Skip to main content

Karamba’s Carwall thwarts mass hacks

Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving. Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation. David Barzilai, the company’s chairman and co-founder, said with tens of millions of l
September 13, 2016 Read time: 2 mins
8519 Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving.  

Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation.
 
David Barzilai, the company’s chairman and co-founder, said with tens of millions of lines of code in car software, it is impossible to guarantee all security bugs are eliminated. Carwall does not stop a hacker exploiting a security bug to transmit malware to a vehicle’s ECUs but it does prevent that malware being activated.

When Carwall detects foreign activity or code on an ECU it sends an alert to the manufacturer and system providers’ details on security bugs the hackers exploited, the code they attempted to run and the function it would execute. According to Barzilai, as the factory settings are definitive, Carwall does not produce false positives.

The software can be installed retrospectively to in-service vehicles by authorised distributers but cannot prevent individual hacks where the hacker can physically connect the vehicle’s CANbus architecture.

Related Content

  • June 27, 2025
    With C-ITS we can get ourselves connected
    Workzones need to be safer for drivers and workers – and the technology exists to harmonise safety with mobility needs, says Swarco’s Daniel Lenczowski
  • April 10, 2014
    Cellint measures speed and travel time without roadside infrastructure
    Collecting speed and travel time data without using roadside infrastructure could offer new possibilities to cash-strapped road authorities. Streaming video may be useful for traffic controllers to monitor incidents and automatic number plate recognition may be required for enforcement, but neither are necessary for many ITS functions. For instance travel times, tailbacks, percentage of vehicles turning, origin and destination analysis can all be done using Bluetooth and/or WI-Fi sensors and without video o
  • October 10, 2018
    Just Zip it! Lindsay takes to the road
    Greater vehicle connectivity is going to have huge implications for traffic management. David Arminas climbed aboard a Lindsay Road Zipper to see what this might mean in future As vice president of barrier specialist QMB Canada, Marc-Andre Seguin is sanguine about the future for moveable barriers. On the one hand, it looks good. The oft-stated advantage of moveable barriers is that the systems are cheaper to install than adding a lane or two to a highway or bridge. Directional changes to lanes can boost
  • January 9, 2014
    Audi and TTTech partner on key-enabling technologies for the piloted car
    Auto manufacturer Audi has partnered with TTech, Austrian network solutions provider, to introduce key-enabling technologies for the piloted car, which the companies say will result in a highly integrated platform ECU named zFAS, which is based on a complex multicore network, hosting sophisticated sensor fusion and a variety of innovative functions such as piloted parking or driving. "Our goal is leadership in piloted parking and piloted driving. For this purpose TTTech and Audi are developing a highly a