Award Abstract # 1319019
CSR: Small: Towards Confederated Web-Based Services

NSF Org: CNS
Division Of Computer and Network Systems
Recipient: NORTHEASTERN UNIVERSITY
Initial Amendment Date: July 10, 2013
Latest Amendment Date: July 10, 2013
Award Number: 1319019
Award Instrument: Standard Grant
Program Manager: Marilyn McClure
mmcclure@nsf.gov
 (703)292-5197
CNS
 Division Of Computer and Network Systems
CSE
 Directorate for Computer and Information Science and Engineering
Start Date: September 1, 2013
End Date: August 31, 2016 (Estimated)
Total Intended Award Amount: $498,783.00
Total Awarded Amount to Date: $498,783.00
Funds Obligated to Date: FY 2013 = $498,783.00
History of Investigator:
  • Alan Mislove (Principal Investigator)
    amislove@ccs.neu.edu
  • Christopher Wilson (Co-Principal Investigator)
Recipient Sponsored Research Office: Northeastern University
360 HUNTINGTON AVE
BOSTON
MA  US  02115-5005
(617)373-5600
Sponsor Congressional District: 07
Primary Place of Performance: Northeastern University
360 Huntington Ave
Boston
MA  US  02115-5005
Primary Place of Performance
Congressional District:
07
Unique Entity Identifier (UEI): HLTMVS2JZBS6
Parent UEI:
NSF Program(s): CSR-Computer Systems Research
Primary Program Source: 01001314DB NSF RESEARCH & RELATED ACTIVIT
Program Reference Code(s): 7923
Program Element Code(s): 735400
Award Agency Code: 4900
Fund Agency Code: 4900
Assistance Listing Number(s): 47.070

ABSTRACT

Users today have access to a broad range of free, web-based social services. All of these services operate under a similar model: Users entrust the service provider with their personal information and content, and in return, the service provider makes their service available for free by monetizing the user-provided information and selling the results to third parties (e.g., advertisers). In essence, users pay for these services by providing their data (i.e., giving up their privacy) to the provider.

This project is using cloud computing to re-architect web-based services in order to enable end users to regain privacy and control over their data. In this approach---a confederated architecture---each user provides the computing resources necessary to support her use of the service via cloud providers. All user data is encrypted and not exposed to any third-parties, users retain control over their information, and users access the service via a web browser as normal.

The incredible popularity of today's web-based services has lead to significant concerns over privacy and user control over data. Addressing these concerns requires a re-thinking of the current popular web-based business models, and, unfortunately, existing providers are dis-incentivized from doing so. The impact of this project will potentially be felt by the millions of users who use today's popular services, who will be provided with an alternative to the business models of today.

PROJECT OUTCOMES REPORT

Disclaimer

This Project Outcomes Report for the General Public is displayed verbatim as submitted by the Principal Investigator (PI) for this award. Any opinions, findings, and conclusions or recommendations expressed in this Report are those of the PI and do not necessarily reflect the views of the National Science Foundation; NSF has not approved or endorsed its content.

Users today have access to a broad range of free, web-based social services. All of these services operate under a similar model:  Users entrust the service provider with their personal information and content, and in return, the service provider makes their service available for free by monetizing the user-provided information and selling the results to third parties (e.g., advertisers).  In essence, users pay for these services by providing their data (i.e., giving up their privacy) to the provider.

This project explored techniques to use cloud computing to re-architect web-based services, allowing end users to regain privacy and control over their data.  In this approach--a confederated architecture--each user provides the computing resources necessary to support her use of the service via cloud providers.  All user data is encrypted and not exposed to any third-parties, users retain control over their information, and users access the service via a web browser as normal.

Intellectual Merit:

The first major component of this project was the development of the Priv.io service.  We developed techniques that allow a service similar to today's online social networks to be implemented in a manner where each user stores their content on a storage provider of their choice (e.g., Amazon's S3, Dropbox, etc).  All content is encrypted, and priv.io works with unmodified web browsers on both desktop and mobile devices.  Overall, the successful implementation of Priv.io demonstrated that alternate architectures exist that can support systems similar to popular online social networks, while providing users much greater control over their data and privacy.

The second major component of this project was a close study of the online advertising services that enable popular sites like Facebook today.  We developed a technique to determine the price that advertisers must pay to target different demographics, and developed further techniques to be able to make consistent measurements.  Through the exploration of suggested bid data for different demographics, we find dramatic differences in prices paid across different user interests and locations.

The third major component of this project was a technique to detect when web sites and applications are leaking users' personal information (e.g., web trackers, advertisers, etc).  We developed a novel method that can automatically discover various types of PI carried in network traffic, given only the network traffic itself as input. Our results empower users and organizations to detect when websites and applications are transmitting their PI across the network.

Broader Impact:

The incredible popularity of today's web-based services has lead to significant concerns over privacy and user control over data.  Addressing these concerns requires a re-thinking of the current popular web-based business models, and, unfortunately, existing providers are dis-incentivized from doing so. The impact of this project will hopefully be felt by the millions of users who use today's popular services, who will be provided with an alternative to the business models of today.  Additionally, we make all of the code and data that resulted from this project available to the research community.


Last Modified: 09/09/2016
Modified by: Alan Mislove

Please report errors in award information by writing to: awardsearch@nsf.gov.

Print this page

Back to Top of page