Software Vulnerability Markets¶
Al-Garni, A. M., & Malaiya, Y. K. (2014). Software Vulnerability Markets: Discoverers and Buyers. International Journal of Computer, Information Science and Engineering, 8(3), 71-81.
Cited by¶
1 citation across 1 artifact.
Each citation links to the sentence it supports in the citing article.
Primes¶
- Incentive
- In the bug bounty the target behaviour is responsible disclosure of security vulnerabilities; the decider is a security researcher weighing effort against payoff; the consequence is a cash reward; the channel is money, the schedule a threshold (severity tiers), the magnitude set above the researcher's outside option (including, ideally, the black-market price).
This sourceAnalyzes regulated, gray, and black vulnerability markets and shows black/gray markets pay far higher prices for zero-day exploits — establishing that an effective bug-bounty reward must exceed the researcher's outside option, including the black-market price.
- In the bug bounty the target behaviour is responsible disclosure of security vulnerabilities; the decider is a security researcher weighing effort against payoff; the consequence is a cash reward; the channel is money, the schedule a threshold (severity tiers), the magnitude set above the researcher's outside option (including, ideally, the black-market price).
Verification¶
This reference passed the adversarial substantiation pipeline: it was checked to exist and to support the claim it is attached to. See how references were verified.
Registry ID ref:631ad0c122a7 · see in the full table