{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,8]],"date-time":"2026-07-08T23:27:21Z","timestamp":1783553241847,"version":"3.55.0"},"reference-count":57,"publisher":"IGI Global Scientific Publishing","issue":"1","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2020,1,1]]},"abstract":"<p>Cybercrime caused by exploited vulnerabilities bears a huge burden on societies. Most of these vulnerabilities are detectable, and the damage is preventable if software vendors and firms that deploy such software adopt right practices. Bug Bounty Programs (BBPs) by vendors and intermediaries are one of the most important creations in recent years, that helps software vendors to create marketplaces and to detect and prevent such exploits. This article develops the theory of BBPs and present a typology of BBPs using established theories of incentive compatibility and mechanism design. The authors empirically analyze the market creation function of BBPs using granular data from two different types of BBPs on a popular intermediary platform. The research findings suggest that BBPs are valuable opportunities to source vulnerabilities in software; nevertheless, the rate of disclosure and hacker participation marginally increases with vendor's rewards and other incentives. Similarly, the results show that security researchers are motivated to contribute to BBPs that offer higher remuneration and not just those programs with a higher likelihood for bug discovery. Our findings will help researchers and practitioners in information security and allied domains to develop a theoretical and empirical perspective of BBPs, and their usefulness to curb incidents of cybercrime.<\/p>","DOI":"10.4018\/jdm.2020010103","type":"journal-article","created":{"date-parts":[[2019,12,12]],"date-time":"2019-12-12T15:16:11Z","timestamp":1576163771000},"page":"38-63","source":"Crossref","is-referenced-by-count":15,"title":["Bug Bounty Marketplaces and Enabling Responsible Vulnerability Disclosure"],"prefix":"10.4018","volume":"31","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-5095-7607","authenticated-orcid":true,"given":"Hemang Chamakuzhi","family":"Subramanian","sequence":"first","affiliation":[{"name":"Florida International University, Miami, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2184-2058","authenticated-orcid":true,"given":"Suresh","family":"Malladi","sequence":"additional","affiliation":[{"name":"Cybersecurity Researcher & Consultant, Fayetteville, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"2432","reference":[{"key":"JDM.2020010103-0","doi-asserted-by":"crossref","DOI":"10.7249\/RR610","author":"L.Ablon","year":"2014","journal-title":"Markets for cybercrime tools and stolen data: Hackers\u2019 bazaar"},{"key":"JDM.2020010103-1","doi-asserted-by":"crossref","unstructured":"Akerlof, G. A. (1978). The market for \u201clemons\u201d: Quality uncertainty and the market mechanism. In Uncertainty in Economics (pp. 235-251). Elsevier.","DOI":"10.1016\/B978-0-12-214850-7.50022-X"},{"issue":"3","key":"JDM.2020010103-2","first-page":"71","article-title":"Software vulnerability markets: Discoverers and buyers. International Journal Computer","volume":"8","author":"A.Algarni","year":"2014","journal-title":"Information Science and Engineering"},{"key":"JDM.2020010103-3","doi-asserted-by":"publisher","DOI":"10.1109\/ISSRE.2005.30"},{"key":"JDM.2020010103-4","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3133960"},{"key":"JDM.2020010103-5","doi-asserted-by":"publisher","DOI":"10.2307\/2297968"},{"key":"JDM.2020010103-6","doi-asserted-by":"publisher","DOI":"10.1287\/mnsc.1070.0771"},{"key":"JDM.2020010103-7","doi-asserted-by":"publisher","DOI":"10.1007\/11766155_21"},{"key":"JDM.2020010103-8","doi-asserted-by":"publisher","DOI":"10.3233\/IP-170058"},{"key":"JDM.2020010103-9","doi-asserted-by":"publisher","DOI":"10.4018\/jdm.2008040101"},{"key":"JDM.2020010103-10","doi-asserted-by":"publisher","DOI":"10.1145\/2736281"},{"key":"JDM.2020010103-11","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-36563-8_14"},{"key":"JDM.2020010103-12","doi-asserted-by":"publisher","DOI":"10.1145\/2535813.2535818"},{"issue":"2","key":"JDM.2020010103-13","first-page":"1","article-title":"Cybersecurity Principles for Space Systems.","volume":"16","author":"G.Falco","year":"2018","journal-title":"Journal of Aerospace Information Systems"},{"key":"JDM.2020010103-14","unstructured":"Finifter, M., Akhawe, D., & Wagner, D. (2013). An empirical study of vulnerability rewards programs. Paper presented at the 22nd USENIX Security Symposium (USENIX Security 13). Academic Press."},{"key":"JDM.2020010103-15","doi-asserted-by":"publisher","DOI":"10.1109\/MS.2002.976936"},{"key":"JDM.2020010103-16","doi-asserted-by":"publisher","DOI":"10.1109\/TR.1979.5220566"},{"key":"JDM.2020010103-17","unstructured":"Gross, G. (2018, February 23). The Cost of Cybercrime. Internet Security."},{"key":"JDM.2020010103-18","doi-asserted-by":"publisher","DOI":"10.1080\/19390450903037302"},{"key":"JDM.2020010103-19","doi-asserted-by":"publisher","DOI":"10.1109\/ESEM.2017.34"},{"key":"JDM.2020010103-20","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-658-21655-9_20"},{"key":"JDM.2020010103-21","unstructured":"Huang, K., Siegel, M., Madnick, S., Li, X., & Feng, Z. (2016). Diversity or Concentration? Hackers\u2019 Strategy for Working Across Multiple Bug Bounty Programs. Paper presented at the37th IEEE Symposium on Security and Privacy. IEEE Press."},{"key":"JDM.2020010103-22","doi-asserted-by":"publisher","DOI":"10.1287\/mnsc.1040.0357"},{"key":"JDM.2020010103-23","first-page":"753","article-title":"Bugs in the Market: Creating a Legitimate, Transparent, and Vendor-Focused Market for Software Vulnerabilities","volume":"58","author":"J.Kesan","year":"2016","journal-title":"Arizona Law Review"},{"key":"JDM.2020010103-24","doi-asserted-by":"publisher","DOI":"10.2139\/ssrn.2418812"},{"key":"JDM.2020010103-25","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-45741-3_9"},{"key":"JDM.2020010103-26","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-58387-6_8"},{"key":"JDM.2020010103-27","doi-asserted-by":"publisher","DOI":"10.4018\/JDM.2018010101"},{"issue":"1","key":"JDM.2020010103-28","first-page":"37","article-title":"Participatory Design for User-generated Content: Understanding the challenges and moving forward.","volume":"28","author":"R.Lukyanenko","year":"2016","journal-title":"Scandinavian Journal of Information Systems"},{"key":"JDM.2020010103-29","doi-asserted-by":"publisher","DOI":"10.1145\/3339252.3341495"},{"issue":"3","key":"JDM.2020010103-30","first-page":"vii","article-title":"Guest Editorial Preface: Managing Information Security Risks in Digital Business.","volume":"30","author":"X.Luo","year":"2019","journal-title":"Journal of Database Management"},{"key":"JDM.2020010103-31","doi-asserted-by":"publisher","DOI":"10.1093\/cybsec\/tyx008"},{"key":"JDM.2020010103-32","doi-asserted-by":"publisher","DOI":"10.1109\/MS.2018.2880508"},{"key":"JDM.2020010103-33","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2014.2354037"},{"key":"JDM.2020010103-34","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2007.180"},{"key":"JDM.2020010103-35","doi-asserted-by":"publisher","DOI":"10.1080\/23738871.2018.1546883"},{"key":"JDM.2020010103-36","unstructured":"Miller, C. (2007). The legitimate vulnerability market: Inside the secretive world of 0-day exploit sales. Paper presented at theSixth Workshop on the Economics of Information Security (WEIS\u201907). Academic Press."},{"key":"JDM.2020010103-37","doi-asserted-by":"publisher","DOI":"10.1145\/3155808"},{"key":"JDM.2020010103-38","doi-asserted-by":"publisher","DOI":"10.1145\/2989238.2989239"},{"key":"JDM.2020010103-39","doi-asserted-by":"publisher","DOI":"10.4236\/jsea.2013.64A003"},{"key":"JDM.2020010103-40","unstructured":"Ozment, A. (2005). The Likelihood of Vulnerability Rediscovery and the Social Utility of Vulnerability Hunting. Paper presented at theWorkshop on Economics of Information Security. Academic Press."},{"key":"JDM.2020010103-41","doi-asserted-by":"publisher","DOI":"10.4018\/jdm.2014040102"},{"key":"JDM.2020010103-42","unstructured":"Radianti, J., Rich, E., & Gonzalez, J. (2007). Using a mixed data collection strategy to uncover vulnerability black markets. Paper presented at the2nd Pre-ICIS Workshop on Information Security and Privacy. Academic Press."},{"key":"JDM.2020010103-43","unstructured":"Radianti, J., Rich, E., & Gonzalez, J. J. (2009). Vulnerability black markets: Empirical evidence and scenario simulation. Paper presented at the42nd Hawaii International Conference on System Sciences (HICSS). Academic Press."},{"key":"JDM.2020010103-44","doi-asserted-by":"publisher","DOI":"10.2307\/41410405"},{"key":"JDM.2020010103-45","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2018.2842188"},{"key":"JDM.2020010103-46","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2005.17"},{"key":"JDM.2020010103-47","doi-asserted-by":"publisher","DOI":"10.1016\/S1361-3723(14)70463-4"},{"key":"JDM.2020010103-48","doi-asserted-by":"publisher","DOI":"10.17705\/1CAIS.04302"},{"key":"JDM.2020010103-49","doi-asserted-by":"crossref","unstructured":"Shrobe, H., Shrier, D., & Pentland, A. (2018). Fixing a Hole: The Labor Market for Bugs. In New Solutions for Cybersecurity (Ch. 4, pp. 129-159). MIT Press.","DOI":"10.7551\/mitpress\/11636.001.0001"},{"key":"JDM.2020010103-50","doi-asserted-by":"publisher","DOI":"10.1145\/1145287.1145316"},{"key":"JDM.2020010103-51","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00003"},{"key":"JDM.2020010103-52","doi-asserted-by":"publisher","DOI":"10.4018\/JDM.2019070101"},{"key":"JDM.2020010103-53","doi-asserted-by":"publisher","DOI":"10.1145\/2663887.2663906"},{"key":"JDM.2020010103-54","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813704"},{"key":"JDM.2020010103-55","doi-asserted-by":"publisher","DOI":"10.5325\/jinfopoli.7.2017.0372"},{"key":"JDM.2020010103-56","unstructured":"Zhou, J., & Hui, K. (2019). Bug Bounty Programs, Security Investment and Law Enforcement: A Security Game Perspective. Paper presented at the 2019 Workshop on the Economics of Information Security (WEIS). Academic Press. Retrieved from http:\/\/hdl.handle.net\/1783.1\/96436"}],"container-title":["Journal of Database Management"],"original-title":[],"language":"ng","link":[{"URL":"https:\/\/www.igi-global.com\/viewtitle.aspx?TitleId=245299","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,5,6]],"date-time":"2022-05-06T16:25:26Z","timestamp":1651854326000},"score":1,"resource":{"primary":{"URL":"https:\/\/services.igi-global.com\/resolvedoi\/resolve.aspx?doi=10.4018\/JDM.2020010103"}},"subtitle":["An Empirical Analysis"],"short-title":[],"issued":{"date-parts":[[2020,1,1]]},"references-count":57,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2020,1]]}},"URL":"https:\/\/doi.org\/10.4018\/jdm.2020010103","relation":{},"ISSN":["1063-8016","1533-8010"],"issn-type":[{"value":"1063-8016","type":"print"},{"value":"1533-8010","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,1,1]]}}}