首页> 外文会议>ACM / IEEE International Symposium on Empirical Software Engineering and Measurement >Understanding the Heterogeneity of Contributors in Bug Bounty Programs
【24h】

Understanding the Heterogeneity of Contributors in Bug Bounty Programs

机译:了解漏洞赏金计划中贡献者的异质性

获取原文

摘要

Background: While bug bounty programs are not new in software development, an increasing number of companies, as well as open source projects, rely on external parties to perform the security assessment of their software for reward. However, there is relatively little empirical knowledge about the characteristics of bug bounty program contributors. Aim: This paper aims to understand those contributors by highlighting the heterogeneity among them. Method: We analyzed the histories of 82 bug bounty programs and 2,504 distinct bug bounty contributors, and conducted a quantitative and qualitative survey. Results: We found that there are project-specific and non-specific contributors who have different motivations for contributing to the products and organizations. Conclusions: Our findings provide insights to make bug bounty programs better and for further studies of new software development roles.
机译:背景:尽管漏洞赏金计划在软件开发中并不陌生,但越来越多的公司以及开源项目都依赖外部方对其软件进行安全评估以获取回报。但是,关于漏洞赏金计划贡献者的特征的经验知识相对较少。目的:本文旨在通过突出贡献者之间的异质性来了解它们。方法:我们分析了82个错误赏金计划和2,504个不同的错误赏金贡献者的历史,并进行了定量和定性的调查。结果:我们发现,有针对特定项目的贡献者和针对特定项目的贡献者,其为产品和组织做出贡献的动机不同。结论:我们的发现为改进漏洞赏金计划以及进一步研究新软件开发角色提供了见识。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号