论文标题
在线安全竞赛中的观察及其对众包安全性的影响
Observations From an Online Security Competition and Its Implications on Crowdsourced Security
论文作者
论文摘要
在过去的几年中,人群采购的安全行业,尤其是Bug Bounty计划,已经急剧发展,并已成为许多公司软件安全评论的主要来源。但是,学术文献在很大程度上省略了安全团队,尤其是在人群工作环境中。因此,我们对分布式安全团队的组织,协作以及他们所需要的技术的要求一无所知。我们通过在计算机安全捕获量牌(CTF)竞赛中与排名前五的团队(在18,201名参与的团队中)进行焦点小组来填补这一空白。我们发现,这些团队采用了一系列以专业为中心的策略,使他们能够减少与分散,双重工作和缺乏以前的协作有关的问题。观察以安全人群工作平台中以个人工人为中心的模型的当前问题,我们的研究案例将安全工作扩展到团队是可行的和有益的。最后,我们确定了需要未来工作的各个领域,例如在高技能人群工作环境中的社会认同问题。
The crowd sourced security industry, particularly bug bounty programs, has grown dramatically over the past years and has become the main source of software security reviews for many companies. However, the academic literature has largely omitted security teams, particularly in crowd work contexts. As such, we know very little about how distributed security teams organize, collaborate, and what technology needs they have. We fill this gap by conducting focus groups with the top five teams (out of 18,201 participating teams) of a computer security Capture-the-Flag (CTF) competition. We find that these teams adopted a set of strategies centered on specialties, which allowed them to reduce issues relating to dispersion, double work, and lack of previous collaboration. Observing the current issues of a model centered on individual workers in security crowd work platforms, our study cases that scaling security work to teams is feasible and beneficial. Finally, we identify various areas which warrant future work, such as issues of social identity in high-skilled crowd work environments.