{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T12:20:23Z","timestamp":1782994823034,"version":"3.54.5"},"publisher-location":"Cham","reference-count":29,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783319457406","type":"print"},{"value":"9783319457413","type":"electronic"}],"license":[{"start":{"date-parts":[[2016,1,1]],"date-time":"2016-01-01T00:00:00Z","timestamp":1451606400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2016,1,1]],"date-time":"2016-01-01T00:00:00Z","timestamp":1451606400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2016]]},"DOI":"10.1007\/978-3-319-45741-3_9","type":"book-chapter","created":{"date-parts":[[2016,9,14]],"date-time":"2016-09-14T04:50:25Z","timestamp":1473828625000},"page":"161-178","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":24,"title":["Banishing Misaligned Incentives for Validating Reports in Bug-Bounty Platforms"],"prefix":"10.1007","author":[{"given":"Aron","family":"Laszka","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mingyi","family":"Zhao","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jens","family":"Grossklags","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2016,9,15]]},"reference":[{"issue":"3","key":"9_CR1","first-page":"71","volume":"8","author":"A Algarni","year":"2014","unstructured":"Algarni, A., Malaiya, Y.: Software vulnerability markets: discoverers and buyers. Int. J. Comput. Inf. Sci. Eng. 8(3), 71\u201381 (2014)","journal-title":"Int. J. Comput. Inf. Sci. Eng."},{"key":"9_CR2","unstructured":"Alhazmi, O., Malaiya, Y.: Modeling the vulnerability discovery process. In: 16th IEEE International Symposium on Software Reliability Engineering (ISSRE) (2005)"},{"key":"9_CR3","unstructured":"Anderson, R.: Security in open versus closed systems - The dance of Boltzmann, Coase and Moore. In: Open Source Software Economics (2002)"},{"key":"9_CR4","doi-asserted-by":"crossref","unstructured":"Bacon, D., Chen, Y., Parkes, D., Rao, M.: A market-based approach to software evolution. In: 24th ACM SIGPLAN Conference Companion on Object Oriented Programming, Systems, Languages, and Applications (2009)","DOI":"10.1145\/1639950.1640066"},{"key":"9_CR5","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"298","DOI":"10.1007\/11766155_21","volume-title":"Emerging Trends in Information and Communication Security","author":"R B\u00f6hme","year":"2006","unstructured":"B\u00f6hme, R.: A comparison of market approaches to software vulnerability disclosure. In: M\u00fcller, G. (ed.) ETRICS 2006. LNCS, vol. 3995, pp. 298\u2013311. Springer, Heidelberg (2006)"},{"key":"9_CR6","unstructured":"Brady, R., Anderson, R., Ball, R.: Murphy\u2019s law, the fitness of evolving species, and the limits of software reliability. Technical Report 471, University of Cambridge, Computer Laboratory (1999)"},{"key":"9_CR7","unstructured":"Bugcrowd: The state of bug bounty, July 2015"},{"key":"9_CR8","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"111","DOI":"10.1007\/978-3-642-14215-4_7","volume-title":"Detection of Intrusions and Malware, and Vulnerability Assessment","author":"A Doup\u00e9","year":"2010","unstructured":"Doup\u00e9, A., Cova, M., Vigna, G.: Why Johnny can\u2019t pentest: an analysis of black-box web vulnerability scanners. In: Kreibich, C., Jahnke, M. (eds.) DIMVA 2010. LNCS, vol. 6201, pp. 111\u2013131. Springer, Heidelberg (2010)"},{"key":"9_CR9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"197","DOI":"10.1007\/978-3-642-36563-8_14","volume-title":"Engineering Secure Software and Systems","author":"A Edmundson","year":"2013","unstructured":"Edmundson, A., Holtkamp, B., Rivera, E., Finifter, M., Mettler, A., Wagner, D.: An empirical study on the effectiveness of security code review. In: J\u00fcrjens, J., Livshits, B., Scandariato, R. (eds.) ESSoS 2013. LNCS, vol. 7781, pp. 197\u2013212. Springer, Heidelberg (2013)"},{"key":"9_CR10","doi-asserted-by":"crossref","unstructured":"Egelman, S., Herley, C., van Oorschot, P.: Markets for Zero-Day Exploits: Ethics and Implications. In: New Security Paradigms Workshop (2013)","DOI":"10.1145\/2535813.2535818"},{"key":"9_CR11","unstructured":"Finifter, M., Akhawe, D., Wagner, D.: An empirical study of vulnerability rewards programs. In: USENIX Security Symposium (2013)"},{"key":"9_CR12","doi-asserted-by":"crossref","unstructured":"Frei, S., Schatzmann, D., Plattner, B., Trammell, B.: Modeling the security ecosystem - The dynamics of (in)security. In: Economics of Information Security and Privacy (2009)","DOI":"10.1007\/978-1-4419-6967-5_6"},{"key":"9_CR13","unstructured":"HackerOne: Improving public bug bounty programs with signal requirements. HackerOne Blog, March 2016. https:\/\/hackerone.com\/blog\/signal-requirements"},{"key":"9_CR14","doi-asserted-by":"publisher","first-page":"47","DOI":"10.1016\/j.cose.2015.11.006","volume":"58","author":"C Huang","year":"2016","unstructured":"Huang, C., Liu, J., Fang, Y., Zuo, Z.: A study on web security incidents in China by analyzing vulnerability disclosure platforms. Comput. Secur. 58, 47\u201362 (2016)","journal-title":"Comput. Secur."},{"issue":"5","key":"9_CR15","doi-asserted-by":"publisher","first-page":"726","DOI":"10.1287\/mnsc.1040.0357","volume":"51","author":"K Kannan","year":"2005","unstructured":"Kannan, K., Telang, R.: Market for software vulnerabilities? Think again. Manage. Sci. 51(5), 726\u2013740 (2005)","journal-title":"Manage. Sci."},{"key":"9_CR16","unstructured":"Laszka, A., Zhao, M., Grossklags, J.: Optimal policies for bug bounty programs (extended version) (2016). http:\/\/aronlaszka.com\/papers\/laszka2016banishing.pdf"},{"key":"9_CR17","unstructured":"Libicki, M., Ablon, L., Webb, T.: The Defenders Dilemma: Charting a Course Toward Cybersecurity. Rand Corporation (2015)"},{"key":"9_CR18","doi-asserted-by":"crossref","unstructured":"Maillart, T., Zhao, M., Grossklags, J., Chuang, J.: Given enough eyeballs, all bugs are shallow? Revisiting Eric Raymond with bug bounty markets. In: Workshop on the Economics of Information Security (WEIS) (2016)","DOI":"10.1093\/cybsec\/tyx008"},{"key":"9_CR19","unstructured":"Ozment, A.: Bug auctions: Vulnerability markets reconsidered. In: Workshop on the Economics of Information Security (WEIS) (2004)"},{"key":"9_CR20","unstructured":"Ozment, A.: The likelihood of vulnerability rediscovery and the social utility of vulnerability hunting. In: Workshop on the Economics of Information Security (WEIS) (2005)"},{"key":"9_CR21","unstructured":"Ozment, A., Schechter, S.: Milk or wine: Does software security improve with age? In: USENIX Security Symposium (2006)"},{"issue":"1","key":"9_CR22","doi-asserted-by":"crossref","first-page":"43","DOI":"10.2307\/41410405","volume":"36","author":"S Ransbotham","year":"2012","unstructured":"Ransbotham, S., Mitra, S., Ramsey, J.: Are markets for vulnerabilities effective? MIS Q. 36(1), 43\u201364 (2012)","journal-title":"MIS Q."},{"issue":"1","key":"9_CR23","doi-asserted-by":"publisher","first-page":"14","DOI":"10.1109\/MSP.2005.17","volume":"3","author":"E Rescorla","year":"2005","unstructured":"Rescorla, E.: Is finding security holes a good idea? IEEE Secur. Priv. 3(1), 14\u201319 (2005)","journal-title":"IEEE Secur. Priv."},{"key":"9_CR24","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"73","DOI":"10.1007\/3-540-45831-X_6","volume-title":"Infrastructure Security","author":"SE Schechter","year":"2002","unstructured":"Schechter, S.E.: How to buy better testing. In: Davida, G.I., Frankel, Y., Rees, O. (eds.) InfraSec 2002. LNCS, vol. 2437, pp. 73\u201387. Springer, Heidelberg (2002)"},{"key":"9_CR25","doi-asserted-by":"crossref","unstructured":"Shahzad, M., Shafiq, M., Liu, A.: A large scale exploratory analysis of software vulnerability life cycles. In: International Conference on Software Engineering (2012)","DOI":"10.1109\/ICSE.2012.6227141"},{"key":"9_CR26","doi-asserted-by":"crossref","unstructured":"Van Goethem, T., Piessens, F., Joosen, W., Nikiforakis, N.: Clubbing seals: Exploring the ecosystem of third-party security seals. In: 21st ACM SIGSAC Conference on Computer and Communications Security (CCS) (2014)","DOI":"10.1145\/2660267.2660279"},{"key":"9_CR27","doi-asserted-by":"crossref","unstructured":"Zhao, M., Grossklags, J., Chen, K.: An exploratory study of white hat behaviors in a web vulnerability disclosure program. In: 2014 ACM CCS Workshop on Security Information Workers (2014)","DOI":"10.1145\/2663887.2663906"},{"key":"9_CR28","doi-asserted-by":"crossref","unstructured":"Zhao, M., Grossklags, J., Liu, P.: An empirical study of web vulnerability discovery ecosystems. In: 22nd ACM SIGSAC Conference on Computer and Communications Security (CCS) (2015)","DOI":"10.1145\/2810103.2813704"},{"key":"9_CR29","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"173","DOI":"10.1007\/978-3-319-30806-7_11","volume-title":"Engineering Secure Software and Systems","author":"M Zhao","year":"2016","unstructured":"Zhao, M., Liu, P.: Empirical analysis and modeling of black-box mutational fuzzing. In: Caballero, J., Bodden, E., Athanasopoulos, E. (eds.) ESSoS 2016. LNCS, vol. 9639, pp. 173\u2013189. Springer, Heidelberg (2016)"}],"container-title":["Lecture Notes in Computer Science","Computer Security \u2013 ESORICS 2016"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-45741-3_9","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,9,15]],"date-time":"2021-09-15T02:44:36Z","timestamp":1631673876000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-319-45741-3_9"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016]]},"ISBN":["9783319457406","9783319457413"],"references-count":29,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-45741-3_9","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2016]]},"assertion":[{"value":"15 September 2016","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ESORICS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"European Symposium on Research in Computer Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Heraklion","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Greece","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2016","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"26 September 2016","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"30 September 2016","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"21","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"esorics2016","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"This content has been made available to all.","name":"free","label":"Free to read"}]}}