The Benefits of Vulnerability Discovery and Bug Bounty Programs: Case Studies of Chromium and Firefox

The Benefits of Vulnerability Discovery and Bug Bounty Programs: Case Studies of Chromium and Firefox
复制标题

漏洞发现和 Bug 赏金计划的好处:Chromium 和 Firefox 的案例研究

DOI:
10.1145/3543507.3583352
复制
发表时间:
2023
期刊:
Proceedings of the ACM Web Conference 2023 (WWW'23
影响因子:
--
通讯作者:
Laszka, Aron
Laszka, Aron
中科院分区:
--
文献类型:
--
作者:
Atefi, Soodeh;Sivagnanam, Amutheezan;Ayman, Afiya;Grossklags, Jens;Laszka, Aron

文献摘要

参考文献

相似文献

最近,漏洞赏金计划越来越受欢迎,并成为许多组织安全文化的重要组成部分。漏洞赏金计划使组织能够通过利用外部安全专家群体的各种专业知识(即,臭虫猎人)。尽管如此,量化bug奖励计划的好处仍然难以捉摸,这对管理它们提出了重大挑战。以前的研究侧重于衡量他们的好处,在报告的漏洞的数量或根据报告的漏洞的属性,如严重性或可利用性。然而,除了这些固有属性之外,报告的价值还取决于在内部专家发现并修补漏洞之前威胁行为者发现漏洞的可能性。在本文中,我们对Chromium和Firefox进行了数据驱动的研究漏洞奖励计划。首先,我们估计发现一个漏洞的难度,使用重新发现的概率作为一个新的度量。我们的研究结果表明,漏洞发现和修补通过使威胁行为者难以找到漏洞来提供明显的好处;然而,我们也发现了改进的机会,例如激励漏洞猎人更多地关注开发版本。其次,我们比较了内部与外部发现的漏洞类型以及被威胁行为者利用的漏洞类型。我们观察到外部漏洞猎人,内部安全团队和外部威胁行为者发现的漏洞之间存在显着差异,这表明漏洞奖励计划通过补充内部团队的专业知识提供了重要的好处,但也应该激励外部猎人更多地关注可能被威胁行为者利用的漏洞类型。
Recently, bug-bounty programs have gained popularity and become a significant part of the security culture of many organizations. Bug-bounty programs enable organizations to enhance their security posture by harnessing the diverse expertise of crowds of external security experts (i.e., bug hunters). Nonetheless, quantifying the benefits of bug-bounty programs remains elusive, which presents a significant challenge for managing them. Previous studies focused on measuring their benefits in terms of the number of vulnerabilities reported or based on the properties of the reported vulnerabilities, such as severity or exploitability. However, beyond these inherent properties, the value of a report also depends on the probability that the vulnerability would be discovered by a threat actor before an internal expert could discover and patch it. In this paper, we present a data-driven study of the Chromium and Firefox vulnerability-reward programs. First, we estimate the difficulty of discovering a vulnerability using the probability of rediscovery as a novel metric. Our findings show that vulnerability discovery and patching provide clear benefits by making it difficult for threat actors to find vulnerabilities; however, we also identify opportunities for improvement, such as incentivizing bug hunters to focus more on development releases. Second, we compare the types of vulnerabilities that are discovered internally vs. externally and those that are exploited by threat actors. We observe significant differences between vulnerabilities found by external bug hunters, internal security teams, and external threat actors, which indicates that bug-bounty programs provide an important benefit by complementing the expertise of internal teams, but also that external hunters should be incentivized more to focus on the types of vulnerabilities that are likely to be exploited by threat actors.
促进物联网漏洞管理的道德黑客:初步探讨错误赏金计划和负责任的披露
DOI: --
发表时间: 2019
期刊: International Conference on Telecommunications and Remote Sensing
影响因子: --
作者:
A. Ding;Gianluca Limon De Jesus;M. Janssen
通讯作者: M. Janssen
网络安全漏洞赏金计划:实践、问题和建议
DOI: --
发表时间: 2020
期刊: IEEE Software
影响因子: 3.3
作者:
Suresh Malladi;H. Subramanian
通讯作者: H. Subramanian
消除错误赏金平台中验证报告的不一致激励措施
DOI: --
发表时间: 2016
期刊: European Symposium on Research in Computer Security
影响因子: --
作者:
Aron Laszka;Mingyi Zhao;Jens Grossklags
通讯作者: Jens Grossklags
私人订购塑造网络安全政策:漏洞赏金案例
DOI: --
发表时间: 2018
期刊:
影响因子: --
作者:
A. Elazari
通讯作者: A. Elazari
DOI: --
发表时间: 2016
影响因子: 3.9
作者:
T. Maillart;Mingyi Zhao;Jens Grossklags;J. Chuang
通讯作者: J. Chuang