Observations From an Online Security Competition and Its Implications on Crowdsourced Security

04/26/2022
by   Alejandro Cuevas, et al.
0

The crowd sourced security industry, particularly bug bounty programs, has grown dramatically over the past years and has become the main source of software security reviews for many companies. However, the academic literature has largely omitted security teams, particularly in crowd work contexts. As such, we know very little about how distributed security teams organize, collaborate, and what technology needs they have. We fill this gap by conducting focus groups with the top five teams (out of 18,201 participating teams) of a computer security Capture-the-Flag (CTF) competition. We find that these teams adopted a set of strategies centered on specialties, which allowed them to reduce issues relating to dispersion, double work, and lack of previous collaboration. Observing the current issues of a model centered on individual workers in security crowd work platforms, our study cases that scaling security work to teams is feasible and beneficial. Finally, we identify various areas which warrant future work, such as issues of social identity in high-skilled crowd work environments.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
12/29/2022

Voices of Workers: Why a Worker-Centered Approach to Crowd Work Is Challenging

How can we better understand the broad, diverse, shifting, and invisible...
research
02/15/2021

Self-Organizing Teams in Online Work Settings

As the volume and complexity of distributed online work increases, the c...
research
11/13/2022

Collaborative Application Security Testing for DevSecOps: An Empirical Analysis of Challenges, Best Practices and Tool Support

DevSecOps is a software development paradigm that places a high emphasis...
research
10/30/2018

The effect of multidisciplinary collaborations on research diversification

This work verifies whether research diversification by a scientist is in...
research
05/21/2023

CoSINT: Designing a Collaborative Capture the Flag Competition to Investigate Misinformation

Crowdsourced investigations shore up democratic institutions by debunkin...
research
09/13/2021

Forensics for Microsoft Teams

Microsoft Teams is a collaboration and communication platform developed ...
research
11/08/2017

A Cross-Country Comparison of Crowdworker Motivations

Crowd employment is a new form of short term employment that has been ra...

Please sign up or login with your details

Forgot password? Click here to reset