Private Ordering Shaping Cybersecurity Policy: The Case of Bug Bounties

Private Ordering Shaping Cybersecurity Policy: The Case of Bug Bounties
复制标题

私人订购塑造网络安全政策:漏洞赏金案例

DOI:
--
复制
发表时间:
2018
期刊:
影响因子:
--
通讯作者:
A. Elazari
A. Elazari
中科院分区:
--
文献类型:
--
作者:
A. Elazari

文献摘要

被引文献

相似文献

安全漏洞正在成为新的石油。大型企业和主要国家都在努力应对不断扩大的网络风险,因为网络攻击和数据泄露的新闻正在占据媒体,成为头条新闻。漏洞市场从未见过如此繁荣。这种网络混乱现实的一个结果是“漏洞赏金”计划的扩散,安全研究人员合法地用新发现的漏洞换取金钱和声誉奖励。组织邀请个人黑客进行渗透测试的这种做法正在成为网络安全的最佳实践,并正在跨行业和政府组织扩展。虽然立法者、政策制定者和法院继续努力为白色和灰色帽子黑客提供便利,但在模糊和过于宽泛的反黑客法律下,行业通过形式合同和市场机制创造了一种替代制度来促进安全研究。然而,正如本文将展示的那样,这种制度并不完美。新兴的“漏洞赏金”经济的规则主要由公司和中介“平台”决定,使用多层单方面起草的“要么接受,要么放弃”条款,这往往使黑客处于“法律的”伤害之中--将民事和刑事责任的风险转移给黑客,而不是授权访问。也就是说,这是向前迈出的一步:一个案例研究,阐明了私人订购在塑造网络安全监管格局方面发挥的日益增长且往往未被观察到的作用。漏洞赏金计划通过合同邀请超过12万名黑客合法地交易漏洞以获得声誉和金钱奖励。如果没有形式合同,这种新兴的昆虫赏金经济将无法持续。然而,必须做更多的工作,以确保错误赏金真正运作的安全港,他们声称是和服务的功能,作为一个替代黑市。本文简要说明了目前的问题,在错误赏金私人统治的监管环境,并建议采取措施,以提高质量的错误赏金法律的条款,以真正促进道德黑客。
Security vulnerabilities are becoming the new oil. Mega-corporations and leading nations are struggling alike to address the ever-expanding cyber risk, as news of cyberattacks and data breaches are consuming the press, making top headlines. Never before the market for vulnerabilities has seen such prosperity. One result of this cyber chaos reality, is the proliferation of “bug bounties” programs in which security researchers legally trade newly discovered vulnerabilities for monetary and reputational rewards. This practice of organizations inviting individual hackers to perform penetration testing is becoming a best practice in cybersecurity and is expanding across industries and governmental organizations. While legislators, policymakers and courts continue to struggle to facilitate white and grey hat hacking, under murky and overbroad anti-hacking laws, industry, through form-contracts and market mechanisms created an alternative regime to foster security research. Yet, as this paper will show, that regime isn’t perfect. The rules of the emerging “bug bounty” economy are mainly dictated by companies and intermediary “platforms”, using multiple layers of unilaterally drafted “take-it-or-leave-it” terms, that often put hackers in “legal” harm’s way -- shifting the risk for civil and criminal liability towards hackers instead of authorizing access. That said, it is a step forward: a case study illuminating the growing and often unobserved role private ordering plays in shaping the cybersecurity regulatory landscape. Bug bounties programs through contracts invite more than 120,000 hackers to legally trade vulnerabilities for reputational and monetary rewards. Without form-contracts this emerging bug bounty economy wouldn’t be sustainable. Yet, more must be done to ensure bug bounties truly operate as the safe harbor they claim to be and serve their function as an alternative to the black market. This paper briefly illuminates the current problems in the bug bounty privately-ruled regulatory landscape and suggest steps to improve the quality of bug bounty legal terms in order to truly foster ethical hacking.