Skip to main content

Karamba’s Carwall thwarts mass hacks

Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving. Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation. David Barzilai, the company’s chairman and co-founder, said with tens of millions of l
September 13, 2016 Read time: 2 mins
8519 Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving.  

Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation.
 
David Barzilai, the company’s chairman and co-founder, said with tens of millions of lines of code in car software, it is impossible to guarantee all security bugs are eliminated. Carwall does not stop a hacker exploiting a security bug to transmit malware to a vehicle’s ECUs but it does prevent that malware being activated.

When Carwall detects foreign activity or code on an ECU it sends an alert to the manufacturer and system providers’ details on security bugs the hackers exploited, the code they attempted to run and the function it would execute. According to Barzilai, as the factory settings are definitive, Carwall does not produce false positives.

The software can be installed retrospectively to in-service vehicles by authorised distributers but cannot prevent individual hacks where the hacker can physically connect the vehicle’s CANbus architecture.

Related Content

  • November 1, 2016
    Connected offers free I2V connectivity
    A new system could reduce the cost of implementing I2V communications across a city to less than that for a single intersection, as Colin Sowman hears. It may seem too good to be true but US company Connected Signals is offering city authorities the equipment to provide infrastructure to vehicle (I2V) communications for free. The system enables drivers to receive information about the timing of signals they are approaching via the EnLighten smartphone app (or connected in-vehicle display).
  • February 1, 2012
    Positive incentives an alternative to road user charging?
    The Netherlands has been looking at incentivising rush-hour avoidance. The intention is to better understand road users' motivations and find alternatives to congestion charging. Something significant needs to happen if we are to adequately address the traffic congestion and other issues caused by the ever-rising numbers of vehicles on our roads. Congestion or distance-based charging is seen as one way of managing demand and raising revenue for improvements to transport infrastructure. However, charging is
  • May 5, 2016
    AV/ridesharing mix wins major auto investment
    The US has a new trend in personal mobility and David Crawford takes a closer look. US automaker General Motors and ridesharer Lyft’s announcement of a strategic partnership aimed at delivering, over time, an integrated network of on-demand autonomous as well as conventional vehicles has taken the nation’s car industry from traditional manufacturing to new arenas.
  • July 17, 2012
    Cloud computing technology benefits GIS
    Geographic Information Systems are a relatively late adopter of cloud computing,but the benefits of host services for geospatial data and analysis are becoming clear. Jason Barnes reports Both the concept and the reality of cloud computing have been around for some time. More and more industry sectors are entrusting external service providers with the provision of their computing services via the internet. However, the Geographic Information System (GIS) industry has been slow to embrace the trend. This is