The Rules of Engagement for Bug Bounty Programs

被引:13
|
作者
Laszka, Aron [1 ]
Zhao, Mingyi [2 ]
Malbari, Akash [3 ]
Grossklags, Jens [4 ]
机构
[1] Univ Houston, Houston, TX USA
[2] Snap Inc, Santa Monica, CA 90405 USA
[3] Penn State Univ, University Pk, PA 16802 USA
[4] Tech Univ Munich, Munich, Germany
关键词
D O I
10.1007/978-3-662-58387-6_8
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
White hat hackers, also called ethical hackers, who find and report vulnerabilities to bug bounty programs have become a significant part of today's security ecosystem. While the efforts of white hats contribute to heightened levels of security at the participating organizations, the white hats' participation needs to be carefully managed to balance risks with anticipated benefits. One way, taken by organizations, to manage bug bounty programs is to create rules that aim to regulate the behavior of white hats, but also bind these organizations to certain actions (e.g., level of bounty payments). To the best of our knowledge, no research exists that studies the content of these program rules and their impact on the effectiveness of bug bounty programs. We collected and analyzed the rules of 111 bounty programs on a major bug bounty platform, HackerOne. We qualitatively study the contents of these rules to determine a taxonomy of statements governing the expected behavior of white hats and organizations. We also report specific examples of rules to illustrate their reach and diversity across programs. We further engage in a quantitative analysis by pairing the findings of the analysis of the program rules with a second dataset about the performance of the same bug bounty programs, and conducting statistical analyses to evaluate the impact of program rules on program outcomes.
引用
收藏
页码:138 / 159
页数:22
相关论文
共 50 条
  • [1] Bug Bounty Programs - a Mapping Study
    Magazinius, Ana
    Mellegard, Niklas
    Olsson, Linda
    2019 45TH EUROMICRO CONFERENCE ON SOFTWARE ENGINEERING AND ADVANCED APPLICATIONS (SEAA 2019), 2019, : 412 - 415
  • [2] An Empirical Study of Bug Bounty Programs
    Walshe, Thomas
    Simpson, Andrew
    PROCEEDINGS OF THE 2020 IEEE 2ND INTERNATIONAL WORKSHOP ON INTELLIGENT BUG FIXING (IBF '20), 2020, : 35 - 44
  • [3] Understanding the Heterogeneity of Contributors in Bug Bounty Programs
    Hata, Hideaki
    Guo, Mingyu
    Babar, M. Ali
    11TH ACM/IEEE INTERNATIONAL SYMPOSIUM ON EMPIRICAL SOFTWARE ENGINEERING AND MEASUREMENT (ESEM 2017), 2017, : 223 - 228
  • [4] Bug Bounty Programs for Cybersecurity: Practices, Issues, and Recommendations
    Malladi, Suresh S.
    Subramanian, Hemang C.
    IEEE SOFTWARE, 2020, 37 (01) : 31 - 39
  • [5] Security Professional Skills Representation in Bug Bounty Programs and Processes
    Mumtaz, Sara
    Rodriguez, Carlos
    Zamanirad, Shayan
    SERVICE-ORIENTED COMPUTING, ICSOC 2020, 2021, 12632 : 334 - 348
  • [6] Navigating vulnerability markets and bug bounty programs: A public policy perspective
    Zrahia, Aviram
    INTERNET POLICY REVIEW, 2024, 13 (01):
  • [7] Beyond the Bugs: Enhancing Bug Bounty Programs through Academic Partnerships
    Kristofik, Andrej
    Vostoupal, Jakub
    Malinka, Kamil
    Kasl, Frantisek
    Loutocky, Pavel
    19TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY, AND SECURITY, ARES 2024, 2024,
  • [8] Optimizing Bug Bounty Programs for Efficient Malware-Related Vulnerability Discovery
    Yulianto, Semi
    Soewito, Benfano
    Gaol, Ford Lumban
    Kurniawan, Aditya
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2024, 15 (04) : 291 - 299
  • [9] Productivity and Patterns of Activity in Bug Bounty Programs: Analysis of HackerOne and Google Vulnerability Research
    Luna, Donatello
    Allodi, Luca
    Cremonini, Marco
    14TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY (ARES 2019), 2019,
  • [10] What We Know About Bug Bounty Programs - An Exploratory Systematic Mapping Study
    Magazinius, Ana
    Mellegard, Niklas
    Olsson, Linda
    SOCIO-TECHNICAL ASPECTS IN SECURITY AND TRUST, STAST 2019, 2021, 11739 : 89 - 106