Skip to main content

Karamba’s Carwall thwarts mass hacks

Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving. Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation. David Barzilai, the company’s chairman and co-founder, said with tens of millions of l
September 13, 2016 Read time: 2 mins
8519 Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving.  

Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation.
 
David Barzilai, the company’s chairman and co-founder, said with tens of millions of lines of code in car software, it is impossible to guarantee all security bugs are eliminated. Carwall does not stop a hacker exploiting a security bug to transmit malware to a vehicle’s ECUs but it does prevent that malware being activated.

When Carwall detects foreign activity or code on an ECU it sends an alert to the manufacturer and system providers’ details on security bugs the hackers exploited, the code they attempted to run and the function it would execute. According to Barzilai, as the factory settings are definitive, Carwall does not produce false positives.

The software can be installed retrospectively to in-service vehicles by authorised distributers but cannot prevent individual hacks where the hacker can physically connect the vehicle’s CANbus architecture.

Related Content

  • November 28, 2016
    UK must prepare for increased transport cyber-security threat, says TSC
    The UK Transport sector needs to increase its focus on cyber-security in the face of rapidly emerging technological developments, according to Transport Systems Catapult (TSC). In a new report, supported by IBM, the Institute of Engineering Technology (IET), the Intelligent Mobility Partnership (IMPART) and the Digital Catapult, the TSC cites numerous trends in the realms of technology, cyber security, mobility, and society are all converging to make it a much more complex environment in which to deliver
  • July 24, 2017
    Traffex snapshot reveals enforcement advances
    An indication of just how far beyond spot speed and red light the enforcement sector has progressed was evident in the range of new and improved equipment on display at the recent Traffex event in Birmingham. One of the key trends, particularly in the UK but also evident elsewhere, is the increase in average speed enforcement, according to RedSpeed’s managing director Robert Ryan, who predicts a big increase in installations this year. “The price point has reached a level authorities can afford,” he says, a
  • December 8, 2014
    Traffic management to the fore at Vision 2014
    Colin Sowman reviews some of the traffic-related exhibits at the 2014 Vision Show in Stuttgart. Traffic was a major theme at this years’ Vision Show in Stuttgart and several manufacturers used the exhibition to highlight their traffic-related equipment and applications.
  • February 23, 2018
    Companies depend on automation, AI and machine learning for cyber security
    To defend against cyber attacks, 39% of organisations are reliant on automation, 34% on machine learning and 32% on artificial intelligence (AI), according to the Cisco 2018 annual report conducted on 3,600 chief information security officers. It found that over half of all attacks resulted in financial damages of more than $500,000 (£697,000), including, but not limited to, lost revenue, clients, opportunities, and out-of-pocket costs. The study revealed that adversaries are using Malware sophistication