Home / Current Issue / Paper 1707316
Conceiving Effective Rules for Bug-Bounty Platforms and Security Vulnerability Detection
Subject area: Science,Engineering and Technology · Area of research: Cybersecurity
Abstract
In a world of rising security risks, legislation and standards for protecting existing IT information and data preservation are major concerns and costs. Security and data vulnerability concern every company. Ethical and unethical hackers find and report vulnerabilities to bug bounty sites for modern security. Organizations rely on white hats, but they must constantly assess risks and rewards. Concerned institutions adopt special regulations to control white hat activity wherever they are, imposing responsibility on the participating organization like bounty levies. The quantitative study established bug bounty platform standards for system security vulnerability detection. The research explored and suggested basic security vulnerability detection criteria to detect typical system flaws. The study proposed relevant security vulnerability detection rules.
Keywords
White Hat; Ethical Hacker; Bug Bounty Platform.
References
[1] Finifter, M., Akhawe, D., Wagner, D. (2013). An empirical study of vulnerability rewards programs. In: USENIX Security Symposium.
[2] Kuehn, A., Mueller, M. (2014). Analyzing bug bounty programs: An institutional perspective on the economics of software vulnerabilities. TPRC Conference Paper
[3] Zhao, M., Grossklags, J., Liu, P. (2015). An empirical study of web vulnerability discovery ecosystems. In: 22nd ACM SIGSAC Conference on Computer and Communications Security (CCS)
[4] Amit Elazari (2019). Private ordering shaping cybersecurity policy: The case of bug bounties. In R. Ellis & V. Mohan (Eds.), Rewired: Cybersecurity Governance (pp. 102). Wiley.
[5] Matthew Finifter, Devdatta Akhawe, and David Wagner (2013). An empirical study of vulnerability rewards program. In 22nd USENIX Security Symposium (USENIXSecurity). USENIX Association.
[6] Aron Laszka, Mingyi Zhao, Akash Malbari, and Jens Grossklags (2018). The rules of engagement for bug bounty programs. In 22nd International Conference on Financial Cryptography and Data Security (FC). Springer.
[7] Kelsey R. Fulton, Samantha Katcher, Kevin Song, Marshini Chetty, Michelle L. Mazurek, Chloé Messdaghi, and Daniel Votipka (2023). Vulnerability discovery for all: Experiences of marginalization in vulnerability discovery. In To Appear in 32nd USENIX Security Symposium (USENIX Security). USENIX Association.
[8] Daniel Votipka, Seth Rabin, Kristopher Micinski, Jeffrey S. Foster, and Michelle L. Mazurek (2020). An observational investigation of reverse engineers’ processes. In 29th USENIX Security Symposium (USENIX Security). USENIX Association.
[9] Bozorgi, M., Saul, L., Savage, S., & Voelker, G. (2010). Beyond heuristics: Learning to classify vulnerabilities and predict exploits. In Proceedings of the 16th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining (KDD).
[10] Clark, S., Frei, S., Blaze, M., Smith, J. (2010). Familiarity breeds contempt: The honeymoon effect and the role of legacy code in zero-day vulnerabilities. In: Proceedings of the 26th Annual Computer Security Applications Conference (ACSAC). pp. 251–260
[11] Ozment, A. (2005). The likelihood of vulnerability rediscovery and the social utility of vulnerability hunting. In: Workshop on the Economics of Information Security (WEIS)
[12] Ozment, A., Schechter, S. (2006) Milk or wine: Does software security improve with age? In: USENIX Security Symposium
[13] Edmundson, A., Holtkamp, B., Rivera, E., Finifter, M., Mettler, A., Wagner, D. (2013). An empirical study on the effectiveness of security code review, In Engineering Secure Software and Systems
[14] Huang, K., Siegel, M., Madnick, S., Li, X., Feng, Z. (2016). Poster: Diversity or concentration? Hackers’ strategy for working across multiple bug bounty programs. In 37th IEEE Symposium on Security and Privacy (S&P)
[15] Maillart, T., Zhao, M., Grossklags, J., Chuang, J. (2017). Given enough eyeballs, all bugs are shallow? Revisiting Eric Raymond with bug bounty markets. Journal of Cyber security.
[16] Zhao, Grossklags, and Liu, (2016) “An empirical study of web vulnerability discovery ecosystems.” Hacker One, Improving Public Bug Bounty Programs with Signal Requirements, HackerOne Blog. https://hackerone.com/blog/signalrequirements
[17] The bug-bounty rules for Twitter on the Hacker One platform
How to cite this paper
@article{1707316,
author = {Feyisayo Mariam Yussuf},
title = {Conceiving Effective Rules for Bug-Bounty Platforms and Security Vulnerability Detection},
journal = {Iconic Research And Engineering Journals},
year = {2025},
volume = {8},
number = {9},
pages = {1-5},
issn = {2456-8880},
url = {https://www.irejournals.com/formatedpaper/1707316.pdf},
abstract = {In a world of rising security risks, legislation and standards for protecting existing IT information and data preservation are major concerns and costs. Security and data vulnerability concern every company. Ethical and unethical hackers find and report vulnerabilities to bug bounty sites for modern security. Organizations rely on white hats, but they must constantly assess risks and rewards. Concerned institutions adopt special regulations to control white hat activity wherever they are, imposing responsibility on the participating organization like bounty levies. The quantitative study established bug bounty platform standards for system security vulnerability detection. The research explored and suggested basic security vulnerability detection criteria to detect typical system flaws. The study proposed relevant security vulnerability detection rules.},
keywords = {White Hat; Ethical Hacker; Bug Bounty Platform.},
month = {March},
}