Skip to main content

Karamba’s Carwall thwarts mass hacks

Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving. Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation. David Barzilai, the company’s chairman and co-founder, said with tens of millions of l
September 13, 2016 Read time: 2 mins
8519 Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving.  

Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation.
 
David Barzilai, the company’s chairman and co-founder, said with tens of millions of lines of code in car software, it is impossible to guarantee all security bugs are eliminated. Carwall does not stop a hacker exploiting a security bug to transmit malware to a vehicle’s ECUs but it does prevent that malware being activated.

When Carwall detects foreign activity or code on an ECU it sends an alert to the manufacturer and system providers’ details on security bugs the hackers exploited, the code they attempted to run and the function it would execute. According to Barzilai, as the factory settings are definitive, Carwall does not produce false positives.

The software can be installed retrospectively to in-service vehicles by authorised distributers but cannot prevent individual hacks where the hacker can physically connect the vehicle’s CANbus architecture.

Related Content

  • November 21, 2013
    Autonomous vehicles, the pros and cons
    Driver interface and human factors could provide the biggest obstacles to autonomous vehicles as Jon Masters discovers.
  • January 22, 2019
    Access and Irdeto partner to protect in-car data and services
    Security specialist Irdeto has teamed up with Access Co to develop protection for the increasing amount of personal data that is generated by Wi-Fi, Bluetooth and Vehicle to Everything (V2X) communication. As cars are increasingly turned into open environments due to advances in connectivity, the threat of data theft has risen. Niels Haverkorn, general manager of connected transport at Irdeto, says: “We are partnering with Access to create a complete and secure ecosystem, which means that V2X communicatio
  • September 25, 2019
    BlackBerry’s Jeff Davis: ‘Hands off 5.9GHz!’
    As a US Marine, BlackBerry’s Jeff Davis saw the world’s trouble spots. But much of his attention is now focused on what he sees as the ITS sector’s biggest issue: cybersecurity. Adam Hill finds out more Oh, I often feel I’m the dumbest guy in the room,” laughs Jeff Davis, senior director, connected transportation, at BlackBerry. It’s hard to credit this. Davis has a range of experience that sets him apart from most people in the ITS sector. He was in the US Marine Corps, with seven tours of duty, inclu
  • November 7, 2014
    Electric car value chain overturned
    The market for hybrid and pure electric cars homologated as such is set to be US$188 billion in 2025 according to IDTechEx analysis. However, according to Dr Peter Harrop, chairman of IDTechEx, the world has changed for cars overall and now big is not always beautiful for mainstream car manufacture. EVs will reflect this. Although Sergio Marchionne, boss of Fiat Chrysler, famously said six million units a year is needed for a car maker to be profitable, his head of research Pietro Perlo left to successf