Given Enough Eyeballs, All Bugs Are Shallow? Revisiting Eric Raymond with Bug Bounty Programs
arXiv:1608.03445 · doi:10.1093/cybsec/tyx008
Abstract
Bug bounty programs offer a modern platform for organizations to crowdsource their software security and for security researchers to be fairly rewarded for the vulnerabilities they find. Little is known however on the incentives set by bug bounty programs: How they drive new bug discoveries, and how they supposedly improve security through the progressive exhaustion of discoverable vulnerabilities. Here, we recognize that bug bounty programs create tensions, for organizations running them on the one hand, and for security researchers on the other hand. At the level of one bug bounty program, security researchers face a sort of St-Petersburg paradox: The probability of finding additional bugs decays fast, and thus can hardly be matched with a sufficient increase of monetary rewards. Furthermore, bug bounty program managers have an incentive to gather the largest possible crowd to ensure a larger pool of expertise, which in turn increases competition among security researchers. As a result, we find that researchers have high incentives to switch to newly launched programs, for which a reserve of low-hanging fruit vulnerabilities is still available. Our results inform on the technical and economic mechanisms underlying the dynamics of bug bounty program contributions, and may in turn help improve the mechanism design of bug bounty programs that get increasingly adopted by cybersecurity savvy organizations.
19 pages, 3 figures, 1 table, forthcoming at Journal of Cybersecurity (2017)
References in corpus (2)
Cited by in corpus (10)
- Closing the AI Accountability Gap: Defining an End-to-End Framework for Internal Algorithmic Auditing
- Hey Google, What Exactly Do Your Security Patches Tell Us? A Large-Scale Empirical Study on Android Patched Vulnerabilities
- GitHub Sponsors: Exploring a New Way to Contribute to Open Source
- A Bug Bounty Perspective on the Disclosure of Web Vulnerabilities
- Aristotle vs. Ringelmann: On Superlinear Production in Open Source Software
- Cost Sharing Security Information with Minimal Release Delay
- Bounties in Open Source Development on GitHub: A Case Study of Bountysource Bounties
- A Deep Dive Into How Open-Source Project Maintainers Review and Resolve Bug Bounty Reports
- Computational Diplomacy: How "hackathons for good" feed a participatory future for multilateralism in the digital age
- Proposal of a Novel Bug Bounty Implementation Using Gamification