Title
An Exploratory Study of White Hat Behaviors in a Web Vulnerability Disclosure Program
Abstract
White hats are making significant contributions to cybersecurity by submitting vulnerability discovery reports to public vulnerability disclosure programs and company-initiated vulnerability reward programs. In this paper, we study white hat behaviors by analyzing a 3.5-year dataset which documents the contributions of 3254 white hats and their submitted 16446 Web vulnerability reports. Our dataset is collected from Wooyun, the predominant Web vulnerability disclosure program in China. We first show that Wooyun is continuously attracting new contributors from the white hat community. We then examine white hats' contributions along several dimensions. In particular, we provide evidence about the diversity inside Wooyun's white hat community and discuss the importance of this diversity for vulnerability discovery. Our results suggest that more participation, and thereby more diversity, contributes to higher productivity of the vulnerability discovery process.
Year
DOI
Venue
2014
10.1145/2663887.2663906
SIW@CCS
Keywords
DocType
Citations 
security and protection,vulnerability disclosure,vulnerability discovery,behavior,testing and debugging
Conference
8
PageRank 
References 
Authors
0.49
13
3
Name
Order
Citations
PageRank
Mingyi Zhao1624.93
Jens Grossklags21297109.03
Kai Chen352033.99