Skip to main content

Karamba’s Carwall thwarts mass hacks

Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving. Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation. David Barzilai, the company’s chairman and co-founder, said with tens of millions of l
September 13, 2016 Read time: 2 mins
8519 Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving.  

Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation.
 
David Barzilai, the company’s chairman and co-founder, said with tens of millions of lines of code in car software, it is impossible to guarantee all security bugs are eliminated. Carwall does not stop a hacker exploiting a security bug to transmit malware to a vehicle’s ECUs but it does prevent that malware being activated.

When Carwall detects foreign activity or code on an ECU it sends an alert to the manufacturer and system providers’ details on security bugs the hackers exploited, the code they attempted to run and the function it would execute. According to Barzilai, as the factory settings are definitive, Carwall does not produce false positives.

The software can be installed retrospectively to in-service vehicles by authorised distributers but cannot prevent individual hacks where the hacker can physically connect the vehicle’s CANbus architecture.

Related Content

  • July 31, 2012
    Dubai metro - the world's longest automated rail system
    David Crawford reviews the recent opening of Dubai's Red Line. The US$7.6bn Dubai Metro, the Phase I Red Line of which started partial operation in September 2009, will be the world's longest driverless rail system on its planned completion in 2011. With a total length of some 75km, it will then overtake the 68.7km Vancouver SkyTrain and be able to carry over 1.2 million passengers on a typical day.
  • March 28, 2018
    US DOTs introduce measures to stop wrong-way driving
    Wrong-way driving (WWD) is a remarkably innocuous term for incidents that all too often cause some of the worst accidents that emergency services have to deal with. Several US states are now taking steps to minimise the problem, as Alan Dron finds out. You’re driving down a highway at night when you see approaching headlights. You initially assume they are merely those of an oncoming car on the opposite carriageway. It’s only when they are within 200 yards or so that you realise that the other driver is in
  • September 14, 2022
    OPINION: ITS must be included in EU Green Deal
    To reach the objectives of the European Green Deal, a classification system has been developed to identify environmentally-sustainable activities. However, Richard Lax of Kapsch TrafficCom is worried that it might not have the intended effect – and ITS could lose out as a result…
  • November 2, 2016
    Ertico coordinates big data debate
    David Crawford finds that agreeing a common data standard for auto manufacturers’ onboard sensors, navigation system companies and map makers is proving a complex task.