Organizational Learning on Bug Bounty Platforms

被引:0
|
作者
Ahmed, Ali [1 ]
Lee, Ho Cheung Brian [1 ]
机构
[1] Univ Massachusetts Lowell, Lowell, MA 01854 USA
来源
AMCIS 2020 PROCEEDINGS | 2020年
关键词
Vulnerability; Resolution-time; bug bounty; hacking; learning curve;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Crowdsourced vulnerability discovery has become an increasingly popular method to find security vulnerabilities in a system. In this research, we have analyzed the firm's experience-performance relationship in resolving such security vulnerabilities on bug-bounty platforms. Using a dataset from HackerOne, a major bug bounty platform, we have shown that the firms' vulnerability resolving time on the platform has a U-shape relationship with their experience in resolving the reports. We argue that the firms over-generalize their limited experience initially, which leads to a negative experience effect on resolving performance. However, as the firms encounter more reported vulnerabilities, the actual learning effect dominates the experience effect and improves the firms' resolving performance. We further show that the firms' resolving performance depends on the relevance of the information they received. When the reported vulnerability is relevant and receives a bounty reward, it alleviates the over-generalizing effect but introduces an information overload effect.
引用
收藏
页数:10
相关论文
共 18 条
  • [1] Blockchain-based Bug Bounty Framework
    Badash, Lital
    Tapas, Nachiket
    Nadler, Asaf
    Longo, Francesco
    Shabtai, Asaf
    36TH ANNUAL ACM SYMPOSIUM ON APPLIED COMPUTING, SAC 2021, 2021, : 239 - 248
  • [2] Bug Bounty Programs for Cybersecurity: Practices, Issues, and Recommendations
    Malladi, Suresh S.
    Subramanian, Hemang C.
    IEEE SOFTWARE, 2020, 37 (01) : 31 - 39
  • [3] Bountychain: Toward Decentralizing a Bug Bounty Program with Blockchain and IPFS
    Alex Hoffman
    Phillipe Austria
    Chol Hyun Park
    Yoohwan Kim
    International Journal of Networked and Distributed Computing, 2021, 9 : 86 - 93
  • [4] Bountychain: Toward Decentralizing a Bug Bounty Program with Blockchain and IPFS
    Hoffman, Alex
    Austria, Phillipe
    Park, Chol Hyun
    Kim, Yoohwan
    INTERNATIONAL JOURNAL OF NETWORKED AND DISTRIBUTED COMPUTING, 2021, 9 (2-3) : 86 - 93
  • [5] Beyond the Bugs: Enhancing Bug Bounty Programs through Academic Partnerships
    Kristofik, Andrej
    Vostoupal, Jakub
    Malinka, Kamil
    Kasl, Frantisek
    Loutocky, Pavel
    19TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY, AND SECURITY, ARES 2024, 2024,
  • [6] Optimizing Bug Bounty Programs for Efficient Malware-Related Vulnerability Discovery
    Yulianto, Semi
    Soewito, Benfano
    Gaol, Ford Lumban
    Kurniawan, Aditya
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2024, 15 (04) : 291 - 299
  • [7] What We Know About Bug Bounty Programs - An Exploratory Systematic Mapping Study
    Magazinius, Ana
    Mellegard, Niklas
    Olsson, Linda
    SOCIO-TECHNICAL ASPECTS IN SECURITY AND TRUST, STAST 2019, 2021, 11739 : 89 - 106
  • [8] Using Real-world Bug Bounty Programs in Secure Coding Course: Experience Report
    Malinka, Kamil
    Firc, Anton
    Loutocky, Pavel
    Vostoupal, Jakub
    Kristofik, Andrej
    Kasl, Frantisek
    PROCEEDINGS OF THE 2024 CONFERENCE INNOVATION AND TECHNOLOGY IN COMPUTER SCIENCE EDUCATION, VOL 1, ITICSE 2024, 2024, : 227 - 233
  • [9] The organizational learning curve
    Fioretti, Guido
    EUROPEAN JOURNAL OF OPERATIONAL RESEARCH, 2007, 177 (03) : 1375 - 1384
  • [10] A connectionist model of the organizational learning curve
    Fioretti G.
    Computational and Mathematical Organization Theory, 2007, 13 (1) : 1 - 16