USENIX Security2020Top-tier venue
The Industrial Age of Hacking
Timothy Nosco, Jared Ziegler, Zechariah Clark, Davy Marrero, Todd Finkler, Andrew Barbarello, W. Michael Petullo
Abstract
There is a cognitive bias in the hacker community to select a piece of software and invest significant human resources into finding bugs in that software without any prior indication of success. We label this strategy depth-first search and propose an alternative: breadth-first search. In breadthfirst search, humans perform minimal work to enable automated analysis on a range of targets before committing additional time and effort to research any particular one. We present a repeatable human study that leverages teams of varying skill while using automation to the greatest extent possible. Our goal is a process that is effective at finding bugs; has a clear plan for the growth, coaching, and efficient use of team members; and supports measurable, incremental progress. We derive an assembly-line process that improves on what was once intricate, manual work. Our work provides evidence that the breadth-first approach increases the effectiveness of teams.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers6
- An Interview Study on Third-Party Cyber Threat Hunting Processes in the U.S. Department of Homeland SecurityWilliam P. Maxam III, James C. DavisUSENIX Security 2024 · 14 citations
- ProphetFuzz: Fully Automated Prediction and Fuzzing of High-Risk Option Combinations with Only Documentation via Large Language ModelDawei Wang, Geng Zhou, Li Chen, Dan Li et al.CCS 2024 · 9 citations
- Engaging Company Developers in Security Research Studies: A Comprehensive Literature Review and Quantitative SurveyRaphael Serafini, Stefan Albert Horstmann, Alena NaiakshinaUSENIX Security 2024 · 7 citations
- Decompiling the Synergy: An Empirical Study of Human-LLM Teaming in Software Reverse EngineeringZion Leonahenahe Basque, Samuele Doria, Ananta Soneji, Wil Gibbs et al.NDSS 2026 · 7 citations
- An Investigation of Interaction and Information Needs for Protocol Reverse Engineering AutomationSamantha Katcher, James Mattei, Jared Chandler, Daniel VotipkaCHI 2025 · 7 citations
Builds on3
- Driller: Augmenting Fuzzing Through Selective Symbolic ExecutionNick Stephens, John Grosen, Christopher Salls, Andrew Dutcher et al.NDSS 2016 · 1,021 citations
- Evaluating Fuzz TestingGeorge Klees, Andrew Ruef, Benji Cooper, Shiyi Wei et al.CCS 2018 · 753 citations
- Hackers vs. Testers: A Comparison of Software Vulnerability Discovery ProcessesDaniel Votipka, Rock Stevens, Elissa M. Redmiles, Jeremy Hu et al.S&P 2018 · 151 citations
Related papers
- Sleuth: A Switchable Dual-Mode Fuzzer to Investigate Bug Impacts Following a Single PoCHaolai Wei, Liwei Chen, Zhijie Zhang, Gang Shi et al.ISSTA 2024 · 1 citation
- Understanding the Reproducibility of Crowd-reported Security VulnerabilitiesDongliang Mu, Alejandro Cuevas, Limin Yang, Hang Hu et al.USENIX Security 2018 · 138 citations
- Toward User-Driven Algorithm Auditing: Investigating users' strategies for uncovering harmful algorithmic behaviorAlicia DeVos, Aditi Dhabalia, Hong Shen, Kenneth Holstein et al.CHI 2022 · 96 citations
- "Watching over the shoulder of a professional": Why Hackers Make Mistakes and How They Fix ThemIrina Ford, Ananta Soneji, Faris Bugra Kokulu, Jayakrishna Vadayath et al.S&P 2024 · 4 citations
- Study Club, Labor Union or Start-Up? Characterizing Teams and Collaboration in the Bug Bounty EcosystemYangheran Piao, Temima Hrle, Daniel W. Woods, Ross AndersonS&P 2025
