Skip to main content

Karamba’s Carwall thwarts mass hacks

Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving. Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation. David Barzilai, the company’s chairman and co-founder, said with tens of millions of l
September 13, 2016 Read time: 2 mins
8519 Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving.  

Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation.
 
David Barzilai, the company’s chairman and co-founder, said with tens of millions of lines of code in car software, it is impossible to guarantee all security bugs are eliminated. Carwall does not stop a hacker exploiting a security bug to transmit malware to a vehicle’s ECUs but it does prevent that malware being activated.

When Carwall detects foreign activity or code on an ECU it sends an alert to the manufacturer and system providers’ details on security bugs the hackers exploited, the code they attempted to run and the function it would execute. According to Barzilai, as the factory settings are definitive, Carwall does not produce false positives.

The software can be installed retrospectively to in-service vehicles by authorised distributers but cannot prevent individual hacks where the hacker can physically connect the vehicle’s CANbus architecture.

Related Content

  • December 22, 2023
    Asecap Days 2023: Data drives the best decisions
    Almost all the data being collected by highway operators is going to waste. But if firms collect and analyse these ‘vast lakes of data’ they can investigate threats, monitor management systems and drive up revenues, delegates were told at Asecap Days 2023. Geoff Hadwick reports
  • October 23, 2018
    Addison Lee and Oxbotica to implement AV services in London by 2021
    Addison Lee has partnered with self-driving vehicle software company Oxbotica in a bid to bring autonomous ride-sharing services to London by 2021. Addison Lee, a UK private taxi hire firm, says it will also explore opportunities to provide corporate shuttles, airport and campus-based services. Andy Boland, CEO of Addison Lee, says: “By providing ride-sharing services, we can help address congestion, free space used for parking and improve urban air quality through zero-emission vehicles.” The partners
  • May 15, 2017
    University research shows a few self-driving cars can improve traffic flow
    The presence of just a few autonomous vehicles can eliminate the stop-and-go driving of the human drivers in traffic, along with the accident risk and fuel inefficiency it causes, according to new research by the University of Illinois at Urbana-Champaign. Funded by the National Science Foundation’s Cyber-Physical Systems program, the research was led by a multi-disciplinary team of researchers with expertise in traffic flow theory, control theory, robotics, cyber-physical systems, and transportation engine
  • January 5, 2016
    Will mobile apps kick-start mobility pricing?
    Thomas Hallauer from Ptolemus believes trials of connected road charging services will show the pay per mile concept will go much further than previously thought. Drivers are progressively becoming directly connected to the transport infrastructure and while the methods are changing, the innovation is really in the models rather than the technology.