Skip to main content

Karamba’s Carwall thwarts mass hacks

Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving. Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation. David Barzilai, the company’s chairman and co-founder, said with tens of millions of l
September 13, 2016 Read time: 2 mins
8519 Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving.  

Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation.
 
David Barzilai, the company’s chairman and co-founder, said with tens of millions of lines of code in car software, it is impossible to guarantee all security bugs are eliminated. Carwall does not stop a hacker exploiting a security bug to transmit malware to a vehicle’s ECUs but it does prevent that malware being activated.

When Carwall detects foreign activity or code on an ECU it sends an alert to the manufacturer and system providers’ details on security bugs the hackers exploited, the code they attempted to run and the function it would execute. According to Barzilai, as the factory settings are definitive, Carwall does not produce false positives.

The software can be installed retrospectively to in-service vehicles by authorised distributers but cannot prevent individual hacks where the hacker can physically connect the vehicle’s CANbus architecture.

For more information on companies in this article

Related Content

  • USDoT looks at the costs and potential benefits of connected vehicles
    October 26, 2017
    David Crawford looks at latest lessons learned from the trials of connected vehicles in the US. The progress of connected vehicle (CV) technologies takes centre stage among the hot topics highlighted in the September 2017 edition – the first since 2014 – of the ‘ITS Benefits, Costs and Lessons Learned’ survey from the US ITS Joint Program Office (JPO). The organisation is an arm of the US Department of Transportation (USDoT).
  • Legalities of in-vehicle systems and cooperative infrastructures
    February 1, 2012
    Paul Laurenza of Dykema Gossett PLLC discusses the paths which lawmakers may go down on the route to making in-vehicle systems and cooperative infrastructures a reality. The question of whether or not to mandate in-vehicle systems for safety and other applications is a vexed one. There is a presumption on some parts that going down the road of forcing systems' fitment is somehow too domineering or restricting. Others would argue that it is the only realistic way of ensuring that systems achieve widespread d
  • WheelRight displays proven tyre condition system
    April 5, 2016
    Under-inflated tyres are a widespread, global issue that impact road and driver safety. Indeed, across Europe alone, under-inflated tyres contribute to 9% of all fatal road accidents and 41% of serious injury road accidents, according to EU data.
  • Connected vehicle technology the solution to safety?
    January 25, 2012
    A series of 'driver clinics' is under way across five states, as vehicle manufacturers and the US Government pin their hopes on connected vehicles becoming the next big advance in road safety. Pete Goldin reports. What would a car say if it could talk? Its first words might be: "Here I am". Many vehicles are communicating that very message to each other right now. Admittedly, this is in controlled environments of US Department of Transportation (USDoT) tests, but within the next few years 'connected vehicle