Vulnerability Discovery for All: Experiences of Marginalization in Vulnerability Discovery
Kelsey R. Fulton, Samantha Katcher, Kevin Song, Marshini Chetty, Michelle L. Mazurek, Chloé Messdaghi, Daniel Votipka
摘要
Vulnerability discovery is an essential aspect of software security. Currently, the demand for security experts significantly exceeds the available vulnerability discovery workforce. Further, the existing vulnerability discovery workforce is highly homogeneous, dominated by white and Asian men. As such, one promising avenue for increasing the capacity of the vulnerability discovery community is through recruitment and retention from a broader population. Although significant prior research has explored the challenges of equity and inclusion in computing broadly, the competitive and frequently self-taught nature of vulnerability discovery work may create new variations on these challenges. This paper reports on a semi-structured interview study (N = 16) investigating how people from marginalized populations come to participate in vulnerability discovery, whether they feel welcomed by the vulnerability discovery community, and what challenges they face when joining the vulnerability discovery community. We find that members of marginalized populations face some unique challenges, while other challenges common in vulnerability discovery are exacerbated by marginalization.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper10
- SoK: Safer Digital-Safety Research Involving At-Risk UsersRosanna Bellini, Emily Tseng, Noel Warford, Alaa Daffalla 等S&P 2024 · 被引用 48 次
- An Interview Study on Third-Party Cyber Threat Hunting Processes in the U.S. Department of Homeland SecurityWilliam P. Maxam III, James C. DavisUSENIX Security 2024 · 被引用 14 次
- The Benefits of Vulnerability Discovery and Bug Bounty Programs: Case Studies of Chromium and FirefoxSoodeh Atefi, Amutheezan Sivagnanam, Afiya Ayman, Jens Grossklags 等WWW 2023 · 被引用 13 次
- Security and Privacy Software Creators' Perspectives on Unintended ConsequencesHarshini Sri Ramulu, Helen Schmitt, Dominik Wermke, Yasemin AcarUSENIX Security 2024 · 被引用 4 次
- "Abuse Risks are Often Inherent to Product Features": Exploring AI Vendors' Bug Bounty and Responsible Disclosure PoliciesYangheran Piao, Jingjie Li, Daniel W. WoodsUSENIX Security 2026 · 被引用 1 次
它引用的顶会 Paper3
- Hackers vs. Testers: A Comparison of Software Vulnerability Discovery ProcessesDaniel Votipka, Rock Stevens, Elissa M. Redmiles, Jeremy Hu 等S&P 2018 · 被引用 151 次
- HackEd: A Pedagogical Analysis of Online Vulnerability Discovery ExercisesDaniel Votipka, Eric Zhang, Michelle L. MazurekS&P 2021 · 被引用 22 次
- An Observational Investigation of Reverse Engineers' ProcessesDaniel Votipka, Seth M. Rabin, Kristopher K. Micinski, Jeffrey S. Foster 等USENIX Security 2020
相关 Paper
- "I'm trying to learn...and I'm shooting myself in the foot": Beginners' Struggles When Solving Binary Exploitation ExercisesJames Mattei, Christopher Pellegrini, Matthew Soto, Marina Sanusi Bohuk 等USENIX Security 2025
- It Shouldn't Be This Difficult: Researcher Perspectives on Diversity and Inclusion in Usable Privacy and Security ResearchPriyasha Chatterjee, Smirity Kaushik, Karola Marky, Yixin ZouCHI 2026 · 被引用 1 次
- Women Security Experts Are Not The Enemy: A Qualitative Study on Gender-Related Communication ChallengesAsli Yardim, Stefan Albert Horstmann, Raphael Serafini, Joshua Gabriel Speckels 等CHI 2025 · 被引用 3 次
- Investigating the Impact of Interpersonal Challenges on Feeling Welcome in OSSBianca Trinkenreich, Zixuan Feng, Rudrajit Choudhuri, Marco Aurélio Gerosa 等ICSE 2025 · 被引用 2 次
- A Seat at the Virtual Table: Emergent Inclusion in Remote MeetingsAmanda Lacy, Seth Polsley, Samantha Ray, Tracy HammondCSCW 2022 · 被引用 9 次
