A longitudinal study of hacker behaviour.

ACM Symposium on Applied Computing (SAC)(2022)

引用 2|浏览2
暂无评分
摘要
Bug bounty programmes employ the skills and curiosity of independent security researchers (hackers) to support pre- and post-deployment security. Driven by the question How effective are bug bounty platforms at retaining the interest of hackers? , this paper aims to address two issues concerning hackers' behaviour. First, to resolve the information asymmetry between programme and platform operators, it is necessary to measure the number of active hackers on a platform. Second, to assist programme operators' understanding, we identify the archetypal behaviours of hackers across a platform. We found that 6,813 hackers (with public accounts) have successfully submitted at least one vulnerability report on Bugcrowd. Of these, approximately 45% (with an account age greater than 9 months) can be considered inactive. We conclude that a significant number of inactive and unproductive hackers may contribute, in part, to the difficulties faced by programme operators. In particular, difficulties in retaining the focus of hackers can lead to underwhelming returns from the resources invested.
更多
查看译文
关键词
Bug bounty programmes, vulnerability disclosure, software security, behavioural modelling
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要