课题基金 / 基金详情

CRII: SaTC: Towards Efficient and Scalable Crowdsourced Vulnerability-Discovery using Bug-Bounty Programs

CRII: SaTC: Towards Efficient and Scalable Crowdsourced Vulnerability-Discovery using Bug-Bounty Programs
CRII:SaTC:使用错误赏金计划实现高效且可扩展的众包漏洞发现
批准号:
1850510
负责人:
Aron Laszka
金额:
$17.42万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2019
资助国家:
美国
项目状态:
已结题
起止时间:
2019-03-01 至 2022-02-28

项目摘要

项目成果

Aron Laszka的其他基金

相似基金

相关文献

中文摘要
翻译
许多组织和公司最近选择使用所谓的漏洞赏金计划,该计划允许外部安全专家评估组织产品和服务的安全性,并报告安全漏洞以换取奖励。漏洞赏金计划提供了独特的好处,允许组织公开表明他们对安全的承诺,并以负担得起的方式利用数千名安全专家的各种专业知识。尽管bug赏金计划迅速流行,但人们对它的理解并不充分,而且可能管理不善。因此,漏洞赏金计划可能会浪费大量资源,而且它们很少能够发挥其改善网络安全的潜力。该项目将通过收集和发布关于漏洞奖励生态系统的全面数据集,建立健全的漏洞奖励计划理论,并为组织和监管机构提供实用建议,从而显着提高漏洞奖励计划的效率。该项目将使组织和公司直接受益,使他们能够更有效地管理漏洞奖励计划,这将使他们能够以较低的成本消除安全漏洞,并通过提高产品和服务的安全性使用户受益。该项目将有四个研究重点。第一个目标是建立一个数据集,通过从公共bug赏金计划中收集活动数据和规则描述,与定期参与计划的专家进行访谈和焦点小组研究,收集社交媒体帖子,并整合现有的数据集,如漏洞数据库,来捕获整个bug赏金生态系统。第二个重点是分析这个数据集,以了解生态系统及其参与者的动机和行动,并描述过程,如发现和报告脆弱性和奖励报告。为了对文本数据进行编码,该项目将首先开发一个术语和bug赏金相关概念的分类法。在数据分析结果的驱动下,第三个目标将开发一个正式的bug奖励生态系统模型,该模型将包括技术流程以及行为和经济激励。为了捕捉这样一个复杂生态系统的各个方面,该项目将采用来自多个学科和领域的模型和技术,包括经济学和网络安全。在这个模型的基础上,第四个重点将提出和评估新的方法,以提高效率和可扩展性的错误赏金计划。该项目将考虑单个错误赏金计划的政策,例如奖励漏洞报告的规则,以及监管错误赏金计划和促进它们之间协调的机制。该研究项目还将涉及来自代表性不足群体的研究生,他们将有一个从事跨学科研究的绝佳机会。该奖项反映了NSF的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Many organizations and companies have recently chosen to use so-called bug-bounty programs, which allow outside security experts to evaluate the security of an organization's products and services and to report security vulnerabilities in exchange for rewards. Bug-bounty programs provide unique benefits by allowing organizations to publicly signal their commitment to security and to harness the diverse expertise of thousands of security experts in an affordable way. Despite their rapidly growing popularity, bug-bounty programs are not well understood and can be mismanaged. As a result, bug bounty programs can waste substantial resources and they rarely live up to their potential to improve cybersecurity. This project will significantly improve the efficiency of bug-bounty programs by collecting and publishing comprehensive datasets on the bug-bounty ecosystem, by establishing a sound theory of bug-bounty programs, and by providing practical recommendations for organizations and regulators. The project will directly benefit organizations and companies by enabling them to manage bug-bounty programs more efficiently, which will allow them to eliminate security vulnerabilities at a lower cost, and it will also benefit users by improving the security of products and services.The project will have four research thrusts. The first thrust will build a dataset that captures the entire bug-bounty ecosystem by collecting activity data and rule descriptions from public bug-bounty programs, conducting interviews and focus-group studies with experts who regularly participate in programs, collecting social-media posts, and incorporating existing datasets, such as vulnerability databases. The second thrust will analyze this dataset to understand the ecosystem and its actors' incentives and actions, and to characterize processes, such as discovering and reporting vulnerabilities and rewarding reports. To code textual data, the project will first develop a terminology and taxonomy of bug-bounty related concepts. Driven by the results of the data analysis, the third thrust will develop a formal model of the bug-bounty ecosystem, which will incorporate technological processes as well as behavioral and economic incentives. To capture all aspects of such a complex ecosystem, the project will employ models and techniques from multiple disciplines and areas, including economics and cybersecurity. Building on this model, the fourth thrust will propose and evaluate novel approaches for improving the efficiency and scalability of bug-bounty programs. The project will consider policies for individual bug-bounty programs, such as rules for rewarding vulnerability reports, as well as mechanisms for regulating bug-bounty programs and for instigating coordination between them. The research project will also involve graduate students from underrepresented groups, who will have an excellent opportunity to engage in interdisciplinary research.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(7)
专著(0)
科研奖励(0)
会议论文
DOI: 10.1145/3366423.3380078
发表时间: 2020-02
期刊: Proceedings of The Web Conference 2020
影响因子: --
作者: [Sadegh Farhang;Mehmet Bahadir Kirdan;Aron Laszka;Jens Grossklags]
通讯作者: Sadegh Farhang;Mehmet Bahadir Kirdan;Aron Laszka;Jens Grossklags
Principled Data-Driven Decision Support for Cyber-Forensic Investigations
为网络取证调查提供有原则的数据驱动决策支持
DOI: 10.1609/aaai.v37i4.25628
发表时间: 2023
期刊: Proceedings of the AAAI Conference on Artificial Intelligence
影响因子: --
作者: [Atefi, Soodeh, Panda, Sakshyam, Panaousis, Emmanouil, Laszka, Aron]
通讯作者: Laszka, Aron
DOI: 10.48550/arxiv.2301.04781
发表时间: 2023-01
期刊:
影响因子: --
作者: [Omer Akgul;Taha Eghtesad;A. Elazari;O. Gnawali;Jens Grossklags;Michelle L. Mazurek;Daniel Votipka]
通讯作者: Omer Akgul;Taha Eghtesad;A. Elazari;O. Gnawali;Jens Grossklags;Michelle L. Mazurek;Daniel Votipka
DOI: 10.1109/tifs.2021.3054966
发表时间: 2021-01-01
期刊: IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY
影响因子: 6.8
作者: [Nisioti, Antonia, Loukas, George, Panaousis, Emmanouil]
通讯作者: Panaousis, Emmanouil
6
    Collaborative Research: RAPID: Addressing Transit Accessibility and Public Health Challenges due to COVID-19
    • 批准号:
      2029952
    • 项目类别:
      Standard Grant
    • 资助金额:
      $4.49万
    • 财政年份:
      2020
    • 负责人:
      Aron Laszka
    • 依托单位:
    海外基金