The Experts below are selected from a list of 126 Experts worldwide ranked by ideXlab platform
Aaron Yi Ding - One of the best experts on this subject based on the ideXlab platform.
-
ethical hacking for boosting iot vulnerability management a first look into bug bounty programs and Responsible Disclosure
International Conference on Telecommunications, 2019Co-Authors: Aaron Yi Ding, Gianluca Limon De Jesus, Marijn JanssenAbstract:The security of the Internet of Things (IoT) has attracted much attention due to the growing number of IoT-oriented security incidents. IoT hardware and software security vulnerabilities are exploited affecting many companies and persons. Since the causes of vulnerabilities go beyond pure technical measures, there is a pressing demand nowadays to demystify IoT "security complex" and develop practical guidelines for both companies, consumers, and regulators. In this paper, we present an initial study targeting an unexplored sphere in IoT by illuminating the potential of crowdsource ethical hacking approaches for enhancing IoT vulnerability management. We focus on Bug Bounty Programs (BBP) and Responsible Disclosure (RD), which stimulate hackers to report vulnerability in exchange for monetary rewards. We carried out a qualitative investigation supported by literature survey and expert interviews to explore how BBP and RD can facilitate the practice of identifying, classifying, prioritizing, remediating, and mitigating IoT vulnerabilities in an effective and cost-efficient manner. Besides deriving tangible guidelines for IoT stakeholders, our study also sheds light on a systematic integration path to combine BBP and RD with existing security practices (e.g., penetration test) to further boost overall IoT security.
-
Ethical hacking for boosting IoT vulnerability management: A first look into bug bounty programs and Responsible Disclosure
'Association for Computing Machinery (ACM)', 2019Co-Authors: Aaron Yi Ding, De Jesus, Gianluca Limon, Janssen M.f.w.h.a.Abstract:The security of the Internet of Things (IoT) has attracted much attention due to the growing number of IoT-oriented security incidents. IoT hardware and software security vulnerabilities are exploited affecting many companies and persons. Since the causes of vulnerabilities go beyond pure technical measures, there is a pressing demand nowadays to demystify IoT "security complex" and develop practical guidelines for both companies, consumers, and regulators. In this paper, we present an initial study targeting an unexplored sphere in IoT by illuminating the potential of crowdsource ethical hacking approaches for enhancing IoT vulnerability management. We focus on Bug Bounty Programs (BBP) and Responsible Disclosure (RD), which stimulate hackers to report vulnerability in exchange for monetary rewards. We carried out a qualitative investigation supported by literature survey and expert interviews to explore how BBP and RD can facilitate the practice of identifying, classifying, prioritizing, remediating, and mitigating IoT vulnerabilities in an effective and cost-efficient manner. Besides deriving tangible guidelines for IoT stakeholders, our study also sheds light on a systematic integration path to combine BBP and RD with existing security practices (e.g., penetration test) to further boost overall IoT security.Green Open Access added to TU Delft Institutional Repository ‘You share, we take care!’ – Taverne project https://www.openaccess.nl/en/you-share-we-take-care Otherwise as indicated in the copyright section: the publisher is the copyright holder of this work and the author uses the Dutch legislation to make this work public.Information and Communication Technolog
-
Ethical Hacking for IoT Security: A First Look into Bug Bounty Programs and Responsible Disclosure.
Proceedings of the Eighth International Conference on Telecommunications and Remote Sensing - ICTRS '19, 2019Co-Authors: Aaron Yi Ding, Gianluca Limon De Jesus, Marijn JanssenAbstract:The security of the Internet of Things (IoT) has attracted much attention due to the growing number of IoT-oriented security incidents. IoT hardware and software security vulnerabilities are exploited affecting many companies and persons. Since the causes of vulnerabilities go beyond pure technical measures, there is a pressing demand nowadays to demystify IoT "security complex" and develop practical guidelines for both companies, consumers, and regulators. In this paper, we present an initial study targeting an unexplored sphere in IoT by illuminating the potential of crowdsource ethical hacking approaches for enhancing IoT vulnerability management. We focus on Bug Bounty Programs (BBP) and Responsible Disclosure (RD), which stimulate hackers to report vulnerability in exchange for monetary rewards. We carried out a qualitative investigation supported by literature survey and expert interviews to explore how BBP and RD can facilitate the practice of identifying, classifying, prioritizing, remediating, and mitigating IoT vulnerabilities in an effective and cost-efficient manner. Besides deriving tangible guidelines for IoT stakeholders, our study also sheds light on a systematic integration path to combine BBP and RD with existing security practices (e.g., penetration test) to further boost overall IoT security.
-
Ethical Hacking for IoT Security: A First Look into Bug Bounty Programs and Responsible Disclosure
'Association for Computing Machinery (ACM)', 2019Co-Authors: Aaron Yi Ding, De Jesus, Gianluca Limon, Janssen MarijnAbstract:The security of the Internet of Things (IoT) has attracted much attention due to the growing number of IoT-oriented security incidents. IoT hardware and software security vulnerabilities are exploited affecting many companies and persons. Since the causes of vulnerabilities go beyond pure technical measures, there is a pressing demand nowadays to demystify IoT "security complex" and develop practical guidelines for both companies, consumers, and regulators. In this paper, we present an initial study targeting an unexplored sphere in IoT by illuminating the potential of crowdsource ethical hacking approaches for enhancing IoT vulnerability management. We focus on Bug Bounty Programs (BBP) and Responsible Disclosure (RD), which stimulate hackers to report vulnerability in exchange for monetary rewards. We carried out a qualitative investigation supported by literature survey and expert interviews to explore how BBP and RD can facilitate the practice of identifying, classifying, prioritizing, remediating, and mitigating IoT vulnerabilities in an effective and cost-efficient manner. Besides deriving tangible guidelines for IoT stakeholders, our study also sheds light on a systematic integration path to combine BBP and RD with existing security practices (e.g., penetration test) to further boost overall IoT security.Comment: Pre-print version for conference publication at ICTRS 201
Marijn Janssen - One of the best experts on this subject based on the ideXlab platform.
-
ethical hacking for boosting iot vulnerability management a first look into bug bounty programs and Responsible Disclosure
International Conference on Telecommunications, 2019Co-Authors: Aaron Yi Ding, Gianluca Limon De Jesus, Marijn JanssenAbstract:The security of the Internet of Things (IoT) has attracted much attention due to the growing number of IoT-oriented security incidents. IoT hardware and software security vulnerabilities are exploited affecting many companies and persons. Since the causes of vulnerabilities go beyond pure technical measures, there is a pressing demand nowadays to demystify IoT "security complex" and develop practical guidelines for both companies, consumers, and regulators. In this paper, we present an initial study targeting an unexplored sphere in IoT by illuminating the potential of crowdsource ethical hacking approaches for enhancing IoT vulnerability management. We focus on Bug Bounty Programs (BBP) and Responsible Disclosure (RD), which stimulate hackers to report vulnerability in exchange for monetary rewards. We carried out a qualitative investigation supported by literature survey and expert interviews to explore how BBP and RD can facilitate the practice of identifying, classifying, prioritizing, remediating, and mitigating IoT vulnerabilities in an effective and cost-efficient manner. Besides deriving tangible guidelines for IoT stakeholders, our study also sheds light on a systematic integration path to combine BBP and RD with existing security practices (e.g., penetration test) to further boost overall IoT security.
-
Ethical Hacking for IoT Security: A First Look into Bug Bounty Programs and Responsible Disclosure.
Proceedings of the Eighth International Conference on Telecommunications and Remote Sensing - ICTRS '19, 2019Co-Authors: Aaron Yi Ding, Gianluca Limon De Jesus, Marijn JanssenAbstract:The security of the Internet of Things (IoT) has attracted much attention due to the growing number of IoT-oriented security incidents. IoT hardware and software security vulnerabilities are exploited affecting many companies and persons. Since the causes of vulnerabilities go beyond pure technical measures, there is a pressing demand nowadays to demystify IoT "security complex" and develop practical guidelines for both companies, consumers, and regulators. In this paper, we present an initial study targeting an unexplored sphere in IoT by illuminating the potential of crowdsource ethical hacking approaches for enhancing IoT vulnerability management. We focus on Bug Bounty Programs (BBP) and Responsible Disclosure (RD), which stimulate hackers to report vulnerability in exchange for monetary rewards. We carried out a qualitative investigation supported by literature survey and expert interviews to explore how BBP and RD can facilitate the practice of identifying, classifying, prioritizing, remediating, and mitigating IoT vulnerabilities in an effective and cost-efficient manner. Besides deriving tangible guidelines for IoT stakeholders, our study also sheds light on a systematic integration path to combine BBP and RD with existing security practices (e.g., penetration test) to further boost overall IoT security.
Gianluca Limon De Jesus - One of the best experts on this subject based on the ideXlab platform.
-
ethical hacking for boosting iot vulnerability management a first look into bug bounty programs and Responsible Disclosure
International Conference on Telecommunications, 2019Co-Authors: Aaron Yi Ding, Gianluca Limon De Jesus, Marijn JanssenAbstract:The security of the Internet of Things (IoT) has attracted much attention due to the growing number of IoT-oriented security incidents. IoT hardware and software security vulnerabilities are exploited affecting many companies and persons. Since the causes of vulnerabilities go beyond pure technical measures, there is a pressing demand nowadays to demystify IoT "security complex" and develop practical guidelines for both companies, consumers, and regulators. In this paper, we present an initial study targeting an unexplored sphere in IoT by illuminating the potential of crowdsource ethical hacking approaches for enhancing IoT vulnerability management. We focus on Bug Bounty Programs (BBP) and Responsible Disclosure (RD), which stimulate hackers to report vulnerability in exchange for monetary rewards. We carried out a qualitative investigation supported by literature survey and expert interviews to explore how BBP and RD can facilitate the practice of identifying, classifying, prioritizing, remediating, and mitigating IoT vulnerabilities in an effective and cost-efficient manner. Besides deriving tangible guidelines for IoT stakeholders, our study also sheds light on a systematic integration path to combine BBP and RD with existing security practices (e.g., penetration test) to further boost overall IoT security.
-
Ethical Hacking for IoT Security: A First Look into Bug Bounty Programs and Responsible Disclosure.
Proceedings of the Eighth International Conference on Telecommunications and Remote Sensing - ICTRS '19, 2019Co-Authors: Aaron Yi Ding, Gianluca Limon De Jesus, Marijn JanssenAbstract:The security of the Internet of Things (IoT) has attracted much attention due to the growing number of IoT-oriented security incidents. IoT hardware and software security vulnerabilities are exploited affecting many companies and persons. Since the causes of vulnerabilities go beyond pure technical measures, there is a pressing demand nowadays to demystify IoT "security complex" and develop practical guidelines for both companies, consumers, and regulators. In this paper, we present an initial study targeting an unexplored sphere in IoT by illuminating the potential of crowdsource ethical hacking approaches for enhancing IoT vulnerability management. We focus on Bug Bounty Programs (BBP) and Responsible Disclosure (RD), which stimulate hackers to report vulnerability in exchange for monetary rewards. We carried out a qualitative investigation supported by literature survey and expert interviews to explore how BBP and RD can facilitate the practice of identifying, classifying, prioritizing, remediating, and mitigating IoT vulnerabilities in an effective and cost-efficient manner. Besides deriving tangible guidelines for IoT stakeholders, our study also sheds light on a systematic integration path to combine BBP and RD with existing security practices (e.g., penetration test) to further boost overall IoT security.
-
enhancing vulnerability management for iot devices with bug bounty programs and Responsible Disclosure
2019Co-Authors: Gianluca Limon De JesusAbstract:The Internet of Things (IoT) will soon impact the lives of thousands of people as numerous IoT devices are emerging in the consumer market. Consumers goods consist of products designed for the consumption of final consumers. Even though IoT applications are expected to improve people's lives, security is often lacking in current IoT devices. Vulnerabilities in these type of products pose serious risks to the security and privacy of consumers. Compared to traditional electronics, IoT devices are endowed with internet connectivity that can be exploited by hackers in remote attacks. Several attacks on IoT products that can threaten the security of a large of number actors have already been observed. To minimize the risk of attacks, developers and vendors need to identify vulnerabilities in time before any malevolent individual can exploit them. In recent years, as part of vulnerability management practices, many organizations have started to implement crowdsourced security methods such as Bug Bounty Programs (BBPs) and Responsible Disclosure Policies (RDPs). BBPs and RDPs are programs that involve the participation of ethical hackers in the security processes of organizations, reporting vulnerabilities to companies in exchange for monetary rewards or recognition. These methods present the benefit that thousands of hackers can work together with companies to identify and patch vulnerabilities. Empirical research suggests that BBPs and RDPs effectively augment existing vulnerability management practices by companies. However, the application of these programs in the field of IoT has never been studied. There are many questions open regarding the potential and future adoption of Bug Bounty Programs and Responsible Disclosure Policies. The research aim is to study and expand the literature on security practices for IoT, focusing on the application of BBPs and RDPs, and to conduct an interview-based investigation with experts in order to provide practical recommendations for companies to enhance vulnerability management practices for IoT consumer goods. For this research, the literature on IoT security and security practices is confronted with empirical data from expert interviews. The empirical data was gathered during an internship at Deloitte in the Netherlands. In total, 19 interviews with cybersecurity experts from different companies in the field were collected for this thesis. The results are employed to generate recommendations for companies to improve their vulnerability management practices with the use of BBPs and RDPs. The recommendations are directed to companies developing, manufacturing, and commercializing consumer IoT devices that want to enhance the security of their products. The main contributions of this research consist of practical and tangible security recommendations for companies to tackle IoT vulnerabilities in consumer goods, which will help enhance the overall IoT security practices. Moreover, our findings raise attention on the societal risks derived from the unsafe deployment of vulnerable IoT products into the consumer market. We create awareness on the IoT security challenge, and present a call for further actions from companies, consumers, and regulators in the IoT domain.
Fritz Mario - One of the best experts on this subject based on the ideXlab platform.
-
Responsible Disclosure of Generative Models Using Scalable Fingerprinting
2021Co-Authors: Yu Ning, Skripniuk Vladislav, Chen Dingfan, Davis Larry, Fritz MarioAbstract:Over the past six years, deep generative models have achieved a qualitatively new level of performance. Generated data has become difficult, if not impossible, to be distinguished from real data. While there are plenty of use cases that benefit from this technology, there are also strong concerns on how this new technology can be misused to spoof sensors, generate deep fakes, and enable misinformation at scale. Unfortunately, current deep fake detection methods are not sustainable, as the gap between real and fake continues to close. In contrast, our work enables a Responsible Disclosure of such state-of-the-art generative models, that allows researchers and companies to fingerprint their models, so that the generated samples containing a fingerprint can be accurately detected and attributed to a source. Our technique achieves this by an efficient and scalable ad-hoc generation of a large population of models with distinct fingerprints. Our recommended operation point uses a 128-bit fingerprint which in principle results in more than $10^{36}$ identifiable models. Experiments show that our method fulfills key properties of a fingerprinting mechanism and achieves effectiveness in deep fake detection and attribution. Code and models are available at GitHub
Mario Fritz - One of the best experts on this subject based on the ideXlab platform.
-
Responsible Disclosure of generative models using scalable fingerprinting
arXiv: Cryptography and Security, 2020Co-Authors: Vladislav Skripniuk, Dingfan Chen, Larry S Davis, Mario FritzAbstract:Over the past six years, deep generative models have achieved a qualitatively new level of performance. Generated data has become difficult, if not impossible, to be distinguished from real data. While there are plenty of use cases that benefit from this technology, there are also strong concerns on how this new technology can be misused to spoof sensors, generate deep fakes, and enable misinformation at scale. Unfortunately, current deep fake detection methods are not sustainable, as the gap between real and fake continues to close. In contrast, our work enables a Responsible Disclosure of such state-of-the-art generative models, that allows researchers and companies to fingerprint their models, so that the generated samples containing a fingerprint can be accurately detected and attributed to a source. Our technique achieves this by an efficient and scalable ad-hoc generation of a large population of models with distinct fingerprints. Our recommended operation point uses a 128-bit fingerprint which in principle results in more than $10^{36}$ identifiable models. Experiments show that our method fulfills key properties of a fingerprinting mechanism and achieves effectiveness in deep fake detection and attribution.