Skip to main content

Karamba’s Carwall thwarts mass hacks

Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving. Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation. David Barzilai, the company’s chairman and co-founder, said with tens of millions of l
September 13, 2016 Read time: 2 mins
8519 Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving.  

Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation.
 
David Barzilai, the company’s chairman and co-founder, said with tens of millions of lines of code in car software, it is impossible to guarantee all security bugs are eliminated. Carwall does not stop a hacker exploiting a security bug to transmit malware to a vehicle’s ECUs but it does prevent that malware being activated.

When Carwall detects foreign activity or code on an ECU it sends an alert to the manufacturer and system providers’ details on security bugs the hackers exploited, the code they attempted to run and the function it would execute. According to Barzilai, as the factory settings are definitive, Carwall does not produce false positives.

The software can be installed retrospectively to in-service vehicles by authorised distributers but cannot prevent individual hacks where the hacker can physically connect the vehicle’s CANbus architecture.

Related Content

  • February 26, 2016
    Nissan disables Leaf app following hacking scare
    According to news reports, Nissan has disabled its NissanConnect EV app after it was found that hackers could remotely control in-car systems. Security researcher Troy Hunt discovered the vulnerability during a software workshop he was attending and has detailed his findings on his blog. In a test with fellow researcher Scott Helme, they found they were able to remotely turn on the car's heated seating, heated steering wheel, fans and air conditioning. According to Helmes, “Fortunately, the Nissan Le
  • October 19, 2022
    Leonardo addresses new mobility trends
    Italy-headquartered Leonardo outlines why, and how, the company is at the forefront of more effective, efficient, and sustainable mobility - a top European priority - through investments in the Next Generation EU programme, aimed at achieving energy and climatic objectives.
  • February 15, 2018
    Panasonic and Trend Micro to enhance cyber security for connected cars
    Panasonic has joined forces with Trend Micro to develop solutions that protect autonomous and connected cars against cyber attacks, with the intention of launching commercially after 2020. The partnership will focus on advancing technologies that detect and prevent intrusions into Electronic Control Units (ECUs) which manage acceleration, steering and braking as well as in-vehicle infotainment devices.
  • October 31, 2018
    Less than 1% of UK drivers aware of hacking threats – new research
    Nearly all UK drivers with keyless technology are unaware of the major digital threats posed by hackers, according to research conducted by MoneySuperMarket. The study reveals that 99% of drivers are unaware of security flaws such as phone phishing, where hackers send emails to drivers which contain malicious links that connect to a car’s Wi-Fi features and take control. MoneySuperMarket says 16% of drivers - or someone they know - have experienced car hacking. Also, eight out of 10 drivers do not k