Our culture has become increasingly dependent on software for automation, productivity, and quality of life; the interconnectivity of nearly everything, market-labeled “the Internet of Things,” has only increased this dependency. The software that delivers these services exists on a wide variety of platforms from traditional computers to handhelds to game machines and even appliances such as alarm clocks. Application developers are driven to deliver increasingly complex innovative features and functionality faster. Today, system and software vulnerabilities are being revealed and exploited in those applications at a disastrous pace, and the need for identifying application layer vulnerabilities before the malicious user community does has become increasingly more dire. Bug bounty programs are a crowd-sourced collective with a large and potentially well-motivated force, they can be difficult to run and potentially empower the very bad actors they mean to prevent. There is no substitute for strong security by design and robust testing through a Systems Development Life Cycle (SDLC); together, these programs are essential to a safe Internet, offering more cyber security benefits than traditional testing, are more effective at uncovering security flaws quickly, and are generally less expensive.
These programs are crowd-sourced services that have been called “hacker bounty programs” and more recently are often referred to as “vulnerability rewards programs” (VRP); they essentially offer monetary rewards that can be taken advantage of by skilled developers and users for discovering vulnerabilities in the form of unwanted or unexpected features, or undesirable flaws and functionality. These flaws when left unaddressed, can be used to exploit the application, system, or user and may be used for nefarious purposes by cyber criminals. These programs encourage or require their customers, developers, and the general public to join their formalized program where they commit to reporting security vulnerabilities directly to the application developer’s organization or outsourced service, which are then reviewed by a dedicated technical team. This team will review, validate and determine rewards for the bounty hunter’s submission.
Bug bounty programs can compare to penetration tests (“pen tests”) which are scheduled events that require highly skilled resources to be dedicated for a set period of time. The teams tend to be a very small or outsourced creating resource reliance challenges, and the basis for a traditional penetration test is geared towards systemic or infrastructure vulnerabilities, only scratching the surface of application vulnerabilities. What can be missed are ways to manipulate the application within the parameters of a known good environment – business logic testing; this is where a bounty program excels at thwarting cyber-crime. Software has become increasingly complex and can be aided by the more innovative and flexible functional testing. Leveraging a wide variety of testing methodologies throughout the crowd-sourced community, applications benefit from different testers finding different problems as opposed to more traditional testing methods based on standard tools which cannot deliver the same security as a massive, multi-user collective of skilled testers.
Bug bounty programs tend to provide the same or better value with a generally less expensive net impact, and the positive revenue influence of cost avoidance, reclaimed productivity, and reputational integrity attributable to the rapid correction of preventable cyber-crime events are material. Bug bounties are only paid to submitted validated and previously undiscovered bugs. It is a cost-effective model, because firms only pay for validated vulnerabilities, and not for any time that was invested searching. Additionally, it allows firms to gain the benefits application vulnerability testing without maintaining staff or hiring consultants for the effort. To be effective, a transparent process for internal and crowd-sourced security testers is important; quick discovery is essential to minimize as much as can be minimized occurrences of security holes becoming released in the wild and publicly known. The flexibility of modern threats have increased both the percentage and total of zero-day attacks, attacks that exploit vulnerabilities before they are known to the software manufacturer or the protection services. The frequency of software exploits is so high and the composite skills and resources of the criminals are so vast, that it may be impossible to reliably produce code invulnerable to zero-day faults.
Application developers should ensure that their bounty programs offer competitive compensation for vulnerabilities found; more competitive than can be found on black markets. Also, the pool of bounty hunters should be sufficiently redundant to facilitate a population of skilled testers that would effectively counteract this and aid in fighting cybercrime; it is statistically likely that a significant and material weakness or vulnerability would be identified by multiple testers. A company should also ensure that there are sufficient processes to track code submissions and supply peer code reviews, that it should be relatively easy to find injected malicious code. Also, as with any program designed with security in mind, processes to verify and do background checks on all employees and contractors is imperative to any application development. Ultimately, it is better for an organization to have attackers target them in a structured and known way, trusting that the notion of responsible disclosure than to have unknown bad actors exploit weaknesses and not disclose them at all. Variable bounty prices can help off-set costs, but perhaps the best way for smaller companies to manage this is by using one of the major bug bounty providers such as Bugcrowd to defer and manage costs.
Organizations will still need to ensure that there is sufficient skilled staff dedicated to their vulnerability assessments to examine all of the reported vulnerabilities, validate findings, then determine and prioritize issues. A bug bounty program, regardless of its robustness, costs, or effectiveness can never replace an organizations formalized SDLC discipline; there is no substitute for the inherent benefits to those processes and rigor. The program will be most effective when it augments a robust security and vulnerability assessment program that spends the time and resources on internal security design and testing to build it initially with security by design; this will help alleviate the pressures felt by a team may that may become overwhelmed with findings.