Skip to main content

Karamba’s Carwall thwarts mass hacks

Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving. Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation. David Barzilai, the company’s chairman and co-founder, said with tens of millions of l
September 13, 2016 Read time: 2 mins
8519 Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving.  

Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation.
 
David Barzilai, the company’s chairman and co-founder, said with tens of millions of lines of code in car software, it is impossible to guarantee all security bugs are eliminated. Carwall does not stop a hacker exploiting a security bug to transmit malware to a vehicle’s ECUs but it does prevent that malware being activated.

When Carwall detects foreign activity or code on an ECU it sends an alert to the manufacturer and system providers’ details on security bugs the hackers exploited, the code they attempted to run and the function it would execute. According to Barzilai, as the factory settings are definitive, Carwall does not produce false positives.

The software can be installed retrospectively to in-service vehicles by authorised distributers but cannot prevent individual hacks where the hacker can physically connect the vehicle’s CANbus architecture.

Related Content

  • March 29, 2017
    Lowering the barriers to combined control rooms
    Integrating control rooms can improve traffic management, security and emergency response without excessive cost or compromising privacy. In the wake of the recent terrorist events in France and Germany where the transport system was exploited with deadly consequences, many governments and agencies are reviewing the security arrangements – particularly around popular and high profile events. Increasing security in transport systems that must remain accessible to the general public will not be easy but in ma
  • June 7, 2017
    Technology and finance shapes up to make MaaS happen
    The technology and finance aspects needed for Mobility as a Service (MaaS) to become widely adopted are taking shape as Geoff Hadwick and Colin Sowman hear. Sampo Hietanen, CEO of MaaS Global and ‘father’ of MaaS, started his address to ITS International’s recent MaaS Market conference in London by saying: “All of the problems that can be solved by a company or group of companies have already been solved, and now we are left with the big ones such as housing, transport and health. He called MaaS the “Netfli
  • March 1, 2013
    HeERO - harmonising e-Call across Europe
    The second stage of the EC’s HeERO project, which aims to address some of the issues surrounding the eCall system, has just got underway. Jason Barnes reports. As the European Commission (EC)’s Har­monised eCall European Pilot (HeERO) project progresses into its second stage, ‘HeERO 2’, significant progress has already been made in addressing the technological and institutional issues relating to the pan-European deployment of an eCall system based around the new ‘112’ universal emergency telephone number.
  • December 14, 2012
    Car to car communications a step closer
    Vehicle manufacturers have targeted 2015 for the first cars to roll off European assembly lines fitted with operational V2X technology. They and their partners in the Car 2 Car Communications Consortium are confident of meeting the target, reports Jon Masters. Around three years from now vehicles should be appearing in showrooms boasting the capability of communicating with each other. Manufacturers will have started fitting the first proprietary car-to-car driver-aid safety devices and deployment of ‘vehic