Enrolling hackers into a market for cyber-vulnerabilities
Type
conference paper
Date Issued
2024-09-10
Author(s)
Abstract
Bug bounty platforms serve as intermediaries between companies and «ethical» hackers. They position themselves as a solution to the surge of cyber attacks that organizations are undergoing. As typical of digital platforms, they serve as marketplace organizers by bringing together supply and demand. On the one hand, they allow these hackers to responsibly disclose the vulnerabilities they find. And on the other hand, they help companies to reward them. This results in a market for vulnerabilities, in which companies must commodify their security and put a price on the work of hackers.
This situation thus a prime example of «self-vulnerabilization». Indeed, by networking the economy capitalism created the threats it is now attempting to remedy. This presentation will discuss the use of a market mechanism to solve a security concern through the lens of conventions theory. It will focus on two main «tests» that the authorities and the platform managers face in the implementation of this new market, and how conventions are mobilized in order to settle the tensions and
allow the market to operate.
First, corporations and public authorities must enroll a sufficiently large workforce into the market. Thus far, offensive hacking has been the turf of criminals and hacktivists. We will thus study how the ethic of hacking is shifting from anti-establishment activism to legitimate economic endeavor.
Second, some form of a reward scheme must be implemented in order to build a labor market. Competencies are difficult to assess in this market, as there are no formal qualifications for offensive hacking. For this reason, the platforms organize contests and put a price on the vulnerabilities that hackers find. As we will see, this implies that actors must agree on novel standards for measuring cyber risk.
This study draws from interviews with hackers, platform managers, and CISO (chief information security officers) taking part in this market.
This situation thus a prime example of «self-vulnerabilization». Indeed, by networking the economy capitalism created the threats it is now attempting to remedy. This presentation will discuss the use of a market mechanism to solve a security concern through the lens of conventions theory. It will focus on two main «tests» that the authorities and the platform managers face in the implementation of this new market, and how conventions are mobilized in order to settle the tensions and
allow the market to operate.
First, corporations and public authorities must enroll a sufficiently large workforce into the market. Thus far, offensive hacking has been the turf of criminals and hacktivists. We will thus study how the ethic of hacking is shifting from anti-establishment activism to legitimate economic endeavor.
Second, some form of a reward scheme must be implemented in order to build a labor market. Competencies are difficult to assess in this market, as there are no formal qualifications for offensive hacking. For this reason, the platforms organize contests and put a price on the vulnerabilities that hackers find. As we will see, this implies that actors must agree on novel standards for measuring cyber risk.
This study draws from interviews with hackers, platform managers, and CISO (chief information security officers) taking part in this market.
Language
English
Event Title
Congress of the Swiss Sociological Association
Event Location
Basel
Event Date
2024