Skip to main content

Karamba’s Carwall thwarts mass hacks

Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving. Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation. David Barzilai, the company’s chairman and co-founder, said with tens of millions of l
September 13, 2016 Read time: 2 mins
8519 Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving.  

Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation.
 
David Barzilai, the company’s chairman and co-founder, said with tens of millions of lines of code in car software, it is impossible to guarantee all security bugs are eliminated. Carwall does not stop a hacker exploiting a security bug to transmit malware to a vehicle’s ECUs but it does prevent that malware being activated.

When Carwall detects foreign activity or code on an ECU it sends an alert to the manufacturer and system providers’ details on security bugs the hackers exploited, the code they attempted to run and the function it would execute. According to Barzilai, as the factory settings are definitive, Carwall does not produce false positives.

The software can be installed retrospectively to in-service vehicles by authorised distributers but cannot prevent individual hacks where the hacker can physically connect the vehicle’s CANbus architecture.

Related Content

  • February 6, 2012
    Cooperative systems and privacy not mutually exclusive
    Are co-operative systems and personal privacy mutually exclusive? Not necessarily, says Neil Hoose. But the more advanced the application, the greater the concession of privacy may have to become
  • February 25, 2015
    New legal basis brings EU wide cross border enforcement
    Pan-EU enforcement is set to become a reality after legislation is revised. In May 2014 the European Court of Justice ruled that European Directive 2011/82/EU, which came into force in November 2013 to facilitate the exchange of information between member states in relation to eight road traffic offences, had been set up on an incorrect legal basis. The regulations had been introduced under police cooperation rules on the prevention of crime, but the Court decided that the measures in the Directive do not c
  • April 23, 2025
    Huawei advocates for change
    Achieving technological change also requires a shift in mindset, as Jacky Wang, vice president of Huawei’s Smart Transportation business unit, explains
  • April 10, 2012
    Flexible, demand-based parking charges ease parking problems
    Innovative parking initiatives on the US Pacific Coast. David Crawford reviews. Californian cities are leading the way in trialling new solutions to their endemic parking problems. According to Donald Shoup, a professor of urban planning at the University of California in Los Angeles, drivers looking for available spots can cause up to 74% of traffic congestion in downtown areas. One solution is variable, demand-responsive pricing of parking.