security and border protection, we have to think beyond radar-base systems or laser scanners. What is needed today are solutions for detecting and tracking vehicles while recording evidence to deacide if any action is necessary. There is no sole sensor capable of