Given enough eyeballs, all bugs are shallow? Revisiting Eric Raymond with bug bounty programs

Given enough eyeballs, all bugs are shallow? Revisiting Eric Raymond with bug bounty programs
复制标题

只要有足够的眼球,所有的虫子都是浅薄的?

DOI:
--
复制
发表时间:
2016
影响因子:
3.9
通讯作者:
J. Chuang
J. Chuang
中科院分区:
--
文献类型:
--
作者:
T. Maillart;Mingyi Zhao;Jens Grossklags;J. Chuang

文献摘要

被引文献

相似文献

漏洞赏金计划为组织提供了一个现代化的平台,可以众包他们的软件安全性,并为安全研究人员提供公平的奖励,因为他们发现了漏洞。然而,关于漏洞奖励计划所设定的激励措施,我们知之甚少:它们如何推动新的漏洞发现,以及它们如何通过逐步耗尽可修复的漏洞来提高安全性。在这里,我们认识到漏洞赏金计划会造成紧张局势,一方面是运行它们的组织,另一方面是安全研究人员。在漏洞赏金计划的层面上,安全研究人员面临着一种圣彼得堡悖论:发现更多漏洞的可能性迅速下降,因此很难与足够增加的金钱奖励相匹配。此外,漏洞赏金计划的管理者有动机聚集尽可能多的人群,以确保更大的专业知识库,这反过来又增加了安全研究人员之间的竞争。因此,我们发现,研究人员有很高的动机切换到新推出的程序,其中的低挂水果漏洞储备仍然可用。我们的研究结果提供了漏洞赏金计划贡献动态背后的技术和经济机制的信息,反过来可能有助于改进漏洞赏金计划的机制设计,这些计划越来越多地被网络安全组织所采用。
Bug bounty programs offer a modern platform for organizations to crowdsource their software security and for security researchers to be fairly rewarded for the vulnerabilities they find. Little is known however on the incentives set by bug bounty programs: How they drive new bug discoveries, and how they supposedly improve security through the progressive exhaustion of discoverable vulnerabilities. Here, we recognize that bug bounty programs create tensions, for organizations running them on the one hand, and for security researchers on the other hand. At the level of one bug bounty program, security researchers face a sort of St-Petersburg paradox: The probability of finding additional bugs decays fast, and thus can hardly be matched with a sufficient increase of monetary rewards. Furthermore, bug bounty program managers have an incentive to gather the largest possible crowd to ensure a larger pool of expertise, which in turn increases competition among security researchers. As a result, we find that researchers have high incentives to switch to newly launched programs, for which a reserve of low-hanging fruit vulnerabilities is still available. Our results inform on the technical and economic mechanisms underlying the dynamics of bug bounty program contributions, and may in turn help improve the mechanism design of bug bounty programs that get increasingly adopted by cybersecurity savvy organizations.