首页> 外文期刊>Information Polity: The International Journal of Government and Democracy in the Information Age >Crowdsourced cybersecurity innovation: The case of the Pentagon's vulnerability reward program
【24h】

Crowdsourced cybersecurity innovation: The case of the Pentagon's vulnerability reward program

机译:众群网络安全创新:五角大楼漏洞奖励计划的情况

获取原文
获取原文并翻译 | 示例
       

摘要

The U.S. federal government and its agencies face increasingly sophisticated and persistent cyberattacks from black hat hackers who breach cybersecurity for malicious purposes or for personal gain. With the rise of malicious attacks that caused untold financial damage and substantial reputational damage, private-sector high-tech firms such as Google, Microsoft and Yahoo adopted an innovative practice known as vulnerability reward program (VRP) or bug bounty program which crowdsources software bug detection from the cybersecurity community. In an alignment with the 2016 U.S. Cybersecurity National Action Plan, the Department of Defense adopted a pilot VRP in 2016. We use the Pentagon's VRP case to examine how it fits with the national cybersecurity policy. Our case study results show the feasibility of the government adoption and implementation of the innovative concept of VRP to enhance the government cybersecurity posture as well as the need to develop sophisticated cybersecurity policy and enhanced cybersecurity capability.
机译:美国联邦政府及其代理商面临来自黑帽黑客的越来越复杂的持续持续的网络攻击,他违反了恶意目的或个人利益的网络安全。随着恶意攻击的兴起,导致无国产性损害和实质性声誉损害,谷歌,微软和雅虎等私营部门的高科技公司采用了一个创新的惯例,称为漏洞奖励计划(VRP)或Bug Bounty计划,这些程序软件错误从网络安全社区检测。在与2016年美国网络安全国家行动计划的一致性中,辩护部于2016年通过了一项试点VRP。我们使用五角大楼的VRP案件来检查它如何与国家网络安全政策合作。我们的案例研究结果表明,政府通过和实施VRP创新概念的可行性,以加强政府网络安全姿势,以及有必要制定复杂的网络安全政策和提高的网络安全能力。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号