PhD "Tackle Android vulnerabilities through the integration of eBPF” F/M

il y a 1 mois


Châtillon, France Orange Business Services Temps plein

about the role

Your role is to conduct a thesis on tackling Android vulnerabilities through the integration of eBPF.

Global Context and Problem Statement

Android is the world's most widely used operating system (OS), accounting for over 40% of the market share. This makes it a prime target for cybercriminals who exploit vulnerabilities for data theft, espionage, and device takeover. As a popular OS, Android users may exhibit problematic behaviours and use outdated versions. Additionally, even when adhering to all security recommendations, devices can still be targeted by insidious zero-day zero-click attacks. Therefore, it is essential to detect and mitigate the exploitation of these vulnerabilities.

However, monitoring the dual aspect of the Android system is complex. Indeed, Android applications consist of both high-level bytecode (Dalvik bytecode) and low-level machine code (C/C++/assembly). Attacks can occur "in both worlds" and thus evade existing system-level monitoring technologies.

Scientific Objective, Results, and Challenges

The objective of this PhD is to bridge the gap between these different parts by focusing on the Android virtual machine interface (DVM/ART). The proposed approach involves using eBPF (extended Berkeley Packet Filter), a proven technology for dynamic program loading that has been successful on Linux. It enables the creation of universal rules that can execute on any eBPF-compatible system and are triggered by predefined events (hooks).

The PhD is structured into three main parts: integration, detection, and security policy management. The first step is to integrate eBPF technology into the core of Android by identifying key events to monitor and adapting eBPF instructions to enhance, for example, information reporting to system agents. This integration will enable the use of this new system to actively detect attempts to exploit vulnerabilities through specific detection rules, thereby demonstrating the effectiveness of the approach. The final step involves deploying a security policy management architecture, enabling the distribution and installation of these eBPF rules across a range of Android devices, to make the solution fully operational and also enable specialization for distinct user profiles.

about you

Scientific and technical skills:

Proficiency in programming languages such as C/C++, Java or Kotlin, and familiarity with reading assembly code. Understanding of the principles of operating systems and virtual machines, including virtual memory, scheduling, synchronization, allocation, garbage collection, and Just-In-Time Compiler. Proficiency in both French and English. Interest in cybersecurity.

The ideal candidate for this doctoral position should demonstrate intellectual curiosity, autonomy, scientific rigour, analytical and synthesis skills, excellent writing and communication abilities (in French and English for scientific articles, internal reports, and presentations), and a cooperative mindset.

Expected Profile: Candidates who have obtained or are in the process of obtaining a Master's degree, Research Master's degree, engineering degree (diplôme d’ingénieur), or equivalent in Computer Science/Engineering, ideally with a specialization in systems, embedded systems, or cybersecurity.

additional information

The skills acquired during this thesis are directly relevant to cutting-edge technologies that are in high demand in the cybersecurity sector. The solutions developed aim to apply research findings practically and have the potential to be integrated into widely used real-world systems that address industry-specific needs. The PhD will provide opportunities to participate in national and international conferences in the field of security and systems. This will not only allow for the presentation of your own results but also provide the chance to attend advanced presentations and network with other researchers in the field. The obtained results can also be shared internally at Orange and in academic forums, thereby strengthening the collaboration between academic and industry experts.

department

Orange Innovation brings together the research and innovation activities and expertise of the Group's entities and countries. We work every day to ensure that Orange is recognized as an innovative operator by its customers and we create value for the Group and the Brand in each of our projects. With 720 researchers, thousands of marketers, developers, designers and data analysts, it is the expertise of our 6,000 employees that fuels this ambition every day.

Orange Innovation anticipates technological breakthroughs and supports the Group's countries and entities in making the best technological choices to meet the needs of our consumer and business customers.

Within the Orange Innovation Division, you will be part of the Data Privacy Innovation (DPI) team, which brings together researchers and specialized engineers in cybersecurity, virtualization security, cryptography, and personal data protection. You will benefit from an innovative ecosystem that allows for the practical implementation of the studied concepts. The DPI team is located in Caen, Rennes, and Châtillon.

contract

Thesis



  • Châtillon, France Orange Business Services Temps plein

    about the role The Linux kernel offers a privileged observation position that allows to collect data related to running applications and their underlying infrastructure. The kernel also offers an ideal observation point for both network and system activities that any application running within a telecom platform can have. The eBPF (extended Berkeley...


  • Châtillon, France Orange Business Services Temps plein

    about the role Your role is to carry out a PhD on "Mathematical modeling of circular economy, applied to mobile lifecycle" Global context and problem of the subject Reconditioning and recycling are drivers of ecological transition and new economic models. Recent regulatory changes encourage actors, including Orange, to increase the proportion of...


  • Châtillon, France Orange Business Services Temps plein

    about the role Your role is to work on a PhD entitled “Resource optimization in satellite-integrated networks”  Global context and problematic of the subject The extension of coverage with terrestrial networks (TN) is both an economic and technological obstacle. On the other hand, non-terrestrial networks (NTNs) have the capacity to provide...


  • Châtillon, France Orange Business Services Temps plein

    about the role Overall context and problem of the subject Your role is to carry out a PhD on AI-based "demand-response" strategies for a prosumer energy operator in the context of the energy and ecological transition: electrification, proliferation of renewable energies, storage optimisation and energy flexibility. The latter can be achieved in...


  • Châtillon, France Orange Business Services Temps plein

    about the role Your role is to conduct a thesis on "A study of post-quantum public key schemes." Global context and problem statement: It is anticipated that within 5 to 15 years, efficient quantum processors will emerge, posing a threat to the security of public key signature schemes based on large number factorization and discrete logarithm...


  • Châtillon, France Orange Business Services Temps plein

    about the role Your role is to carry out a Post doc work “to evaluate emerging heterogenous compute and hardware acceleration solutions through a case study focusing on disaggregated Radio Access Networks” attached to the WP1 of the European IPCEI-ME/CT (OpenRAN Lab & Testing Platform). Global context and problematic of the subject: In the...


  • Châtillon, France Orange Business Services Temps plein

    about the role Your role is to carry out a PhD on “a game-theoretic approach to efficient and sustainable cloud computing”. Context and problem Human societies and technologies must evolve under the pressure of various factors such as natural resources depletion, limited availability of energy or the growth of the population and its needs...


  • Châtillon, France Orange Business Services Temps plein

    about the role  Your role is to perform PhD work on the topic: " Energy Saving for Intent Based Management " Global context and problematic of the subject: Thanks to digitalization in the industry and society, new markets will open for business services or more generally for what are called verticals (vehicles, health, etc.). The ability to...

  • Post Doc

    il y a 1 mois


    Châtillon, France Orange Business Services Temps plein

    about the role You rôle is to work on the subject : " Implementation of a secure observability solution for cloud-native network functions, capable of effectively detecting threats. " Global context and problematic The deployment of 5G on cloud-native infrastructures introduces additional constraints on the virtualization layer and more...


  • Châtillon, France Orange Business Services Temps plein

    about the role As a PhD student, you will work on a PhD thesis on the subject of: " Securing Federated Learning by Unlearning ". Motivations and Context Cybersecurity has become a major issue in an increasingly digital world. Indeed, cyberattacks are multiplying against both organizations and individuals. These attacks are increasingly...


  • Châtillon, France Siemens Industry Software SAS Temps plein

    **Le manager de ce poste étant aux US, merci de soumettre votre candidature en Anglais.** As a Senior Software Engineer, you will be responsible for designing, developing, and debugging specific geometric modeling features with new algorithms, quite often outside the realm of Parasolid API with a focus on geometry preparation tools for CAE applications. The...


  • Châtillon, France Orange Business Services Temps plein

    about the role The next generation of mobile networks should enable the seamless operation of Industrial IoT systems, while reducing energy consumption. In this context, ultra-reliable low latency communications (URLLC) are a key enabler for these applications that simultaneously require strict constraints in terms of low latency, a high level of...

  • PhD "Hybrid Quantum

    il y a 1 mois


    Châtillon, France Orange Business Services Temps plein

    about the role Global context and problematic of the subject Quantum optimization, particularly quantum operations research, is attracting increasing interest due to recent improvements in the capabilities of quantum computers. Both the academic world (LIMOS, LIST3N, LIRMM, etc.), and the industrial world (EDF, ERICSON, TotalEnergy, etc.) are...


  • Châtillon, France Orange Business Services Temps plein

    about the role Your role is to carry out a PhD thesis work on “Energy savings with Machine Learning for 6G MIMO”.  We are witnessing a craze, particularly among telecom equipment manufacturers, in the use of Machine Learning (ML, AI techniques) to design mobile communications systems. In order to be able to compare the solutions best suited to...


  • Châtillon, France Orange Business Services Temps plein

    about the role Global context and problematic of the subject • Wholesale roaming allows subscribers of a mobile network operator to continue to access their services (voice, SMS, data) when they travel abroad, using the resources from a local operator in the country they are visiting. This gives rise to a remuneration of this local operator by...


  • Châtillon, France Orange Business Services Temps plein

    about the role The MobiTIC project, which brings together INSEE, Gustave Eiffel University and Orange, aims to produce indicators of people's presence and mobility by combining digital and traditional data. These indicators, produced at fine spatial and temporal resolutions, will inform the decisions of local players in the interests of sustainable...


  • Châtillon, France Orange Business Services Temps plein

    about the role Your role is to carry out dissertation work on: "MAC/PHY optimization in next generation wireless networks for environmentally sustainable design". Environmental impact is becoming an increasingly important consideration in the evolution of mobile phone network standards. For example, the 3GPP standardisation group is currently...


  • Châtillon, France Orange Business Services Temps plein

    about the role Your role is to carry out Post doc work on: "Dynamic MIMO beamforming to control time-averaged EMFE in RIS-aided cellular networks" which will be attached to the SNS Hexa-X-II and BPI Intention-6G projects. Several innovative features (, THz band, metasurfaces, AI) were introduced as new enablers for future cellular networks; these...

  • Production Planner

    il y a 2 jours


    Châtillon-sur-Chalaronne, Bourg-en-Bresse, France MSA - The Safety Company Temps plein

    Are you someone who is passionate, motivated, and driven to make a difference?If so, MSA Safety is the perfect fit for your career. At MSA, SAFETY is who we are AND it is what we do. We are a purpose-driven company committed to deploying innovation and technology to deliver on our Mission to help protect people and assets all around the world. We continue...

  • Production Planner

    il y a 1 jour


    Châtillon-sur-Chalaronne, France MSA - The Safety Company Temps plein

    Are you someone who is passionate, motivated, and driven to make a difference?If so, MSA Safety is the perfect fit for your career. At MSA, SAFETY is who we are AND it is what we do. We are a purpose-driven company committed to deploying innovation and technology to deliver on our Mission to help protect people and assets all around the world. We continue...