scieee AI-readable full text Open interactive document viewer

Navigating vulnerability markets and bug bounty programs: A public policy perspective

Zrahia, Aviram

Abstract

EconStor is a publication server for scholarly economic literature, provided as a non-commercial public service by the ZBW.

Full text

Zrahia, Aviram Article Navigating vulnerability markets and bug bounty programs: A public policy perspective Internet Policy Review Provided in Cooperation with: Alexander von Humboldt Institute for Internet and Society (HIIG), Berlin Suggested Citation: Zrahia, Aviram (2024) : Navigating vulnerability markets and bug bounty programs: A public policy perspective, Internet Policy Review, ISSN 2197-6775, Alexander von Humboldt Institute for Internet and Society, Berlin, Vol. 13, Iss. 1, pp. 1-30, https://doi.org/10.14763/2024.1.1740 This Version is available at: https://hdl.handle.net/10419/285315 Standard-Nutzungsbedingungen: Die Dokumente auf EconStor dürfen zu eigenen wissenschaftlichen Zwecken und zum Privatgebrauch gespeichert und kopiert werden. Sie dürfen die Dokumente nicht für öffentliche oder kommerzielle Zwecke vervielfältigen, öffentlich ausstellen, öffentlich zugänglich machen, vertreiben oder anderweitig nutzen. Sofern die Verfasser die Dokumente unter Open-Content-Lizenzen (insbesondere CC-Lizenzen) zur Verfügung gestellt haben sollten, gelten abweichend von diesen Nutzungsbedingungen die in der dort genannten Lizenz gewährten Nutzungsrechte. Terms of use: Documents in EconStor may be saved and copied for your personal and scholarly purposes. You are not to copy documents for public or commercial purposes, to exhibit the documents publicly, to make them publicly available on the internet, or to distribute or otherwise use the documents in public. If the documents have been made available under an Open Content Licence (especially Creative Commons Licences), you may exercise further usage rights as specified in the indicated licence. https://creativecommons.org/licenses/by/3.0/de/legalcode Volume 13 | Navigating vulnerability markets and bug bounty programs: A public policy perspective Aviram Zrahia Tel Aviv University DOI: https://doi.org/10.14763/2024.1.1740 Published: 15 February 2024 Received: 5 October 2023 Accepted: 6 December 2023 Competing Interests: The author has declared that no competing interests exist that have influenced the text. Licence: This is an open-access article distributed under the terms of the Creative Commons Attribution 3.0 License (Germany) which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited. https://creativecommons.org/licenses/by/3.0/de/deed.en Copyright remains with the author(s). Citation: Zrahia, A. (2024). Navigating vulnerability markets and bug bounty programs: A public policy perspective. Internet Policy Review, 13(1). https://doi.org/10.14763/ 2024.1.1740 Keywords: Cybersecurity policy, Bug bounty programs, Economics of vulnerabilities, Digital market, Vulnerability sharing Abstract: As societies become increasingly dependent on digital means, organisations seek ways to prevent software exploitation by eliminating vulnerabilities or acquiring them as products. However, there is an ongoing debate regarding the extent to which governments should become involved in markets for vulnerability sharing. This paper examines the economics of vulnerabilities and outlines possible areas for governmental interventions. I survey three policy alternatives to support the discovery and disclosure of software vulnerabilities: integrating security and penetration testing into the software development life cycle, acquiring exploitable critical vulnerabilities by governments, and promoting bug bounty programs and platforms as vulnerability-sharing structures. For each suggested alternative, I present an impact matrix to qualitatively measure the effectiveness and efficiency of the vulnerability discovery process and the attractiveness, legality and trustworthiness of the disclosure process. I argue that bug bounty programs that bring together organisations and ethical hackers to trade vulnerabilities produce the highest impact. These gig economy structures are often based on two-sided digital market platforms as their foundation and offer a low entry barrier and assurance level for both market players. The discussion provides a foundation for governmental decision-makers to design effective policies for sharing vulnerabilities. Issue 1 1. Introduction Cyber threats emerge as a severe problem for the global economy as society increasingly depends on information technology for all its functions (World Economic Forum, 2023). The actions of offenders can have far-reaching consequences, affecting the financial, social and health well-being of individuals, organisations and nations. Consequently, policymakers have recognised the need to protect citizens and firms against cyber threats, leading to a growing trend in designing, adopting and implementing cybersecurity-related governmental policies. According to Ankit Fadia et al. (2020), more than 100 governments have developed national cybersecurity defence strategies, and some have also established dedicated National Cybersecurity Agencies (NCAs) to help protect the public against cybersecurity attacks, theft, fraud and abuse.1 There are various methods that cyber attackers can use; however, exploiting software vulnerabilities (bugs) remains a significant attack vector (Cyber Attacks Statistics, n.d.). Common ways to prevent software exploitation before such an attack attempt is made are eliminating vulnerabilities during coding and proactively discovering and fixing them in existing products and services. Leveraging third-party crowd wisdom can make it easier to detect vulnerabilities; I hereafter refer to these vulnerabilities as the product and their trading activity as the market for vulnerabilities. This article examines the following public policy problem: How should governments become involved in vulnerability-sharing markets? I further focus on the research question: How can policymakers support discovering and disclosing software vulnerabilities in systems, products and services? To address this question, I survey three areas of possible intervention. The first, sometimes called security-bydesign, aims to prevent vulnerabilities introduced during development by integrating security into the software development life cycle (SDLC), and it may involve penetration tests executed by internal or contractor teams. The second aims to reduce the number of high-impact exploits in the black market by acquiring highly exploitable critical vulnerabilities directly or through an intermediary entity. The third is promoting bug bounty programs and platforms as mediation entities between individual security researchers and firms. The expected outcome of this alternative is an increased number and quality of software vulnerabilities discovered by the ethical hacker community and disclosed to the public so that they can de1. Examples include the National Cyber Security Centre (NCSC) in the UK, and the Cybersecurity and Infrastructure Security Agency (CISA) in the US. 2 Internet Policy Review 13(1) | 2024 fend against them. Using a simplified rationalist policy analysis process, I identify two primary goals for the proposed alternatives, which align with the research question. The first goal is to enhance the efficient discovery of vulnerabilities in products and systems, while the second aims to support a legal and trustworthy vulnerability disclosure process. I qualitatively assess three impact categories for each goal to evaluate the suggested policies before presenting the results in a comparative impact matrix. My informed interpretation indicates that bounty programs and platforms are effective and have low barriers to entry for firms and the ethical hacker community. Therefore, I recommend increased governmental intervention by promoting or requiring these structures based on commercial or community-driven coordinated disclosure initiatives. While I have identified a preferred policy, it is essential to note that the discussed options are not mutually exclusive and can be implemented in parallel, as acknowledged by ENISA (2023). The paper aims to provide a starting point for policymakers yet to engage in this area by listing possible intervention alternatives and justifying additional investments for governments already active in the market for vulnerabilities. This article proceeds as follows: Section 2 discusses the dynamics of markets for vulnerabilities and bug bounty programs and lists examples of governmental intervention. Section 3 presents the policy design methodology and highlights some of my considerations. Section 4 describes the problem definition, lists related policy design issues and introduces the evaluated governmental policies. Next, Section 5 compares the solution alternatives, their expected outcomes and the associated trade-offs. Finally, Section 6 concludes the discussion and summarises its main implications and limitations. 2. Background: sharing software vulnerabilities Cyber-related risks are growing and have become one of the most severe global economic risks the world may face over the next decade (World Economic Forum, 2023). Organisational stakeholders can address these risks in various ways, including avoidance, acceptance, mitigation and transfer (Martin-Vegue, 2021). One approach to mitigate the cyber risks associated with software exploitation is to identify and address security vulnerabilities before they are exploited. This approach is aligned with the “identify” and “protect” risk mitigation stages of the Cybersecurity Framework offered by NIST (2018). Discovering vulnerabilities in products and ser3 Zrahia vices can be assigned to the firm’s development or security-testing teams, outsourced to third-party company experts, or delegated to external individual researchers through bug bounty programs in a trend that aligns with the novel idea of crowdsourcing (Akgul et al., 2020). Reviewing government interventions in cybersecurity and the background and dynamics of the vulnerability-sharing problem domain is required to understand this market development better. 2.1. Government intervention in cybersecurity In recent years, governments have established agencies dedicated to protecting their assets and citizens against cyber threats. This task often mandates defining new policies or regulations. Still, progress in mitigating cyber risks is challenging, possibly due to conflicting equities, negative externalities, trade-offs between civil liberties, privacy concerns and more (National Research Council, 2014). The policy alternatives presented in this paper illustrate this challenge. Governmental intervention in cybersecurity is expected to increase in the coming years as cyber protection becomes a regulatory obligation in many sectors. Governments may increase their direct operational involvement in areas considered national priorities, such as Critical Infrastructure Protection (CIP) or Computer Emergency Readiness Team (CERT).2 Consequently, they can promote regulations that will hold the private sector liable. For example, the US aims to shift the responsibility and liability for cybersecurity away from individuals, small businesses and local governments and onto the organisations providing products and services (The White House, 2023). Similarly, the EU promotes in its NIS2 Directive legal measures on operators of essential services in specific sectors if they fail to take appropriate security measures or follow incident notification rules (Directive 2022/ 2555, 2022). Governments and policymakers have long recognised the importance of cybersecurity information sharing as a collaborative effort to enhance cyber-defence (or -adversary) posture by leveraging the broader community’s capabilities, knowledge and experience (Zrahia, 2018).3 The shared information might include threat-centric indicators/objects, best practices and tools and target-related data objects, 2. For example, the US’s 2013 National Infrastructure Protection Plan (CISA, 2013) and the United States Computer Emergency Readiness Team (US-CERT, n.d.). 3. An individual hacker stopped the global WannaCry ransomware attack in 2017, showcasing the power of the community (MalwareTech, 2017). 4 Internet Policy Review 13(1) | 2024 namely software vulnerabilities (Libicki, 2015). This paper concentrates on the latter information type. 2.2. The economics of vulnerabilities A software vulnerability is “a security flaw, glitch, or weakness found in software code” that an attacker could exploit (NIST-CSRC, n.d.). Identifying and fixing software vulnerabilities, commonly known as the vulnerability life cycle, typically begins with the (unintentional) creation of a bug during the coding phase. Unfortunately, an attacker may find and exploit the vulnerability before it is disclosed and a patch developed, resulting in a zero-day (0-day) exploit. However, once the vulnerability is detected and identified by the development team or a security researcher, efforts are prioritised to create and issue a software patch to eliminate the exposure (Bilge & Dumitras, 2012). Extensive research has been conducted on the vulnerability life cycle, including comprehensive overviews by Shahzad et al. (2012) and categorisations of preand post-disclosure risk by Rajasooriya et al. (2016). In addition, Ransbotham et al. (2012) summarise the primary pathways to vulnerability disclosure. Vulnerabilities for sale may be considered a product of the “knowledge economy” created by knowledge-intensive activities and characterised by rapid obsolescence (Powell & Snellman, 2004, p. 199). Furthermore, like other knowledge or data objects, vulnerabilities are non-rival goods that can be used by several parties concurrently. The market for vulnerabilities as products can be described using microeconomics terminology, where organisations generate demand and security professionals supply their expertise and find them. From a supply chain standpoint, finding a vulnerability may be considered a make-or-buy management decision. Williamson (2008) outlines three governance decisions a company may encounter while assessing Transaction Cost Economics (TCE): markets, hybrids and hierarchies. In light of this definition, companies can meet the demand for vulnerabilities with their development and security personnel utilising internal hierarchies. Alternatively, they could use hybrid long-term contracting of specialised companies or embrace a market strategy with skilled individual security researchers with no bilateral stakeholder dependency. I embrace the view of Ablon & Libicki (2015) and divide the vulnerability market into three categories: legitimate (white), illegal (black) and legal but anonymous (grey).4 In the white market, buyers and sellers are identified and may legally trade 4. The terms “white”, “grey” and “black” are the standard naming of these markets in the cyber world. 5 Zrahia vulnerabilities so vendors can fix them. The underground black market is where cybercrime organisations buy exploits, attack services, stolen assets and other illegal products from black-hat hackers. The grey market facilitates the exchange of vulnerabilities and exploits that might be used for offensive purposes. While this market is not illegal per se, it operates in a moral and ethical grey area due to the potential for harm associated with undisclosed vulnerabilities. The analysis requires an understanding of the way the value of a vulnerability changes depending on its life-cycle stage and traded market (Figure 1). A zero-day vulnerability may be valued at six or more figures in the white and black markets (Apple Security Bounty Categories, n.d.; Perlroth, 2021), but its price declines differently over time. In the white market, disclosed vulnerabilities are shared as public goods for free, so their value drops to zero once the vendor releases a patch and they become public goods. In contrast, in the black market, the exploit code has a monetary value even after N-days due to product exclusivity. Regardless, its value drops over time as the likelihood of finding and exploiting a non-patched system decreases. FIGURE 1: Vulnerability as a product value matrix in black and white markets. 2.3. Bug bounty programs and platforms The claim dubbed ‘Linus law’, that “given enough eyeballs, all bugs are shallow” (Raymond, 1999, p. 29) refers to the co-development and testing of open-source software involving many people who deliver a less buggy (and therefore less vulnerable) code together. A similar principle may apply to bug bounty programs util6 Internet Policy Review 13(1) | 2024 ising crowdsourced vulnerability discovery. From an organisational perspective, effectively identifying vulnerabilities is a high-value challenge, so firms can benefit from engaging large crowds of researchers to tackle this task. This choice aligns with theories of firm boundaries, which involve deciding which assets, activities and resources to “own” and which to access through the market (Zenger et al., 2011, p. 95). Bug bounty programs are structured arrangements between organisations and individual security researchers to trade vulnerabilities as products. They allow organisations to interact with cyber-security experts whose knowledge complements the capabilities of the firm’s development and testing teams. Through this exchange, security researchers can report on security vulnerabilities and receive legitimate compensation for their findings and recognition from their peers and the industry for their expertise (Bienz & Juranek, 2020; Malladi & Subramanian, 2020). Bug bounty platforms are two-sided digital marketplaces that host multiple bug bounty programs, bringing together security researchers and organisations to facilitate vulnerability trading (Maillart et al., 2017; Subramanian & Malladi, 2020; Wachs, 2022; Zhao et al., 2017). These platforms reward the first participant submitting a novel vulnerability report with a direct or indirect payment (bounty), creating a tournament-like arrangement (Jo, 2020). Using these platforms reduces information asymmetries and other frictional costs associated with the transaction of specific, infrequent, and uncertain assets (Wachs, 2022). Figure 2 illustrates the role of a bug bounty platform as a facilitator for the vulnerability-sharing transaction between organisations as buyers and researchers as sellers. FIGURE 2: A bug bounty platform as a two-sided market for sharing software vulnerabilities. Bug bounty programs can be viewed as a competitive economy model where buyers and sellers attempt to maximise their utility and profits. The individual re7 Zrahia searchers are the sellers, the organisations generating the bounty programs are the buyers and the discovered vulnerabilities are the goods.5 These structures are also related to the phenomenon of the gig economy: a labour market for independent contracting that happens through, via and on digital platforms (James, 2021). In this setting, a vulnerability report constitutes a mere gig economy transaction with a low entry barrier, potentially allowing policymakers to control the supply size (Zrahia et al., 2022). 3. Policy design methodology Policy analysis involves explaining problems related to the general public and developing alternatives to address them and mitigate their failures. I followed the simplified rationalist process of Weimer & Vining (2017) by dividing the effort into two main components. Section 4 focused on problem analysis, which includes defining the problem, listing potential solutions and setting policy goals. In Section 5, I conducted a solution analysis, further expanding on the policy options while predicting, evaluating and comparing their impacts. I began the problem analysis with the research question: How can policymakers support discovering and disclosing software vulnerabilities in systems, products and services? Next, I argued that the problem is a societal concern that justifies governmental intervention, and I listed the three evaluated solutions. Finally, I briefly described how each alternative would help and its expected outcome. I selected two goals, viewing the first as “substantive” and the second as “procedural” (Bali et al., 2021). The impacts associated with the substantive goal are directly concerned with the ends of the policy, while the results related to the procedural goal, indirectly but significantly, affect processes and outcomes accounting for the means to achieve the policy ends. Furthermore, I set the goals so that each represents a different stage in the vulnerability-sharing process (discovery and disclosure) and a different stakeholder perspective in the market for vulnerabilities — the first goal was associated with the buyer (organisation) perspective, while the second pertained to the seller (researcher). I detailed the three policy alternatives in the solution analysis stage, referencing relevant academic literature and professional resources. To measure the impact of each policy on each goal, I used qualitative scoring criteria of three levels: low, medium and high. These categories are not necessarily equally spaced, and I used ranges within these classes where appropriate. I presented the results in a com5. This viewpoint refers to the market after a researcher finds a vulnerability (ex-post). 8 Internet Policy Review 13(1) | 2024 Governments not already participating in zero-day markets may consider setting goals and establishing evaluation processes, while those already involved may consider increasing their involvement. Reducing the number of available zero days would reduce the number of cyber-criminals and the state programs that depend on them (Maurer, 2017). However, this depends on whether policymakers want to “drain the swamp” of vulnerabilities or use them for offence. 5.1.3. Support bug bounty programs and platforms In recent years, internet governance and digital platform regulation have become hot topics for scholars and practitioners (Epstein et al., 2016; Flew & Martin, 2022; Fuster Morell, 2022). This involvement expands beyond social networks and commodity markets into two-sided markets for vulnerabilities. In this alternative, governments may encourage or enforce vulnerability disclosure programs (VDPs) or bug bounty programs (BBPs) in specific vertical segments. The first program type allows researchers to safely submit their reports to organisations without receiving cash rewards, and the latter offers monetary awards for unique (unknown) valid discoveries (Walshe & Simpson, 2022). Various national-level initiatives have been implemented to facilitate coordinated vulnerability disclosure (CVD) policies. Examples include the US requirement from federal agencies (BOD 20-01: Develop and Publish a Vulnerability Disclosure Policy, 2020), the EU’s CVD policy (ENISA, 2022) and the UK’s vulnerability disclosure toolkit (The National Cyber Security Centre, 2020). These initiatives are often based on commercial bug bounty platforms that outline discovery and disclosure procedures as part of their program’s scope and code of conduct.11 Organisations operating bug bounty programs often fail to convey all the formal constraints applicable to hackers, requiring them to understand the laws underpinning safe and legal security research (Walshe & Simpson, 2023). Crowdsourcing security as a service through bug bounty platforms can enable this process safely and legally. Choi et al. (2010) found bug bounty programs to be a welfare-improving policy instrument since they either do not affect the firm’s disclosure policy or facilitate a change from non-disclosure to disclosure. Alternatively, governments can support community-driven vulnerability disclosure projects such as Disclose.io, which aims to make vulnerability disclosure safe, simple and standardised for everyone.12 11. For example, CISA (the US initiative) uses BugCrowd and EnDyna as their bug bounty platform provider (Goldstein, 2021), while the UK uses HackerOne (Ministry of Defence, 2020). 12. The project provides a comprehensive list of known bug bounty and vulnerability disclosure pro15 Zrahia In addition, bug bounties promote public transparency by facilitating the disclosure process to the public. When ethical security researchers discover vulnerabilities, they can reveal them through full or coordinated vulnerability disclosure methods (Maillart et al., 2017). Full disclosure pressures software owners to fix the issue immediately, as it involves alerting the public directly. Coordinated vulnerability disclosure, on the other hand, allows vendors to address the vulnerability before sharing the details publicly. The optimal disclosure approach remains a topic of debate (Arora & Rahul, 2005; Choi et al., 2010). However, not all vulnerabilities are disclosed or shared with the public during black or grey market transactions (Ablon & Libicki, 2015; McKinney, 2007). A viable governmental intervention policy may legally enforce bug bounty programs on specific industry verticals (Zhao et al., 2017), establish joint initiatives with existing bug bounty platforms or support vulnerability-sharing community efforts. 5.2. Policy impacts analysis In the upcoming sections, the policy goals and their associated impact categories will be qualitatively assessed for each solution alternative, with justifications for the analysis. 5.2.1.Evaluating effective and efficient discovery of vulnerabilities The substantive goal of an effective and efficient vulnerability discovery is aligned with the organisational interests, and the success of a policy in meeting it can be measured by the number and quality of unique vulnerabilities discovered, as well as its economic efficiency. I reflect on insights from the open-source literature and argue that the number of unique discovered vulnerabilities depends on the number of researchers, their expertise and their access level to the product or service (Schryen & Kadura, 2009). In-depth vulnerability research is made possible with code-level access rather than treating the system as a black box (McGraw, 2004). Although secure SDLC policies allow for thorough penetration testing, I argue that the number of discovered vulnerabilities may depend on a limited number of security experts compared to the potentially large crowd of individual researchers accessible through bug bounty programs and platforms (Maillart et al., 2017). Hence, I anticipate a moderate number of vulnerabilities to be discovered. Acquiring zero-day vulnerabilities is a grams, detailing where to submit reports and their respective “safe harbour” status. 16 Internet Policy Review 13(1) | 2024 strategy typically reserved for selected, highly exploitable cases, a subset of the limited supply of these vulnerabilities (Maurer, 2017). Bug bounty programs can lead to the discovery of a moderate to high number of vulnerabilities (Walshe & Simpson, 2020; Zrahia et al., 2022), depending on the program’s rules, incentive structure and degree of openness. The latter refers to the choice between a program that is available to everyone (public) or only to a group of researchers (private) who may be pre-selected and possibly granted elevated access rights to research the product or service (Wachs, 2022). The second impact category I evaluate is the quality of discovered vulnerabilities, which, similarly to the quantity, is affected by the researchers’ expertise and access level. Therefore, I argue that software development and penetration test teams, granted elevated access rights, can find medium-high severity vulnerabilities. Zeroday vulnerabilities traded on the grey market are often of exceptionally high quality due to their exploitable nature (Meakins, 2019). In contrast, the quality of submissions to bug bounty programs can vary between low and high (Walshe & Simpson, 2020; Zrahia et al., 2022), depending on the program’s characteristics and tournament structure, facilitating competition among researchers. Finally, assessing the economic efficiency aspect of a vulnerability discovery policy requires a consideration of its costs and benefits. Secure SDLC and penetration tests are typically paid for by contract according to an agreed Scope of Work (SOW) rather than performance-based payment (Engin, 2023). Hence, I mark its effectiveness level as a medium. By contrast, the cost of purchasing a single zero-day to governments may be extremely high, depending on the vulnerability’s severity, the exploit’s complexity and how long the vulnerability remains undisclosed (Ablon & Libicki, 2015). The latter factor reflects whether the product (the zero-day vulnerability) is a private good, defined by rivalry in consumption and excludability in ownership and use (Weimer & Vining, 2017). Disclosing the vulnerability to the public or other buyers may affect the cost-effectiveness of this policy option if the designated use of the purchased exploit is offensive. Therefore, the impact category for buying zero-day vulnerabilities may vary between medium and high, assuming the governmental goal is defensive. The economic efficiency of bug bounty programs can be measured using the unique-to-total submission ratio,13 which considers the effort and cost of processing duplicate or incorrect vulnerability reports (Zrahia et al., 2022).14 Though invalid reports may significantly burden par13. The unique-to-total submission ratio represents the percentage of unique vulnerabilities found out of the total number of submitted reports. 14. Duplicate submission is a discovery of a vulnerability already known or identified by another re17 Zrahia ticipating organisations (Zhao et al., 2017), there are ways to reduce them by limiting access to the program, changing the rewards structure and more. Therefore, the economic efficiency of bug bounty programs that embrace performance-based payments might be considered medium-high. 5.2.2.Evaluating the disclosure process The procedural goal of establishing an attractive, legal and trustworthy disclosure process pertains to researchers discovering vulnerabilities more than the organisations acquiring them. The first impact category I suggest for measuring this goal is the ease of reporting which also reflects its barriers to entry. Under the secure SDLC and penetration testing policy the internal workforce or contractors can report vulnerabilities promptly and effectively to the organisation. However, as acknowledged by Çetin et al. (2018), implementing this option requires resource investments and expertise which may challenge small organisations, resulting in a medium barrier to entry. Reporting and barriers to entry are notably more difficult in the grey market for zero-day vulnerabilities, as researchers may lack the necessary connections to sell directly to governments. Hence, introducing an intermediary may facilitate a reporting procedure while preserving anonymity for both parties. Bug bounty programs and platforms in the regulated white market have a more straightforward reporting process based on their predefined scope and rules of engagement.15 Furthermore, these platforms have relatively low entry barriers since they support a simple registration process for both market players and may allow anyone to submit vulnerability reports. The second impact measures whether the disclosure process protects the researcher from legal consequences. The SOW for outsourced penetration testing should include clauses that provide legal protection for security researchers. Similarly, the SDLC development process inherently protects employees when fixing bugs. In the grey market policy, researchers selling a zero-day to a government may prefer to remain anonymous and use an intermediary to avoid revealing their identity to the buyer. Moreover, the buying government often wants to maintain the same level of anonymity (Annu-Essuman, 2014). By contrast, bug bounty programs and platforms should include clear disclosure guidance and often support full or partial safe harbour policies to encourage reporting.16 searcher. Therefore, it has no value to the vendor (or even negative value considering the costs associated with processing it). 15. For example, Bugcrowd’s reporting process (Bugcrowd, n.d.). 16. For example, Microsoft’s safe harbour policy (Microsoft, n.d.). 18 Internet Policy Review 13(1) | 2024 The last impact analysed is a trustworthy and attractive model. Trust between buyers and sellers is associated with better exchange performance, lower transaction costs and enhanced knowledge transfer (Poppo et al., 2016). In the vulnerability market, sellers face an additional challenge related to trust: they must prove the authenticity of the vulnerability without revealing it to the buyer. Internal or external organisational teams involved in secure SDLC and penetration tests get paid by contract, making trust a non-issue and the attractiveness of the transaction negotiable. However, trust is a real challenge to both sides when selling zero-days to governments directly or through a grey market broker. Researchers may require anonymised cryptocurrency payments and assurance that they will be fulfilled. On the other hand, buyers who want to obtain a zero-day for offensive purposes need exclusive access and non-disclosure commitments to maintain its value. Therefore, using intermediaries may add trust validation and verification to the transaction as Ablon & Libicki (2015) noted. Similarly, trust is critical in the white vulnerability-sharing market where bug bounty programs and platforms facilitate interactions between two entities that may not have any preexisting relationship or history of interaction. Platform intermediaries can reduce the risk for both parties by ensuring mutually beneficial terms and conditions for disclosure and participation (Subramanian & Malladi, 2020). A coordinated vulnerability disclosure process grants the vendor the necessary time to apply a patch before sharing the vulnerability with the public. No exclusivity risk exists if the organisation intends to fix the issue and notify the public. Vendors usually complete their payments to researchers to maintain their reputation. However, a two-sided bug bounty platform can reduce the risk of unrelieved contractual hazards and add trust and assurance to timely payments. 5.2.3. Comparative impact matrix The comparative impact matrix presented in Table 3 summarises the predicted impact of each alternative on the two defined goals. 19 Zrahia TABLE 3: Impact evaluation of policy options for governmental intervention related to sharing vulnerabilities IMPACT CATEGORY POLICY ALTERNATIVES Encourage secure development and penetration tests Acquire zero-day vulnerabilities Support bug bounty programs and platforms GOAL I: EFFECTIVE AND EFFICIENT DISCOVERY OF VULNERABILITIES NUMBER OF UNIQUE DISCOVERED VULNERABILITIES Medium, given the trade-off between thorough testing and the number of security researchers Low, as only zero-day vulnerabilities are potentially purchased Medium-high, depending on the program’s characteristics QUALITY OF DISCOVERED VULNERABILITIES Medium-high, based on the defined scope, access level and expertise of the testing team High, as it pertains to zero-day critical vulnerabilities only Varies between low and high, based on the program’s characteristics ECONOMIC EFFICIENCY IN PRODUCTION Medium, as the penetration task paid regardless of the findings Varies between medium to high and affected by exclusivity risk and extreme prices of premium vulnerabilities Medium-high, taking into consideration the validto-total submission ratio GOAL II: AN ATTRACTIVE, LEGAL AND TRUSTWORTHY DISCLOSURE PROCESS EASE OF REPORTING AND BARRIERS TO ENTRY High (easy reporting), as defined in the scope of work of the internal workforce or contractors Low (complicated reporting), unless made through a third party, grey market broker High (easy reporting), based on the intermediary platform tools and procedures LEGALLY SAFE DISCLOSURE High (legally safe) as defined explicitly in the scope of work for penetration tests and inherent to the SDLC process Medium, due to the risks associated with grey market transactions High (legally safe), based on the bounty program’s full or partial safe harbour policy TRUSTWORTHY AND ATTRACTIVE MODEL Highly reliable payment per contact Low-medium reliability for both sides, as payments might be conditional and exclusivity questionable Payment is highly reliable as defined in the program’s scope and platform rules 5.2.4. Trade-offs, tensions and misalignments This section highlights potential areas of misalignment among different market 20 Internet Policy Review 13(1) | 2024 players or policymakers related to the goals and impact categories. These conflicts may generate market failures, suggesting that public policy oversight is essential. Firstly, I consider the trade-off vendors face between the quantity and quality of discovered vulnerabilities. It is widely accepted that finding high-severity vulnerabilities requires more expertise and is therefore less common than finding lowquality ones. Additionally, the access level of researchers to the code can impact their ability to find bugs (Schryen & Kadura, 2009). While more researchers testing the code increase the number of discovered vulnerabilities (Maillart et al., 2017), high volumes of low-quality reports can burden operators and consume resources (Walshe & Simpson, 2022). Furthermore, contests can encourage innovation, but admitting more competitors can create tension between innovation and incentives for all players (Terwiesch & Xu, 2008). While having more competitors may stimulate innovation by a higher likelihood that at least one agent will find a highly valued solution, it can also reduce the expected reward of researchers and their incentive to report vulnerabilities. Additionally, attracting high-quality researchers and finding high-severity bugs is becoming more difficult as the program matures, hence the recommendation to increase rewards over time (McCracken, 2019). In light of these issues, I argue that organisations could evaluate their strategy over time and rebalance the number of security researchers and their access level to the code with bug bounty platforms potentially helping match researchers with relevant expertise to specific programs (Kestelyn & Bugcrowd Head of Product Marketing, 2022). Next, I consider the offensive versus defensive use of zero-day vulnerabilities by governments operating in the grey market. The value of a zero-day primarily depends on its scarcity and secrecy (Meakins, 2019). While buying vulnerabilities may be cost-effective if shared with the public some governments may prefer to keep them private for offensive use. Under the latter scenario, they risk losing exclusivity to the vulnerability. If that happens, its value will decline or completely diminish once patched. The governmental decision to keep or reveal a vulnerability may also depend on the geopolitical circumstances. Furthermore, a concern associated with this alternative is whether the government can be trusted to implement it for the benefit of the general public. The Electronic Privacy Information Center (EPIC) criticises the Vulnerabilities Equities Policy of the US mentioned earlier for lack of transparency, privacy implications, and more (The Electronic Privacy Information Center, n.d.). Security researchers may need to balance the expected reward from a vulnerability discovery and the consequences of illegal, immoral or unethical submission to the black or grey markets. These markets might pay ten times (or more) 21 Zrahia higher than the white market would pay, so a researcher who finds a zero-day faces a significant dilemma (Ablon & Libicki, 2015). The procedural goal of facilitating an attractive, legal and trustworthy disclosure process aims to balance this tension and solicit white market transactions. Another aspect to consider is the applicability of the alternatives in a diverse socio-economic context. The evaluated policies require cooperation with private organisations and the general public and may be affected by different scenarios. During the COVID-19 pandemic for example, there was a huge increase in individual researchers’ participation and vulnerability submissions in bug bounty platforms (Zrahia et al., 2022), reflecting the gig-economy nature of this policy option and its sensitivity to external shocks. Finally, the trust challenge arises when there is no bilateral dependency between the seller and the buyer. Intermediating platforms can solve this tension, as illustrated by various e-commerce, knowledge economy and sharing economy literature sources (Akhmedova et al., 2021; Soleimani, 2022; Zanini & Musante, 2013). In the bug bounty programs setting, platforms can act as a trusted third party to ensure that the interests of both parties are met (Miller, 2007). They can help researchers prove the validity of discovered vulnerabilities without disclosing them and help organisations verify the validity of vulnerabilities before making payments. 6. Concluding thoughts and limitations Governments and other policymakers have become highly concerned with protecting the cyber domain and their involvement in this space is growing. Governmental intervention in the market for vulnerabilities may shift transactions from the black market to the white market and improve the security posture of systems, products and services used by the public directly or indirectly. Some governments have already implemented related policies, but others are less involved in this market. Well-considered and carefully thought-out policies can provide valuable oversight of sharing initiatives, advance vulnerability identification and maximise social welfare. This paper explores three possible alternatives for governmental intervention in the market for vulnerabilities: implementing secure development and penetration tests, acquiring zero-day vulnerabilities and supporting bug bounty programs and platforms. I present an impact matrix qualitatively measuring the goals associated with the discovery and disclosure processes for each potential intervention area. 22 Internet Policy Review 13(1) | 2024 While the alternatives are not mutually exclusive, bug bounty programs and platforms produce the highest impact and have a relatively low barrier to entry for both the organisations and the ethical hacker community. Therefore, I advise governmental entities, regulation authorities and other policy decision-makers to consider, encourage or prescribe bug bounty programs and platforms based on commercial or community-driven coordinated disclosure initiatives. Despite the extensive literature on the vulnerability market, this paper compares relevant governmental intervention alternatives from a public policy perspective, highlighting their trade-offs, tensions and misalignments, thus contributing to the problem domain. Discussing these structures may serve as a starting point or guideline to motivate the design of a detailed governmental policy. However, further investigation of researcher incentives, firm motivations and bug bounty platform strategies is required to design more effective programs. A follow-up study may check how bug bounty platform operators could attract more buyers and sellers to encourage vulnerability sharing, and organisations maximise their utility function from bug bounty programs. The limitations of the paper are twofold. First, the recommendation is subjective and reflects my informed interpretation, as there is no precise objective measure of policy superiority. Second, though the paper compares three policies for governmental intervention, evaluating and comparing instruments needed to implement the selected option is beyond its scope and requires more exploration. ACKNOWLEDGEMENTS I am grateful to Alon Tal for insightful discussions and continuous guidance. I also thank the reviewers for their constructive feedback. References Ablon, L., & Bogart, A. (2017). Zero days, thousands of nights: The life and times of zero-day vulnerabilities and their exploits. RAND Corporation. https://doi.org/10.7249/RR1751 Ablon, L., & Libicki, M. (2015). Hackers’ bazaar: The markets for cybercrime tools and stolen data. Defense Counsel Journal, 82(2), 143–152. https://doi.org/10.12690/0161-8202-82.2.143 Akerlof, G. A. (1970). The market for ‘lemons’: Quality uncertainty and the market mechanism. The Quarterly Journal of Economics, 84(3), 488. https://doi.org/10.2307/1879431 23 Zrahia Akgul, O., Eghtesad, T., Elazari, A., Gnawali, O., Grossklags, J., Votipka, D., & Laszka, A. (2020). The hackers’ viewpoint: Exploring challenges and benefits of bug-bounty programs. Proceedings of the 6th Workshop on Security Information Workers (WSIW 2020). Workshop on Security Information Workers (WSIW 2020). https://www2.cs.uh.edu/~gnawali/papers/bugbounty-wsiw20-abstract.html Akhmedova, A., Vila-Brunet, N., & Mas-Machuca, M. (2021). Building trust in sharing economy platforms: Trust antecedents and their configurations. Internet Research, 31(4), 1463–1490. https://d oi.org/10.1108/INTR-04-2020-0212 Annu-Essuman, K. (2014). An Analysis on the Regulation of Grey Market Cyber Materials. Cornell Internation Affairs Review, 8(1). https://doi.org/10.37513/ciar.v8i1.462 Apple security bounty categories. (n.d.). Apple Security Research. https://security.apple.com/bounty/ca tegories Arora, A., & Telang, R. (2005). Economics of software vulnerability disclosure. IEEE Security and Privacy Magazine, 3(1), 20–25. https://doi.org/10.1109/MSP.2005.12 Bali, A. S., Howlett, M., Lewis, J. M., & Ramesh, M. (2021). Procedural policy tools in theory and practice. Policy and Society, 40(3), 295–311. https://doi.org/10.1080/14494035.2021.1965379 Bardach, E., & Patashnik, E. M. (2020). A practical guide for policy analysis: The eightfold path to more effective problem solving. In CQ Press; SAGE Publications (Sixth). SAGE Publications. Bienz, C., & Juranek, S. (2020). Software vulnerabilities and bug bounty rograms. SSRN. https://doi.or g/10.2139/ssrn.3599013 Bilge, L., & Dumitraş, T. (2012). Before we knew it: An empirical study of zero-day attacks in the real world. Proceedings of the 2012 ACM Conference on Computer and Communications Security, 833–844. https://doi.org/10.1145/2382196.2382284 Böhme, R. (2006). A comparison of market approaches to software vulnerability disclosure. In G. Müller (Ed.), Emerging Trends in Information and Communication Security (Vol. 3995, pp. 298–311). Springer Berlin Heidelberg. https://doi.org/10.1007/11766155_21 Brans, M., & Pattyn, V. (2017). Validating methods for comparing public policy: Perspectives from academics and “pracademics”. Introduction to the special issue. Journal of Comparative Policy Analysis: Research and Practice, 19(4), 303–312. https://doi.org/10.1080/13876988.2017.1354560 Bugcrowd. (2018). Integrating crowdsourced security with the software development lifecycle. Bugcrowd. https://www.bugcrowd.com/blog/integrating-crowdsourced-security-with-the-software-d evelopment-lifecycle/ Bugcrowd. (n.d.). Reporting a bug [Instruction manual]. Bugcrowd. https://docs.bugcrowd.com/resear chers/reporting-managing-submissions/reporting-a-bug/ Çetin, O., Altena, L., Gañán, C., & van Eeten, M. (2018). Let me out! Evaluating the effectiveness of quarantining compromised users in walled gardens. Proceedings of the Fourteenth Symposium on Usable Privacy and Security. SOUPS 2018. www.usenix.org/conference/soups2018/presentation/ceti n Choi, J. P., Fershtman, C., & Gandal, N. (2010). Network security: Vulnerabilities and disclosure policy. The Journal of Industrial Economics, 58(4), 868–894. https://doi.org/10.1111/j.1467-6451.201 0.00435.x Cyber attacks statistics. (n.d.). Hackmageddon. https://www.hackmageddon.com/category/security/cy 24 Internet Policy Review 13(1) | 2024