Navigating vulnerability markets and bug bounty programs: A public policy perspective

被引:1
|
作者
Zrahia, Aviram [1 ]
机构
[1] Tel Aviv Univ, Tel Aviv, Israel
来源
INTERNET POLICY REVIEW | 2024年 / 13卷 / 01期
关键词
Cybersecurity; Vulnerability sharing; Digital policy; Hacker; Digital market; DISCLOSURE; ECONOMICS; TRUST;
D O I
10.14763/2024.1.1740
中图分类号
G2 [信息与知识传播];
学科分类号
05 ; 0503 ;
摘要
As societies become increasingly dependent on digital means, organisations seek ways to prevent software exploitation by eliminating vulnerabilities or acquiring them as products. However, there is an ongoing debate regarding the extent to which governments should become involved in markets for vulnerability sharing. This paper examines the economics of vulnerabilities and outlines possible areas for governmental interventions. I survey three policy alternatives to support the discovery and disclosure of software vulnerabilities: integrating security and penetration testing into the software development life cycle, acquiring exploitable critical vulnerabilities by governments, and promoting bug bounty programs and platforms as vulnerability -sharing structures. For each suggested alternative, I present an impact matrix to qualitatively measure the effectiveness and efficiency of the vulnerability discovery process and the attractiveness, legality and trustworthiness of the disclosure process. I argue that bug bounty programs that bring together organisations and ethical hackers to trade vulnerabilities produce the highest impact. These gig economy structures are often based on two-sided digital market platforms as their foundation and offer a low entry barrier and assurance level for both market players. The discussion provides a foundation for governmental decision -makers to design effective policies for sharing vulnerabilities.
引用
收藏
页数:38
相关论文
共 50 条
  • [21] Competition Policy In Health Care Markets: Navigating The Enforcement And Policy Maze
    Gaynor, Martin
    HEALTH AFFAIRS, 2014, 33 (06) : 1088 - 1093
  • [22] Farmers' markets in low income communities: impact of community environment, food programs and public policy
    Young, Candace
    Karpyn, Allison
    Uy, Nicky
    Wich, Katy
    Glyn, Jonathan
    COMMUNITY DEVELOPMENT, 2011, 42 (02) : 208 - 220
  • [23] Navigating the complexities of carbon markets policy in ASEAN: challenges and opportunities
    Hermawan, Sapto
    Kusuma, Febrian Indar Surya
    ENVIRONMENT DEVELOPMENT AND SUSTAINABILITY, 2024,
  • [24] Gambling, Prediction Markets and Public Policy
    Paton, David
    Siegel, Donald S.
    Williams, Leighton Vaughan
    SOUTHERN ECONOMIC JOURNAL, 2010, 76 (04) : 878 - 883
  • [25] Planning, public policy & property markets
    Bourassa, Steven C.
    JOURNAL OF PLANNING EDUCATION AND RESEARCH, 2006, 25 (04) : 440 - 441
  • [26] Higher education markets and public policy
    Dill D.D.
    Higher Education Policy, 1997, 10 (3-4) : 167 - 185
  • [27] Aligning public policy with electricity markets
    Schuler, RE
    2001 POWER ENGINEERING SOCIETY SUMMER MEETING, VOLS 1-3, CONFERENCE PROCEEDINGS, 2001, : 555 - 557
  • [28] Planning, public policy & property markets
    Lizieri, C
    HOUSING STUDIES, 2006, 21 (03) : 445 - 447
  • [29] The Evolution of Strategic Foresight: Navigating Public Policy Making
    Murphy, Anne
    LEADERSHIP & ORGANIZATION DEVELOPMENT JOURNAL, 2013, 34 (04) : 378 - 379
  • [30] PUBLIC POLICY AND PRIVATE PENSION PROGRAMS
    OMEARA, AC
    BUSINESS LAWYER, 1966, 21 (04): : 971 - 979