EconPapers    
Economics at your fingertips  
 

Artificial Bugs for Bug Bounty

Hans Gersbach, Fikri Pitsuwan () and Pio Blieske

No 19047, CEPR Discussion Papers from Centre for Economic Policy Research

Abstract: Bug bounty programs, where external agents are invited to search and report vulnerabilities (bugs) in exchange for rewards (bounty), have become a major tool for companies to improve their systems. We suggest augmenting such programs by inserting artificial bugs to increase the incentives to search for real (organic) bugs. Using a model of crowdsearch, we identify the efficiency gains by artificial bugs, and we show that for this, it is sufficient to insert only one artificial bug. Artificial bugs are particularly beneficial, for instance, if the designer places high valuations on finding organic bugs or if the budget for bounty is not sufficiently high. We discuss how to implement artificial bugs and outline their further benefits.

Keywords: Crowdsearch; Bug Bounty; Artificial Bug; Cybersecurity (search for similar items in EconPapers)
JEL-codes: C72 D82 M52 (search for similar items in EconPapers)
Date: 2024-05
References: Add references at CitEc
Citations:

Downloads: (external link)
https://cepr.org/publications/DP19047 (application/pdf)

Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.

Export reference: BibTeX RIS (EndNote, ProCite, RefMan) HTML/Text

Persistent link: https://EconPapers.repec.org/RePEc:cpr:ceprdp:19047

Ordering information: This working paper can be ordered from
https://cepr.org/publications/DP19047

Access Statistics for this paper

More papers in CEPR Discussion Papers from Centre for Economic Policy Research 33 Great Sutton Street, London EC1V 0DX, UK.
Bibliographic data for series maintained by CEPR ().

 
Page updated 2026-05-29
Handle: RePEc:cpr:ceprdp:19047