English

Decentralized Attack Search and the Design of Bug Bounty Schemes

Theoretical Economics 2023-09-06 v2 Computer Science and Game Theory

Abstract

Systems and blockchains often have security vulnerabilities and can be attacked by adversaries, with potentially significant negative consequences. Therefore, infrastructure providers increasingly rely on bug bounty programs, where external individuals probe the system and report any vulnerabilities (bugs) in exchange for rewards (bounty). We develop a simple contest model of bug bounty. A group of individuals of arbitrary size is invited to undertake a costly search for bugs. The individuals differ with regard to their abilities, which we capture by different costs to achieve a certain probability to find bugs if any exist. Costs are private information. We study equilibria of the contest and characterize the optimal design of bug bounty schemes. In particular, the designer can vary the size of the group of individuals invited to search, add a paid expert, insert an artificial bug with some probability, and pay multiple prizes.

Keywords

Cite

@article{arxiv.2304.00077,
  title  = {Decentralized Attack Search and the Design of Bug Bounty Schemes},
  author = {Hans Gersbach and Akaki Mamageishvili and Fikri Pitsuwan},
  journal= {arXiv preprint arXiv:2304.00077},
  year   = {2023}
}