Skip to main content

Karamba’s Carwall thwarts mass hacks

Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving. Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation. David Barzilai, the company’s chairman and co-founder, said with tens of millions of l
September 13, 2016 Read time: 2 mins
8519 Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving.  

Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation.
 
David Barzilai, the company’s chairman and co-founder, said with tens of millions of lines of code in car software, it is impossible to guarantee all security bugs are eliminated. Carwall does not stop a hacker exploiting a security bug to transmit malware to a vehicle’s ECUs but it does prevent that malware being activated.

When Carwall detects foreign activity or code on an ECU it sends an alert to the manufacturer and system providers’ details on security bugs the hackers exploited, the code they attempted to run and the function it would execute. According to Barzilai, as the factory settings are definitive, Carwall does not produce false positives.

The software can be installed retrospectively to in-service vehicles by authorised distributers but cannot prevent individual hacks where the hacker can physically connect the vehicle’s CANbus architecture.

Related Content

  • September 7, 2017
    Ricardo and Roke Manor to collaborate on next-generation vehicle cyber security
    International technology company Ricardo is to join forces with cyber security specialist Roke Manor Research to develop solutions that will make autonomous and connected transport robust against cyber attack. Many of today’s new vehicles are already connected over the air for telematics and maintenance, for safety systems such as eCall, by consumers using insurance-based monitoring technology, and by the many smartphone apps available to vehicle owners.
  • August 21, 2024
    Second senior AV moment for Contra Costa, Beep & Oxa
    California county launches another Presto pilot to transport 55+ community around
  • May 29, 2013
    Israel aspires to ITS-led future
    Shay Soffer, Chief Scientist with the Israel National Road Safety Authority, talks to Jason Barnes about his country’s current ITS outlook and how he sees this developing in the future. Israel ranks alongside countries such as the US and France in the road safety stakes, with an average 7.1 deaths per billion kilometres driven. But at that point the similarities end, as the country’s overriding issue is pedestrian safety. This is driven by several factors, including being a relatively small country where pe
  • July 4, 2012
    Tackling speed enforcement with electronic vehicle recognition
    An innovative electronic vehicle registration system is being rolled out across Bangkok in Thailand, with road safety and speed enforcement the principal aims Equipment contracts and partnerships relating to a system of electronic vehicle registration (EVR) have been forming in Bangkok over the past couple of years. EVR can be applied to tackle a broad range of problems for transport authorities, including tax evasion, crime and insurance fraud. For Thailand’s Department of Land Transport (DLT), its EVR sy