Title
An Empirical Study of Web Vulnerability Discovery Ecosystems
Abstract
In recent years, many organizations have established bounty programs that attract white hat hackers who contribute vulnerability reports of web systems. In this paper, we collect publicly available data of two representative web vulnerability discovery ecosystems (Wooyun and HackerOne) and study their characteristics, trajectory, and impact. We find that both ecosystems include large and continuously growing white hat communities which have provided significant contributions to organizations from a wide range of business sectors. We also analyze vulnerability trends, response and resolve behaviors, and reward structures of participating organizations. Our analysis based on the HackerOne dataset reveals that a considerable number of organizations exhibit decreasing trends for reported web vulnerabilities. We further conduct a regression study which shows that monetary incentives have a significantly positive correlation with the number of vulnerabilities reported. Finally, we make recommendations aimed at increasing participation by white hats and organizations in such ecosystems.
Year
DOI
Venue
2015
10.1145/2810103.2813704
ACM Conference on Computer and Communications Security
Keywords
Field
DocType
Bug Bounty, Vulnerability Discovery, Vulnerability Disclosure, Monetary Incentives
Incentive,White hat,Computer science,Computer security,Vulnerability assessment,Vulnerability discovery,Business sector,Empirical research,Vulnerability,Ecosystem
Conference
Citations 
PageRank 
References 
14
0.64
20
Authors
3
Name
Order
Citations
PageRank
Mingyi Zhao1624.93
Jens Grossklags21297109.03
Peng Liu31701171.49