Devil lies in the details: running a successful bug bounty programme in your organization
-Shadab Siddiqui
About me
But why am I talking about bug bounties?
Long time ago(2008-2012): Complete List, to name a few:
|
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
What’s a bug bounty program?
for finding/reporting vulnerabilities
Why do we need one?
According to a recent report, 71% of cybercriminals say they can breach the perimeter of a target within 10 hours. The only way to combat this threat is with the help of the whitehat community.`
Note:The bug bounty program won’t eliminate the need for secure software development, secure software testing, pen tests, or ongoing web application and system scans. This bug bounty work is incremental to those efforts and is designed to find flaws that slip through these checks.
History
Ministry of Defense Singapore
Today’s Agenda
How I launched @Ola , 4 years back
Issue created
Valid Issues
Fix in progress
Verification by Researcher
Closing
Invalid Issues
Duplicate
Not able to reproduce
Out of scope
Won’t Fix
Cases of Re-opening an Issue
“Backend” of a bug bounty program...
Considerations for a Bug Bounty program
Generally:
Should be the reason:
This bug bounty work is incremental and is designed to find flaws that slip through these checks.
Fears/Concerns for a BBP
rewarding bad behavior
Bug bounty program/ platform | Hacktrophy | Bugcrowd | Hackerone | ||
Ratio of valid vulnerabilities | 23.3% | 18.5% | 23% | 5% | 4% |
Where/to whom does a BB program applies
Any thumb rule to understand if I need it?
Security Evangelization
Darkside side of not having one
Researcher’s POV
Organization POV:
How to go about launching one?
Ingredients for a BBP
2. Program launch :Conduct marketing activities to attract ethical hackers to your program.
3.
4. Payment
How to build automated platform
Leadership
Concerns
Finance teams (India Specific)
Concerns
Security team
Legal and PR team
Concerns
Logistics issues�
Let’s Rewind once (Checklist)
Why build ?
Why not ?
Building the automation platform is like one time effort
Effort: 1 Week automation
Commercial Platforms:
Do’s
non scoped items/subsidiary
Don'ts
Pen-test + bug bounty program = Better security
To summarise
Notes
Questions???