Skip to main content

Karamba’s Carwall thwarts mass hacks

Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving. Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation. David Barzilai, the company’s chairman and co-founder, said with tens of millions of l
September 13, 2016 Read time: 2 mins
8519 Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving.  

Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation.
 
David Barzilai, the company’s chairman and co-founder, said with tens of millions of lines of code in car software, it is impossible to guarantee all security bugs are eliminated. Carwall does not stop a hacker exploiting a security bug to transmit malware to a vehicle’s ECUs but it does prevent that malware being activated.

When Carwall detects foreign activity or code on an ECU it sends an alert to the manufacturer and system providers’ details on security bugs the hackers exploited, the code they attempted to run and the function it would execute. According to Barzilai, as the factory settings are definitive, Carwall does not produce false positives.

The software can be installed retrospectively to in-service vehicles by authorised distributers but cannot prevent individual hacks where the hacker can physically connect the vehicle’s CANbus architecture.

For more information on companies in this article

Related Content

  • ITS America publishes connected vehicle guidance
    April 22, 2015
    Guidance on the likely impact of multipath communications on connected vehicle development has been published by ITS America. ITS America’s Connected Vehicle Technical Insight looks at the challenges and opportunities wireless interoperability could provide in vehicle applications. In particular the 22-page document examines the processes by which data can be transferred from one vehicle to another (V2V), or between a vehicle and the infrastructure (V2I).
  • Continental developing road departure protection systems
    June 25, 2015
    International automotive supplier Continental is working on new road departure protection systems that aim to eliminate unintended road departures, which currently are not completely covered by today’s lateral guidance advanced driver assistance systems (ADAS), preventing fatal accidents from occurring on highways and rural roads. According to the US Department of Transportation Federal Highway Administration, approximately 55 per cent of traffic fatalities in the US involve a vehicle crossing the roadwa
  • Aimsun assesses Spain V2X impact
    June 21, 2022
    An Aimsun project with C-Roads Spain to assess the impact of Day 1 V2X services has been completed: Aimsun senior transportation modeller Laura Torres explains some of the results
  • MaaS is at the ‘baby steps’ stage – but needs to get up and running soon
    April 16, 2018
    Data sharing between organisations remains a potential problem for Mobility as a Service projects, attendees at February's MaaS Market conference in London were told. Alan Dron listens in on the presentations.