The Rules of Engagement for Bug Bounty Programs

被引:13
|
作者
Laszka, Aron [1 ]
Zhao, Mingyi [2 ]
Malbari, Akash [3 ]
Grossklags, Jens [4 ]
机构
[1] Univ Houston, Houston, TX USA
[2] Snap Inc, Santa Monica, CA 90405 USA
[3] Penn State Univ, University Pk, PA 16802 USA
[4] Tech Univ Munich, Munich, Germany
关键词
D O I
10.1007/978-3-662-58387-6_8
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
White hat hackers, also called ethical hackers, who find and report vulnerabilities to bug bounty programs have become a significant part of today's security ecosystem. While the efforts of white hats contribute to heightened levels of security at the participating organizations, the white hats' participation needs to be carefully managed to balance risks with anticipated benefits. One way, taken by organizations, to manage bug bounty programs is to create rules that aim to regulate the behavior of white hats, but also bind these organizations to certain actions (e.g., level of bounty payments). To the best of our knowledge, no research exists that studies the content of these program rules and their impact on the effectiveness of bug bounty programs. We collected and analyzed the rules of 111 bounty programs on a major bug bounty platform, HackerOne. We qualitatively study the contents of these rules to determine a taxonomy of statements governing the expected behavior of white hats and organizations. We also report specific examples of rules to illustrate their reach and diversity across programs. We further engage in a quantitative analysis by pairing the findings of the analysis of the program rules with a second dataset about the performance of the same bug bounty programs, and conducting statistical analyses to evaluate the impact of program rules on program outcomes.
引用
收藏
页码:138 / 159
页数:22
相关论文
共 50 条
  • [41] Rules of engagement
    Toumey, Chris
    NATURE NANOTECHNOLOGY, 2007, 2 (07) : 386 - 387
  • [42] RULES OF ENGAGEMENT
    Morse, Paige Marie
    CHEMICAL & ENGINEERING NEWS, 2011, 89 (16) : 21 - 23
  • [43] Rules of engagement
    不详
    NATION, 2001, 273 (11) : 3 - 4
  • [44] The rules of engagement
    DeYoung, Brody J.
    Innes, Roger W.
    NEW PHYTOLOGIST, 2007, 176 (03) : 506 - 509
  • [45] Rules of engagement
    Patrick L. Taylor
    Nature, 2007, 450 : 163 - 164
  • [46] The rules of engagement
    Anderson, Brian J.
    PEDIATRIC ANESTHESIA, 2009, 19 (10) : 931 - 933
  • [47] The 'Rules of Engagement'
    不详
    NEW YORK TIMES BOOK REVIEW, 2000, : 42 - 42
  • [48] RULES OF ENGAGEMENT
    Canela, Terrence
    ARCHITECT, 2012, 101 (06): : 29 - 29
  • [49] 'Rules of Engagement'
    Kermode, M
    SIGHT AND SOUND, 2000, 10 (09): : 50 - 51
  • [50] Rules of engagement
    Vetrocq, Marcia E.
    ART IN AMERICA, 2008, 96 (06): : 168 - +