אסף שבתאי

אקדמי בכיר

Blockchain-based bug bounty framework

Lital Badash, Nachiket Tapas, Asaf Nadler, Francesco Longo, Asaf Shabtai

Bug bounty programs are a popular solution for security researchers to disclose software vulnerabilities in exchange for compensation. They suffer, however, from two main drawbacks that limit their effectiveness: (i) they use a trusted intermediary that charges hefty commission fees and may have a conflict of interest with the software vendor, and (ii) they may mistreat security researchers by compensating less than guaranteed and no means to appeal against it. In this paper, we propose a permissioned Blockchain-based framework that addresses the drawbacks of existing bug bounty programs. The framework allows a confidential exchange of vulnerabilities and compensations using smart contracts. In cases of policy violation, security researchers can appeal to a trusted group of security experts called arbitrators, that can force the software vendors to compensate the security researchers fairly. A formal evaluation of the proposed framework using TLA+ specification supports the viability of the proposal. A Hyperledger Fabric-based prototype is implemented to simulate the proposed framework. The analysis of the framework uses a game-theoretic notion to argue that if the majority of arbitrators behave honestly, then the rational strategy of software vendors is to compensate security researchers that disclose vulnerabilities accurately. Similarly, rational security researchers do not gain any financial profit by playing unfairly.

שפת פרסום אנגלית
דפים 239-248
סטטוס פרסום פורסם - 22.03.2021

Keywords

blockchain
bug bounty
software vulnerability

ASJC Scopus subject areas

Software
גישה למסמך
10.1145/3412841.3441906
קבצים וקישורים אחרים
Link to publication in Scopus