Software Vulnerability Markets: Discoverers and Buyers
نویسنده
چکیده
Some of the key aspects of vulnerability—discovery, dissemination, and disclosure—have received some attention recently. However, the role of interaction among the vulnerability discoverers and vulnerability acquirers has not yet been adequately addressed. Our study suggests that a major percentage of discoverers, a majority in some cases, are unaffiliated with the software developers and thus are free to disseminate the vulnerabilities they discover in any way they like. As a result, multiple vulnerability markets have emerged. In some of these markets, the exchange is regulated, but in others, there is little or no regulation. In recent vulnerability discovery literature, the vulnerability discoverers have remained anonymous individuals. Although there has been an attempt to model the level of their efforts, information regarding their identities, modes of operation, and what they are doing with the discovered vulnerabilities has not been explored. Reports of buying and selling of the vulnerabilities are now appearing in the press; however, the existence of such markets requires validation, and the natures of the markets need to be analyzed. To address this need, we have attempted to collect detailed information. We have identified the most prolific vulnerability discoverers throughout the past decade and examined their motivation and methods. A large percentage of these discoverers are located in Eastern and Western Europe and in the Far East. We have contacted several of them in order to collect firsthand information regarding their techniques, motivations, and involvement in the vulnerability markets. We examine why many of the discoverers appear to retire after a highly successful vulnerability-finding career. The paper identifies the actual vulnerability markets, rather than the hypothetical ideal markets that are often examined. The emergence of worldwide government agencies as vulnerability buyers has significant implications. We discuss potential factors that can impact the risk to society and the need for detailed exploration. Keywords—Risk management, software security, vulnerability discoverers, vulnerability markets.
منابع مشابه
Using a Mixed Data Collection Strategy to Uncover Vulnerability Black Markets
Information security researchers hypothesize that black markets exist for the trading of software vulnerabilities and zero-day exploits. Such markets would encourage the development and exploitation of vulnerabilities through direct attack, malware spread or extortion. It is hard to assess the presence of vulnerability black markets and their associated transactions, as they are naturally hidde...
متن کاملMASFIT: Multi-Agent System for FIsh Trading
Traditional wholesale fresh fish markets carry out their sales by means of the Dutch auction protocol, with the buyers physically present in the market hall. In this paper we present the MultiAgent System for FIsh Trading (MASFIT) which allows buyers to participate remotely in several fish markets simultaneously with the help of software agents, while maintaining the traditional auction procedu...
متن کاملMASFIT: Multi-Agent System for Flsh Trading
Traditional wholesale fresh fish markets carry out their sales by means of the Dutch auction protocol, with the buyers physically present in the market hall. In this paper we present the MultiAgent System for FIsh Trading (MASFIT) which allows buyers to participate remotely in several fish markets simultaneously with the help of software agents, while maintaining the traditional auction procedu...
متن کاملA Quest for a Framework to Improve Software Security: Vulnerability Black Markets Scenario
The discovery and management of software vulnerabilities after a product is released to the public is an important element of improving software quality and stability. The discovery of vulnerabilities enables exploitation and stimulates the development of patches or other protections, which in turn may or may not be deployed by product users. Various approaches have been developed to facilitate...
متن کاملMASFIT: Multiagent system for fish trading
Traditional wholesale fresh fish markets carry out their sales by means of the Dutch auction protocol, with the buyers physically present in the market hall. In this paper we present the Multi-Agent System for FIsh Trading (MASFIT) wich allows buyers to participate remotely in several fish markets simultaneously with the help of software agents, while maintaining the traditional auction procedu...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2014