【24h】

Security Professional Skills Representation in Bug Bounty Programs and Processes

机译:安全专业技能表示在Bug赏金计划和流程中

获取原文

摘要

The ever-increasing amount of security vulnerabilities discovered and reported in recent years are significantly raising the concerns of organizations and businesses regarding the potential risks of data breaches and attacks that may affect their assets (e.g. the cases of Yahoo and Equifax). Consequently, organizations, particularly those suffering from these attacks are relying on the job of security professionals. Unfortunately, due to a wide range of cyber-attacks, the identification of such skilled security professional is a challenging task. One such reason is the "skill gap" problem, a mismatch between the security professionals' skills and the skills required for the job (vulnerability discovery in our case). In this work, we focus on platforms and processes for crowdsourced security vulnerability discovery (bug bounty programs) and present a framework for the representation of security professional skills. More specifically, we propose an embedding-based clustering approach that exploits multiple and rich information available across the web (e.g. job postings, vulnerability discovery reports) to translate the security professional skills into a set of relevant skills using clustering information in a semantic vector space. The effectiveness of this approach is demonstrated through experiments, and the results show that our approach works better than baseline solutions in selecting the appropriate security professionals.
机译:近年来发现和报告的不断增长的安全漏洞是大大提高了组织和企业对可能影响其资产的数据违规和袭击的潜在风险的关注(例如,雅虎和赤字的案件)。因此,组织,特别是那些遭受这些袭击的组织正在依靠安全专业人士的工作。不幸的是,由于各种网络攻击,识别如此熟练的安全专业人员是一个具有挑战性的任务。一个这样的原因是“技能差距”问题,安全专业人士的技能与工作所需的技能之间的不匹配(在我们的情况下漏洞发现)。在这项工作中,我们专注于众包安全漏洞发现的平台和流程(Bug Bounty程序),并为安全专业技能表示框架。更具体地说,我们提出了一种基于嵌入的聚类方法,该方法利用Web(例如职位发布,漏洞发现报告)的多个和丰富的信息,以将安全专业技能转化为使用语义矢量空间中的聚类信息转换为一组相关技能。通过实验证明了这种方法的有效性,结果表明,我们的方法在选择适当的安全专业人员时比基线解决方案更好。

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号