Practical and Flexible Kernel CFI Enforcement using eBPF
Jinghao Jia, Michael V. Le, et al.
eBPF 2023
Google and Apple jointly introduced a digital contact tracing technology and an API called "exposure notification,'' to help health organizations and governments with contact tracing. The technology and its interplay with security and privacy constraints require investigation. In this study, we examine and analyze the security, privacy, and reliability of the technology with actual and typical scenarios (and expected typical adversary in mind), and quite realistic use cases. We do it in the context of Virginia's COVIDWISE app. This experimental analysis validates the properties of the system under the above conditions, a result that seems crucial for the peace of mind of the exposure notification technology adopting authorities, and may also help with the system's transparency and overall user trust.
Jinghao Jia, Michael V. Le, et al.
eBPF 2023
Poulami Das, Julia Hesse, et al.
ASIA CCS 2022
Michael V. Le, Salman Ahmed, et al.
ASIA CCS 2023
Pau-Chen Cheng, Wojciech Ozga, et al.
ACM Computing Surveys