Researchers identify ways to exploit 'cloud browsers' for large-scale, anonymous computing

Nov 28, 2012

Researchers from North Carolina State University and the University of Oregon have found a way to exploit cloud-based Web browsers, using them to perform large-scale computing tasks anonymously. The finding has potential ramifications for the security of "cloud browser" services.

At issue are cloud browsers, which create a in the cloud so that computing is done there rather than on a user's machine. This is particularly useful for mobile devices, such as smartphones, which have limited .The cloud-computing paradigm pools the and storage of , allowing shared resources for multiple users.

"Think of a cloud browser as being just like the browser on your desktop computer, but working entirely in the cloud and providing only the resulting image to your screen," says Dr. William Enck, an assistant professor of computer science at NC State and co-author of a paper describing the research.

Because these cloud browsers are designed to perform complex functions, the researchers wanted to see if they could be used to perform a series of large-scale computations that had nothing to do with browsing. Specifically, the researchers wanted to determine if they could perform those functions using the "MapReduce" technique developed by , which facilitates coordinated computation involving parallel efforts by multiple machines.

The research team knew that coordinating any new series of computations would entail passing large packets of data between different nodes, or cloud browsers. To address this challenge, researchers stored data packets on bit.ly and other URL-shortening sites, and then passed the resulting "links" between various nodes.

Using this technique, the researchers were able to perform standard computation functions using that were 1, 10 and 100 in size. "It could have been much larger," Enck says, "but we did not want to be an undue burden on any of the free services we were using."

"We've shown that this can be done," Enck adds. "And one of the broader ramifications of this is that it could be done anonymously. For instance, a third party could easily abuse these systems, taking the free computational power and using it to crack passwords."

However, Enck says cloud browsers can protect themselves to some extent by requiring users to create accounts – and then putting limits on how those accounts are used. This would make it easier to detect potential problems.

The paper, "Abusing Cloud-Based Browsers for Fun and Profit," will be presented Dec. 6 at the 2012 Annual Computer Security Applications Conference in Orlando, Fla. The paper was co-authored by Vasant Tendulkar and Ashwin Shashidharan, graduate students at NC State, and Joe Pletcher, Ryan Snyder and Dr. Kevin Butler, of the University of Oregon. The research was supported by the National Science Foundation and the U.S. Army Research Office.

Explore further: Researchers craft program to stop cloud computer problems before they start

Related Stories

Head for the clouds, feet firmly on the ground

Mar 05, 2012

Computer engineers in the US writing in the International Journal of Communication Networks and Distributed Systems have reviewed the research literature to get a clear picture of cloud computing, its adoption, use and th ...

Recommended for you

Google eyes emerging markets networks

11 hours ago

Google has become deeply involved in a series of projects to build and operate wireless networks in emerging markets including sub-Saharan Africa and Southeast Asia, a report said Friday.

Facial-recognition technology proves its mettle

13 hours ago

(Phys.org) —In a study that evaluated some of the latest in automatic facial recognition technology, researchers at Michigan State University were able to quickly identify one of the Boston Marathon bombing ...

Mobile app to help fight against racism in France

14 hours ago

A French anti-racism association is launching a mobile application it hopes will help eradicate racist graffiti by enabling users to take photos of offensive tags, geo-locate them and get them removed.

User comments : 1

Adjust slider to filter visible comments by rank

Display comments: newest first

Caliban
not rated yet Nov 29, 2012
Hahahaha -- this is one "Tragedy of the Commons" that you can be sure will be quickly rectified.

NONE of the Cloud Fairies will be pleased to learn that people are making use of all that floppage WITHOUT PAYING FOR IT!

More news stories

Google eyes emerging markets networks

Google has become deeply involved in a series of projects to build and operate wireless networks in emerging markets including sub-Saharan Africa and Southeast Asia, a report said Friday.

Drones may violate international law

(Phys.org) —As President Obama gives a speech on national security—including defending U.S. use of drones to combat terrorism—Leila Sadat, JD, international law expert and professor of law at Washington University in ...

Facial-recognition technology proves its mettle

(Phys.org) —In a study that evaluated some of the latest in automatic facial recognition technology, researchers at Michigan State University were able to quickly identify one of the Boston Marathon bombing ...

The long road to the 2000-watt society

The vision of a society in which each inhabitant of the earth manages to consume only 2000 watts has already been around for 15 years. During this time, there has been a steady increase in environmental awareness ...

Galaxies fed by funnels of fuel

(Phys.org) —Computer simulations of galaxies growing over billions of years have revealed a likely scenario for how they feed: a cosmic version of swirly straws.