Skip to main content

Karamba’s Carwall thwarts mass hacks

Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving. Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation. David Barzilai, the company’s chairman and co-founder, said with tens of millions of l
September 13, 2016 Read time: 2 mins
8519 Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving.  

Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation.
 
David Barzilai, the company’s chairman and co-founder, said with tens of millions of lines of code in car software, it is impossible to guarantee all security bugs are eliminated. Carwall does not stop a hacker exploiting a security bug to transmit malware to a vehicle’s ECUs but it does prevent that malware being activated.

When Carwall detects foreign activity or code on an ECU it sends an alert to the manufacturer and system providers’ details on security bugs the hackers exploited, the code they attempted to run and the function it would execute. According to Barzilai, as the factory settings are definitive, Carwall does not produce false positives.

The software can be installed retrospectively to in-service vehicles by authorised distributers but cannot prevent individual hacks where the hacker can physically connect the vehicle’s CANbus architecture.

Related Content

  • February 3, 2012
    Embedded connectivity delivers real time travel information
    Ton Brand describes the GSM Association's Embedded mTelematics programme. As the world's roads become increasingly crowded, consumers and businesses are demanding better real-time information to help them both avoid traffic congestion and make smarter use of public transport. Embedding mobile connectivity directly into vehicles can enable drivers and passengers to see live traffic flows in their localities, as well as the expected arrival time of the next bus, ferry or tram
  • February 23, 2017
    Single system simplicity for smarter city transport
    All encompassing, city-wide transport monitoring and control systems are beginning to make their way onto the market, as Colin Sowman hears. The futuristic vision of cities where everything is connected and operated with maximum efficiency by a gigantic computer remains a distant prospect but related sectors and services are beginning to coalesce: transport monitoring and control for instance.
  • April 15, 2020
    StreetDrone urges more emphasis on C/AV hardware 
    A greater reliance is needed on the contribution hardware can make towards safety within autonomous vehicles (AVs), according to a report by StreetDrone.
  • February 1, 2012
    Cooperative systems and privacy not mutually exclusive
    Are co-operative systems and personal privacy mutually exclusive? Not necessarily, says Neil Hoose. But the more advanced the application, the greater the concession of privacy may have to become. ITS Stockholm in 2009 and the Cooperative Mobility Showcase event which took place alongside Intertraffic in Amsterdam in March this year both featured live, on-street demonstrations of safety and driver information applications that used Vehicle-to-Infrastructure (V2I) and Vehicle-to-Vehicle (V2V) communications,