Devising effective policies for bug-bounty platforms and security vulnerability discovery

Mingyi Zhao, Aron Laszka, Jens Grossklags

Research output: Contribution to journalArticlepeer-review

37 Scopus citations

Abstract

Bug-bounty programs have the potential to harvest the effort and diverse knowledge of thousands of independent security researchers, but running them at scale is challenging due to misaligned incentives and misallocation of effort. In our research, we discuss these challenges in detail and present relevant empirical data. We develop an economic framework consisting of two models that focus on evaluating different policies for improving the effectiveness of bug-bounty programs. Further, we discuss regulatory policy challenges and questions related to vulnerability research and disclosure, such as mandatory bug bounties and the relation to other cybersecurity policies.

Original languageEnglish (US)
Pages (from-to)372-418
Number of pages47
JournalJournal of Information Policy
Volume7
DOIs
StatePublished - 2017

All Science Journal Classification (ASJC) codes

  • Communication
  • Sociology and Political Science
  • Public Administration

Fingerprint

Dive into the research topics of 'Devising effective policies for bug-bounty platforms and security vulnerability discovery'. Together they form a unique fingerprint.

Cite this