CRII: SaTC: Towards Efficient and Scalable Crowdsourced Vulnerability-Discovery using Bug-Bounty Programs
CRII: SaTC: Towards Efficient and Scalable Crowdsourced Vulnerability-Discovery using Bug-Bounty Programs
批准号:
1850510
负责人:
Aron Laszka
金额:
$17.42万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2019
资助国家:
美国
项目状态:
已结题
起止时间:
2019-03-01 至 2022-02-28
中文摘要
点击翻译按钮获取中文摘要
英文摘要
Many organizations and companies have recently chosen to use so-called bug-bounty programs, which allow outside security experts to evaluate the security of an organization's products and services and to report security vulnerabilities in exchange for rewards. Bug-bounty programs provide unique benefits by allowing organizations to publicly signal their commitment to security and to harness the diverse expertise of thousands of security experts in an affordable way. Despite their rapidly growing popularity, bug-bounty programs are not well understood and can be mismanaged. As a result, bug bounty programs can waste substantial resources and they rarely live up to their potential to improve cybersecurity. This project will significantly improve the efficiency of bug-bounty programs by collecting and publishing comprehensive datasets on the bug-bounty ecosystem, by establishing a sound theory of bug-bounty programs, and by providing practical recommendations for organizations and regulators. The project will directly benefit organizations and companies by enabling them to manage bug-bounty programs more efficiently, which will allow them to eliminate security vulnerabilities at a lower cost, and it will also benefit users by improving the security of products and services.The project will have four research thrusts. The first thrust will build a dataset that captures the entire bug-bounty ecosystem by collecting activity data and rule descriptions from public bug-bounty programs, conducting interviews and focus-group studies with experts who regularly participate in programs, collecting social-media posts, and incorporating existing datasets, such as vulnerability databases. The second thrust will analyze this dataset to understand the ecosystem and its actors' incentives and actions, and to characterize processes, such as discovering and reporting vulnerabilities and rewarding reports. To code textual data, the project will first develop a terminology and taxonomy of bug-bounty related concepts. Driven by the results of the data analysis, the third thrust will develop a formal model of the bug-bounty ecosystem, which will incorporate technological processes as well as behavioral and economic incentives. To capture all aspects of such a complex ecosystem, the project will employ models and techniques from multiple disciplines and areas, including economics and cybersecurity. Building on this model, the fourth thrust will propose and evaluate novel approaches for improving the efficiency and scalability of bug-bounty programs. The project will consider policies for individual bug-bounty programs, such as rules for rewarding vulnerability reports, as well as mechanisms for regulating bug-bounty programs and for instigating coordination between them. The research project will also involve graduate students from underrepresented groups, who will have an excellent opportunity to engage in interdisciplinary research.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(7)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
DOI:
10.1145/3366423.3380078
发表时间:
2020-02
期刊:
Proceedings of The Web Conference 2020
影响因子:
--
作者:
[Sadegh Farhang;Mehmet Bahadir Kirdan;Aron Laszka;Jens Grossklags]
通讯作者:
Sadegh Farhang;Mehmet Bahadir Kirdan;Aron Laszka;Jens Grossklags
Principled Data-Driven Decision Support for Cyber-Forensic Investigations
为网络取证调查提供有原则的数据驱动决策支持
DOI:
10.1609/aaai.v37i4.25628
发表时间:
2023
期刊:
Proceedings of the AAAI Conference on Artificial Intelligence
影响因子:
--
作者:
[Atefi, Soodeh, Panda, Sakshyam, Panaousis, Emmanouil, Laszka, Aron]
通讯作者:
Laszka, Aron
DOI:
10.48550/arxiv.2301.04781
发表时间:
2023-01
期刊:
影响因子:
--
作者:
[Omer Akgul;Taha Eghtesad;A. Elazari;O. Gnawali;Jens Grossklags;Michelle L. Mazurek;Daniel Votipka]
通讯作者:
Omer Akgul;Taha Eghtesad;A. Elazari;O. Gnawali;Jens Grossklags;Michelle L. Mazurek;Daniel Votipka
DOI:
10.1109/tifs.2021.3054966
发表时间:
2021-01-01
期刊:
IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY
影响因子:
6.8
作者:
[Nisioti, Antonia, Loukas, George, Panaousis, Emmanouil]
通讯作者:
Panaousis, Emmanouil
The Benefits of Vulnerability Discovery and Bug Bounty Programs: Case Studies of Chromium and Firefox
漏洞发现和 Bug 赏金计划的好处:Chromium 和 Firefox 的案例研究
DOI:
10.1145/3543507.3583352
发表时间:
2023
期刊:
Proceedings of the ACM Web Conference 2023 (WWW'23
影响因子:
--
作者:
[Atefi, Soodeh, Sivagnanam, Amutheezan, Ayman, Afiya, Grossklags, Jens, Laszka, Aron]
通讯作者:
Laszka, Aron
共 6 条
Collaborative Research: RAPID: Addressing Transit Accessibility and Public Health Challenges due to COVID-19
-
批准号:2029952
-
项目类别:Standard Grant
-
资助金额:$4.49万
-
财政年份:2020
-
负责人:Aron Laszka
-
依托单位:
海外基金