Pith. sign in

REVIEW

Understanding the Heterogeneity of Contributors in Bug Bounty Programs

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 1709.06224 v1 pith:XHBKWV6W submitted 2017-09-19 cs.SE

classification cs.SE
keywords bountycontributorsprogramssoftwaredevelopmentheterogeneitythereaims
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Background: While bug bounty programs are not new in software development, an increasing number of companies, as well as open source projects, rely on external parties to perform the security assessment of their software for reward. However, there is relatively little empirical knowledge about the characteristics of bug bounty program contributors. Aim: This paper aims to understand those contributors by highlighting the heterogeneity among them. Method: We analyzed the histories of 82 bug bounty programs and 2,504 distinct bug bounty contributors, and conducted a quantitative and qualitative survey. Results: We found that there are project-specific and non-specific contributors who have different motivations for contributing to the products and organizations. Conclusions: Our findings provide insights to make bug bounty programs better and for further studies of new software development roles.

Discussion (0). Continue with ORCID to comment.

Pith tools