Economic Factors of Vulnerability Trade and Exploitation
Luca Allodi
Abstract
Cybercrime markets support the development and diffusion of new attack technologies, vulnerability exploits, and malware. Whereas the revenue streams of cyber attackers have been studied multiple times in the literature, no quantitative account currently exists on the economics of attack acquisition and deployment. Yet, this understanding is critical to characterize the production of (traded) exploits, the economy that drives it, and its effects on the overall attack scenario. In this paper we provide an empirical investigation of the economics of vulnerability exploitation, and the effects of market factors on likelihood of exploit. Our data is collected first-handedly from a prominent Russian cybercrime market where the trading of the most active attack tools reported by the security industry happens. Our findings reveal that exploits in the underground are priced similarly or above vulnerabilities in legitimate bug-hunting programs, and that the refresh cycle of exploits is slower than currently often assumed. On the other hand, cybercriminals are becoming faster at introducing selected vulnerabilities, and the market is in clear expansion both in terms of players, traded exploits, and exploit pricing. We then evaluate the effects of these market variables on likelihood of attack realization, and find strong evidence of the correlation between market activity and exploit deployment. We discuss implications on vulnerability metrics, economics, and exploit measurement.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 1da3d3e6-4728-4b98-823a-8296c5d56fdcCited by top-tier papers6
- From Patching Delays to Infection Symptoms: Using Risk Profiles for an Early Discovery of Vulnerabilities Exploited in the WildChaowei Xiao, Armin Sarabi, Yang Liu, Bo Li et al.USENIX Security 2018 · 31 citations
- Impersonation-as-a-Service: Characterizing the Emerging Criminal Infrastructure for User Impersonation at ScaleMichele Campobasso, Luca AllodiCCS 2020 · 24 citations
- Go See a Specialist? Predicting Cybercrime Sales on Online Anonymous Markets from Vendor and Product CharacteristicsRolf van Wegberg, Fieke Miedema, Ugur Akyazi, Arman Noroozian et al.WWW 2020 · 14 citations
- "Oh, what people would do with my knife?'' Navigating the Dual-Use Dilemma in PoC Exploit Development, Disclosure, and Community DynamicsArwa Al Alsadi, Lorenz Kustosch, Lamya Alowain, Michel Van Eeten et al.USENIX Security 2026
- Know Your Cybercriminal: Evaluating Attacker Preferences by Measuring Profile Sales on an Active, Leading Criminal Market for User Impersonation at ScaleMichele Campobasso, Luca AllodiUSENIX Security 2023
Builds on1
Related papers
- Plug and Prey? Measuring the Commoditization of Cybercrime via Online Anonymous MarketsRolf van Wegberg, Samaneh Tajalizadehkhoob, Kyle Soska, Ugur Akyazi et al.USENIX Security 2018 · 97 citations
- SoK: Digging into the Digital Underworld of Stolen Data MarketsTina Marjanov, Alice HutchingsS&P 2025
- The Benefits of Vulnerability Discovery and Bug Bounty Programs: Case Studies of Chromium and FirefoxSoodeh Atefi, Amutheezan Sivagnanam, Afiya Ayman, Jens Grossklags et al.WWW 2023 · 13 citations
- Cracking the Wall of Confinement: Understanding and Analyzing Malicious Domain Take-downsEihal Alowaisheq, Peng Wang, Sumayah A. Alrwais, Xiaojing Liao et al.NDSS 2019 · 48 citations
- Expected Exploitability: Predicting the Development of Functional Vulnerability ExploitsOctavian Suciu, Connor Nelson, Zhuoer Lyu, Tiffany Bao et al.USENIX Security 2022
