1 of 37

Devil lies in the details: running a successful bug bounty programme in your organization

-Shadab Siddiqui

2 of 37

About me

  • Head of Information Security, Privacy and Trust @Hotstar
  • Previously Head of Information Security, Fraud, Risk and Compliance @Ola
  • Led Black Ops teams err.. Information Security teams as a specialist @Flipkart and Adobe
  • Loves to solve security for scale

But why am I talking about bug bounties?

Long time ago(2008-2012): Complete List, to name a few:

  • Apple
  • Microsoft
  • Redhat
  • Pinterest
  • Barclay
  • Oracle
  • Quickheal
  • HTC
  • Radiocity
  • Stanford University
  • Volkswagen
  • Inmobi
  • HCL
  • Hulu
  • Topcoder
  • Udemy

3 of 37

What’s a bug bounty program?

  • Receive recognition and compensation

for finding/reporting vulnerabilities

    • White-hat hackers median salary 2.7 times of a software engineers
    • In India, It’s 16 times the median programmer salary vs 2.4 times in US.

Why do we need one?

According to a recent report, 71% of cybercriminals say they can breach the perimeter of a target within 10 hours. The only way to combat this threat is with the help of the whitehat community.`

Note:The bug bounty program won’t eliminate the need for secure software development, secure software testing, pen tests, or ongoing web application and system scans. This bug bounty work is incremental to those efforts and is designed to find flaws that slip through these checks.

4 of 37

History

  • Telecom(AT&T ), Payments(Paypal), healthcare
  • US Pentagon | DOD | European Commission |

Ministry of Defense Singapore

  • Hyatt hotels | Adult websites

5 of 37

Today’s Agenda

  • Use case consideration to have a bug bounty program
  • Fears/Concerns of a bug bounty program
  • Understanding to whom does it applies
  • Darkside of not having one
  • How to launch our own bug bounty program
    • Essentials to setup before launch
    • Logistics
    • How to have a successful one
  • Pitfalls to avoid running our own program
  • Some gyaan

6 of 37

How I launched @Ola , 4 years back

7 of 37

Issue created

8 of 37

Valid Issues

9 of 37

Fix in progress

10 of 37

Verification by Researcher

11 of 37

Closing

12 of 37

Invalid Issues

13 of 37

Duplicate

14 of 37

Not able to reproduce

15 of 37

Out of scope

16 of 37

Won’t Fix

17 of 37

Cases of Re-opening an Issue

18 of 37

“Backend” of a bug bounty program...

19 of 37

Considerations for a Bug Bounty program

Generally:

  • Crowdsourcing security
  • Pay for actual bugs rather than full time employees
  • Security assessment of applications/infrastructure
  • To avoid a bad PR situations
  • Wide range of testers (ethical hackers) with different experiences

Should be the reason:

  • Understanding attackers approach
  • Open connect with security community
  • Understanding resilience/robustness of baked in security mechanism
  • Variety of outputs over a longer period of time.
  • How to go about building a detection/prevention systems
  • Eliminate bias
  • Understanding attack surface area

This bug bounty work is incremental and is designed to find flaws that slip through these checks.

20 of 37

Fears/Concerns for a BBP

  • Can I trust hackers
  • Running a BBP would be too risky
  • Will I get bombarded with vulnerabilities
  • Does it issues a license to exploit apps?
  • Will it put a target(my customer/ PR incident) at me
  • Hard to manage
  • Some may have the opinion that implementing such a program is

rewarding bad behavior

Bug bounty program/ platform

Hacktrophy

Bugcrowd

Hackerone

Google

Facebook

Ratio of valid vulnerabilities

23.3%

18.5%

23%

5%

4%

21 of 37

Where/to whom does a BB program applies

  • Payment companies? Compliant
  • CRM/ticket management start ups?
  • E-commerce/cab aggregation? Known customers
  • Non -IT companies? HR/finance/supply chain ?
  • Content websites, like slides/code/User Generated content/ Videos? Maker -checker check
  • Communication platforms ? Known parties
  • Online content registry like NPM/dockers etc? Everything is signed and hosted

Any thumb rule to understand if I need it?

Security Evangelization

22 of 37

Darkside side of not having one

Researcher’s POV

  • Unable to get in contact the company
  • Their vulnerability report was ignored
  • Their vulnerability report was not fixed
  • They felt notifying the public would prompt a fix

Organization POV:

  • Full Disclosure without company’s approval
  • Bombarded with simple issues
  • Threatening/beg bounty hunters
  • Expect logs to light up
  • Effort and the ability to close a high risk, costly flaw to remediate
  • Hackers disclose vulnerabilities or sell their knowledge on the black market

23 of 37

How to go about launching one?

24 of 37

Ingredients for a BBP

  1. Bug bounty brief
  2. Describes engagement rules
  3. Scoping
  4. Pricing and payments structure

2. Program launch :Conduct marketing activities to attract ethical hackers to your program.

3.

4. Payment

  • Communicating and rewarding the bounty

25 of 37

How to build automated platform

  • A communications channel
  • A ticketing systems to keep track
  • Well communicated SLA for bug bounty submission between all teams across organizations
  • Compartmentalization
  • Workflow for triaging vulnerabilities
  • Payments workflow with finance teams
  • Logistics for BB rewards
  • Buy-ins from legal / PR team
  • Measurements KPIs of the program
  • Evangelization

26 of 37

Leadership

Concerns

  • How to handle all the attention
  • What if people publish/exploit vulns.
  • Let’s not ask people to attack our system,
  • Repercussion :What if we can't patch things in promised SLA
  • Do we need a formal one
  • Why can't we do it with third party firms with NDA or in house security team
  • Putting a target on their back
  • Infosec importance is for the organization
  • Budget

27 of 37

Finance teams (India Specific)

Concerns

  • How to monetary reward without a PO/invoice
  • Validating researcher
  • Acceptance from researchers
  • Verification details of the bank account holder
  • $ or INR, pan card
  • Tax deductions
  • Budget utilisation

28 of 37

Security team

  • Preparation
  • Identify and restrict bad traffic
  • Monitoring to detect abuse<>attack on apps/infra
  • How do we do scoping for bug bounty
  • Automate replies/manage BBP centrally
  • How do we identify SOS bugs

29 of 37

Legal and PR team

Concerns

  • How do we detect and what do we do for people not abiding to BBP policy
  • How would we ready to handle PR incidents
  • What policies for international vs national researchers
  • Should we get a cyber security insurance
  • What policies to have more warmth towards researcher
  • Spamming leaders for vulnerabilities

30 of 37

Logistics issues�

  • How do we send goodies to researchers India and abroad
  • How do we communicate tracking details with researchers
  • How would you plan for international border

31 of 37

Let’s Rewind once (Checklist)

  • Get leadership buy-in
  • Get budget approvals
  • Get things right with finance teams on how would payments happen
  • Get things right with legal and PR team on how to handle if things go south
  • Take care of logistics
  • Properly defined rules, scope and what's acceptable and not for BBP
  • Automated Platform/communications channel to interact with researchers

32 of 37

Why build ?

Why not ?

Building the automation platform is like one time effort

Effort: 1 Week automation

Commercial Platforms:

  • Platform fee (annual)
  • Bounty fees (~20-25% of bounty payout)
  • Some other services fee

33 of 37

Do’s

  • Decide payouts math
  • Scoping (Exclusions)

  • How to handle critical submission of

non scoped items/subsidiary

  • Monitoring social media and code commit to github /pastie/stackoverflow
  • Handling new bug hunters
  • Monitoring on api’s / infra
  • Decide on POC requirements
  • Be clear and transparent
  • Only pay a bounty if it is for an activity that is specifically authorized by your policy
  • Defined rule and policy which countries ain’t allowed

34 of 37

Don'ts

  • WAF of bug bounty submission page
  • Researchers considering your risk strategy when reporting
  • Don’t expose your Jira out and make sure no one can update other projects
  • Don’t expect them to read all the rules
  • Don’t always expect to shake the hand
  • Properly manage even with a low budget else

Pen-test + bug bounty program = Better security

35 of 37

To summarise

36 of 37

Notes

  • Bug bounty programs should be a finishing, not foundational element
  • This isn’t cost-effective replacement for penetration testing
  • Unexpected Testing Methodologies and Techniques Will Regularly Appear on Your Horizon
  • Prepare and take care of your logs
  • Bug Bounty requires efforts
  • Bug bounty is not suitable to test private systems
  • Poorly-implemented Bug Bounty
  • Hire Bug bounty hunter for security team**

37 of 37

Questions???

  • Twitter: @sh4ds1dd