CRII: SaTC: Towards Efficient and Scalable Crowdsourced Vulnerability-Discovery using Bug-Bounty Programs
CRII: SaTC: Towards Efficient and Scalable Crowdsourced Vulnerability-Discovery using Bug-Bounty Programs
批准号:
1850510
负责人:
Aron Laszka
金额:
$17.42万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2019
资助国家:
美国
项目状态:
已结题
起止时间:
2019-03-01 至 2022-02-28
中文摘要
许多组织和公司最近选择使用所谓的漏洞赏金计划,即允许外部安全专家评估组织的产品和服务的安全性,并报告安全漏洞以换取奖励。漏洞奖励计划提供独特的好处,允许组织公开表示其对安全的承诺,并以负担得起的方式利用数千名安全专家的不同专业知识。尽管漏洞赏金计划迅速受到欢迎,但它们并没有得到很好的理解,而且可能会管理不善。因此,漏洞赏金计划可能会浪费大量资源,而且它们很少发挥其改善网络安全的潜力。该项目将通过收集和发布关于错误赏金生态系统的全面数据集,通过建立健全的错误赏金计划理论,并通过为组织和监管机构提供切实可行的建议,来显著提高错误赏金计划的效率。该项目将使组织和公司能够更有效地管理漏洞赏金计划,从而直接受益于他们,这将使他们能够以更低的成本消除安全漏洞,还将通过提高产品和服务的安全性使用户受益。该项目将有四个研究推动力。第一个推力将建立一个数据集,通过收集公共漏洞赏金计划的活动数据和规则描述,对定期参与该计划的专家进行采访和焦点小组研究,收集社交媒体帖子,并整合现有的数据集,如漏洞数据库,来构建一个捕获整个漏洞赏金生态系统的数据集。第二个重点将分析这个数据集,以了解生态系统及其参与者的激励和行动,并描述过程的特征,如发现和报告漏洞以及奖励报告。为了对文本数据进行编码,该项目将首先开发与错误赏金相关的概念的术语和分类法。在数据分析结果的推动下,第三个推力将开发一个正式的错误赏金生态系统模型,其中将包括技术流程以及行为和经济激励。为了捕捉这样一个复杂生态系统的方方面面,该项目将使用来自多个学科和领域的模型和技术,包括经济学和网络安全。在这个模型的基础上,第四个推力将提出和评估提高错误赏金计划的效率和可扩展性的新方法。该项目将考虑个别漏洞赏金计划的政策,如奖励漏洞报告的规则,以及监管漏洞赏金计划和促进它们之间协调的机制。该研究项目还将包括来自代表性不足群体的研究生,他们将有一个从事跨学科研究的绝佳机会。该奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Many organizations and companies have recently chosen to use so-called bug-bounty programs, which allow outside security experts to evaluate the security of an organization's products and services and to report security vulnerabilities in exchange for rewards. Bug-bounty programs provide unique benefits by allowing organizations to publicly signal their commitment to security and to harness the diverse expertise of thousands of security experts in an affordable way. Despite their rapidly growing popularity, bug-bounty programs are not well understood and can be mismanaged. As a result, bug bounty programs can waste substantial resources and they rarely live up to their potential to improve cybersecurity. This project will significantly improve the efficiency of bug-bounty programs by collecting and publishing comprehensive datasets on the bug-bounty ecosystem, by establishing a sound theory of bug-bounty programs, and by providing practical recommendations for organizations and regulators. The project will directly benefit organizations and companies by enabling them to manage bug-bounty programs more efficiently, which will allow them to eliminate security vulnerabilities at a lower cost, and it will also benefit users by improving the security of products and services.The project will have four research thrusts. The first thrust will build a dataset that captures the entire bug-bounty ecosystem by collecting activity data and rule descriptions from public bug-bounty programs, conducting interviews and focus-group studies with experts who regularly participate in programs, collecting social-media posts, and incorporating existing datasets, such as vulnerability databases. The second thrust will analyze this dataset to understand the ecosystem and its actors' incentives and actions, and to characterize processes, such as discovering and reporting vulnerabilities and rewarding reports. To code textual data, the project will first develop a terminology and taxonomy of bug-bounty related concepts. Driven by the results of the data analysis, the third thrust will develop a formal model of the bug-bounty ecosystem, which will incorporate technological processes as well as behavioral and economic incentives. To capture all aspects of such a complex ecosystem, the project will employ models and techniques from multiple disciplines and areas, including economics and cybersecurity. Building on this model, the fourth thrust will propose and evaluate novel approaches for improving the efficiency and scalability of bug-bounty programs. The project will consider policies for individual bug-bounty programs, such as rules for rewarding vulnerability reports, as well as mechanisms for regulating bug-bounty programs and for instigating coordination between them. The research project will also involve graduate students from underrepresented groups, who will have an excellent opportunity to engage in interdisciplinary research.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(7)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
DOI:
10.1145/3366423.3380078
发表时间:
2020-02
期刊:
Proceedings of The Web Conference 2020
影响因子:
--
作者:
[Sadegh Farhang;Mehmet Bahadir Kirdan;Aron Laszka;Jens Grossklags]
通讯作者:
Sadegh Farhang;Mehmet Bahadir Kirdan;Aron Laszka;Jens Grossklags
Principled Data-Driven Decision Support for Cyber-Forensic Investigations
为网络取证调查提供有原则的数据驱动决策支持
DOI:
10.1609/aaai.v37i4.25628
发表时间:
2023
期刊:
Proceedings of the AAAI Conference on Artificial Intelligence
影响因子:
--
作者:
[Atefi, Soodeh, Panda, Sakshyam, Panaousis, Emmanouil, Laszka, Aron]
通讯作者:
Laszka, Aron
DOI:
10.48550/arxiv.2301.04781
发表时间:
2023-01
期刊:
影响因子:
--
作者:
[Omer Akgul;Taha Eghtesad;A. Elazari;O. Gnawali;Jens Grossklags;Michelle L. Mazurek;Daniel Votipka]
通讯作者:
Omer Akgul;Taha Eghtesad;A. Elazari;O. Gnawali;Jens Grossklags;Michelle L. Mazurek;Daniel Votipka
DOI:
10.1109/tifs.2021.3054966
发表时间:
2021-01-01
期刊:
IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY
影响因子:
6.8
作者:
[Nisioti, Antonia, Loukas, George, Panaousis, Emmanouil]
通讯作者:
Panaousis, Emmanouil
The Benefits of Vulnerability Discovery and Bug Bounty Programs: Case Studies of Chromium and Firefox
漏洞发现和 Bug 赏金计划的好处:Chromium 和 Firefox 的案例研究
DOI:
10.1145/3543507.3583352
发表时间:
2023
期刊:
Proceedings of the ACM Web Conference 2023 (WWW'23
影响因子:
--
作者:
[Atefi, Soodeh, Sivagnanam, Amutheezan, Ayman, Afiya, Grossklags, Jens, Laszka, Aron]
通讯作者:
Laszka, Aron
共 6 条
Collaborative Research: RAPID: Addressing Transit Accessibility and Public Health Challenges due to COVID-19
-
批准号:2029952
-
项目类别:Standard Grant
-
资助金额:$4.49万
-
财政年份:2020
-
负责人:Aron Laszka
-
依托单位:
海外基金