KRIŠTOFÍK, Andrej, Jakub VOSTOUPAL, Kamil MALINKA, František KASL and Pavel LOUTOCKÝ. Beyond the Bugs: Enhancing Bug Bounty Programs through Academic Partnerships. Online. In ARES '24: Proceedings of the 19th International Conference on Availability, Reliability and Security. New York: Association for Computing Machinery, 2024, p. 1-8. Available from: https://dx.doi.org/10.1145/3664476.3670455.
Other formats:   BibTeX LaTeX RIS
Basic information
Original name Beyond the Bugs: Enhancing Bug Bounty Programs through Academic Partnerships
Authors KRIŠTOFÍK, Andrej, Jakub VOSTOUPAL, Kamil MALINKA, František KASL and Pavel LOUTOCKÝ.
Edition New York, ARES '24: Proceedings of the 19th International Conference on Availability, Reliability and Security, p. 1-8, 8 pp. 2024.
Publisher Association for Computing Machinery
Other information
Original language English
Type of outcome Proceedings paper
Field of Study 50501 Law
Country of publisher United States of America
Confidentiality degree is not subject to a state or trade secret
Publication form electronic version available online
WWW URL
Organization unit Faculty of Law
Doi http://dx.doi.org/10.1145/3664476.3670455
Keywords in English Cybersecurity; Bug Bounty; ethical hacking; education; curriculums
Tags International impact, Reviewed
Changed by Changed by: Mgr. Andrej Krištofík, učo 458349. Changed: 1/8/2024 16:07.
Abstract
This paper explores the growing significance of vulnerability disclosure and bug bounty programs within the cybersecurity landscape, driven by regulatory changes in the European Union. The effectiveness of these programs relies heavily on the expertise of participants, presenting a challenge amid a shortage of skilled cybersecurity professionals, particularly in less sought-after sectors. To address this issue, the paper proposes a collaborative approach between academia and bug bounty issuers. By integrating bug bounty programs into cybersecurity courses, students gain practical skills and soft skills essential for bug hunting and cybersecurity work. The collaboration benefits both issuers, who gain manageable manpower, and students, who receive valuable hands-on experience. A pilot conducted during the current academic year yielded positive results, indicating the potential of this approach to address the demand for skilled cybersecurity professionals. The insights gained from the pilot inform future considerations and advancements in this collaborative model.
Links
VJ03030052, research and development projectName: Rozvoj kapacit v oblasti kyberbezpečnosti
Investor: Ministry of the Interior of the CR, Capacity building in cybersecurity
PrintDisplayed: 22/8/2024 09:43