arXiv · 2304.00077
Decentralized Attack Search and the Design of Bug Bounty Schemes
Abstract
Systems and blockchains often have security vulnerabilities and can be attacked by adversaries, with potentially significant negative consequences. Therefore, infrastructure providers increasingly rely on bug bounty programs, where external individuals probe the system and report any vulnerabilities (bugs) in exchange for rewards (bounty). We develop a simple contest model of bug bounty. A group of individuals of arbitrary size is invited to undertake a costly search for bugs. The individuals differ with regard to their abilities, which we capture by different costs to achieve a certain probability to find bugs if any exist. Costs are private information. We study equilibria of the contest and characterize the optimal design of bug bounty schemes. In particular, the designer can vary the size of the group of individuals invited to search, add a paid expert, insert an artificial bug with some probability, and pay multiple prizes.
Explore related subjects
Keep this discovery
Hans Gersbach, Akaki Mamageishvili, Fikri Pitsuwan. 2023-03-31. Decentralized Attack Search and the Design of Bug Bounty Schemes. https://arxiv.org/abs/2304.00077
Cite the original work for its findings. Save a collection to share your selection of sources.