Study Club, Labor Union or Start-Up? Characterizing Teams and Collaboration in the Bug Bounty Ecosystem
Yangheran Piao, Temima Hrle, Daniel W. Woods, Ross Anderson
摘要
A unique bug bounty ecosystem has evolved in China. Platforms allow groups of hackers to register together to receive team-level awards. However, little is known about the prevalence and productivity of these teams, or how team members collaborate. To address this gap, we conducted a mixed-methods study. The first stage characterized teams from a top-down ecosystem perspective. We collected bug bounty rankings from 85 platforms, using fuzzy-matching to identify 2.1k unique teams and 5.9k hunters. We show that 46% of users are registered as part of a team, and hunters with teams are more than twice as productive as hunters without teams. The typical team has less than 10 members and only operates on a handful of platforms, but we also identified mega teams participating in more than 50 platforms with hundreds of team members. The second phase provided bottom-up insights into why hackers join teams and how they collaborate within teams. Our semi-structured interviews (n = 18) reveal bug hunting teams are multi-faceted–part study club, part labor union, and part start-up. Teams act like study clubs in enabling knowledge exchange and skills development, and act like labor unions in negotiating with bug bounty platforms and vendors. Hunter teams also displayed company-like aspects when earning and sharing revenue, and also creating rules that members should follow. In doing so, hunter teams help to address three of the main challenges that bug hunters face, namely skills development, negotiating with large technology companies, and income uncertainty.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper2
- "Abuse Risks are Often Inherent to Product Features": Exploring AI Vendors' Bug Bounty and Responsible Disclosure PoliciesYangheran Piao, Jingjie Li, Daniel W. WoodsUSENIX Security 2026 · 被引用 1 次
- "Oh, what people would do with my knife?'' Navigating the Dual-Use Dilemma in PoC Exploit Development, Disclosure, and Community DynamicsArwa Al Alsadi, Lorenz Kustosch, Lamya Alowain, Michel Van Eeten 等USENIX Security 2026
相关 Paper
- Bug Hunters' Perspectives on the Challenges and Benefits of the Bug Bounty EcosystemOmer Akgul, Taha Eghtesad, Amit Elazari, Omprakash Gnawali 等USENIX Security 2023
- Hackers vs. Testers: A Comparison of Software Vulnerability Discovery ProcessesDaniel Votipka, Rock Stevens, Elissa M. Redmiles, Jeremy Hu 等S&P 2018 · 被引用 151 次
- A Deep Dive into How Open-Source Project Maintainers Review and Resolve Bug Bounty ReportsJessy Ayala, Steven Ngo, Joshua GarciaS&P 2025
- An Interview Study on Third-Party Cyber Threat Hunting Processes in the U.S. Department of Homeland SecurityWilliam P. Maxam III, James C. DavisUSENIX Security 2024 · 被引用 14 次
- The Benefits of Vulnerability Discovery and Bug Bounty Programs: Case Studies of Chromium and FirefoxSoodeh Atefi, Amutheezan Sivagnanam, Afiya Ayman, Jens Grossklags 等WWW 2023 · 被引用 13 次
