Welcome Guest. | Log In | Register | Membership Benefits

Secunia Launches Vulnerability Coordination Reward Program

Researchers to be rewarded for coordinating software vulnerabilities

Nov 02, 2011 | 11:52 AM | 


Vulnerability researchers are being invited by Secunia, the leading provider of vulnerability intelligence and vulnerability management tools, to participate in a new programme launched today under which Secunia, independently of any software vendor, will confirm vulnerability discoveries and handle coordination with the vendor on the researchers’ behalf.

The programme, entitled The Secunia Vulnerability Coordination Reward Programme (SVCRP) is open to any researcher who has discovered vulnerability in any software and would like a third party to confirm their findings and handle the co-ordination process with the software vendor for them. As part of the programme, Secunia will offer rewards to researchers who contact them with vulnerabilities they have found and who wish Secunia to coordinate them with the vendor. This comprehensive programme is designed to be complementary to those run by other organisations and will cover all vulnerabilities as long as they meet Secunia’s criteria.

Carsten Eiram, Chief Security Specialist at Secunia, explains, "The fun part of vulnerability research is the actual process of discovering and understanding the vulnerabilities as well as creating proof of concepts or exploits; and not the sometimes extensive coordination and liaison process that follows with the vendor in order to fix the problem. Under the new programme we will both confirm vulnerability discoveries and handle the coordination process, allowing researchers to focus on the more exciting aspects of vulnerability research."

He continued, "Other major vulnerability coordination offerings exist but most have a business model wrapped around them. SVCRP is designed to be a complementary service to these. Most other schemes pay researchers for their discoveries, and, while these offerings are excellent for researchers, the companies are, naturally, very selective in which vulnerabilities they wish to purchase and coordinate. This leaves a huge gap for researchers, who either do not want to sell their vulnerabilities or discover vulnerabilities not fulfilling the requirements of the existing initiatives, but who would still like an independent third party to confirm their discoveries and handle coordination.

Some of these researchers have in the past turned to Secunia for help on an informal basis and we now want to encourage even more researchers to allow us to help coordinate their vulnerability discoveries by providing this reward incentive."

The main benefit to independent researchers is that Secunia offers the expertise to assess and validate the vulnerability, and saves them time and effort in coordinating directly with the vendor to fix the vulnerability, thus allowing them to deal with other priorities as well as giving added weight to their findings.

Benefits to vendors include the fact that vulnerability discoveries from the researchers will be confirmed in great detail by Secunia to determine the core problem in the code. As a result, vendors will receive very precise information about the vulnerability, and Secunia will also work with them to find a complete fix, providing feedback and helping them confirm that their new patches are properly addressing the vulnerabilities prior to release. This should mean quicker investigation and thorough fix of the software problem. In addition, both researchers and vendors will benefit from having a trusted and independent third party such as Secunia to act as an intermediary.

Users will benefit since, as Secunia is able to undertake comprehensive and extensive coordination of vulnerabilities discovered by the researcher, there is likely to be an increase in the number being coordinated with the vendor. This should in turn lead to a greater number of complete solutions to software problems, ultimately leading to more reliable software and therefore more efficient working.

All classes of vulnerability across most products are eligible for the SVCRP programme as long as the following criteria are met:-

- The vulnerability affects a stable product

- The vulnerability affects the latest version of the product

- The product is actively supported by the vendor

- The vulnerability is not already publicly known

- Secunia Research is able to confirm the reported vulnerability.

No Secunia customers will receive any advance notification about the vulnerabilities coordinated by Secunia, whether they are internal discoveries or vulnerabilities coordinated via this reward incentive. All customers, as well as the community at large, will receive the information simultaneously when the Secunia advisory is published. Researchers will continue to receive any payments to which they are entitled from vendors for coordinating vulnerabilities. Secunia will confirm the vulnerabilities through testing in their extensive and independent laboratory testing facilities, but will not receive any money or other reward from vendors either for confirming or for coordinating the vulnerability on behalf of the researcher.

The rewards on offer will range from top-of-the range merchandise to two major annual rewards such as free hotel accommodation and entry to an IT security conference chosen from a list of the most popular global security conferences. The latter rewards will be given for the first time in January 2012. One reward will be given to the researcher who coordinates the most interesting vulnerability as judged by Secunia in the form of a prize under the Most Interesting Coordination Report category. Criteria will include complexity, impact, level and level of detail. The other will be given to the researcher who has been consistently coordinating correct, clearly detailed vulnerability reports that are quick and easy to confirm as judged by Secunia. The researcher will be given the title, ‘Most Valued Contributor’ by Secunia. Other rewards will be continuously given to researchers coordinating their discoveries through Secunia based on their individual performance.

There is no charge or enrolment process for researchers to participate in the programme, which forms part of several initiatives from Secunia to benefit the community.

Note to Editors

About Secunia

Founded in 2002, Secunia is the leading provider of IT security solutions that help businesses and private individuals globally manage and control vulnerability threats, risks across their networks, and endpoints. This is enabled by Secunia's award-winning Vulnerability Intelligence, Vulnerability Assessment, and Patch Management solutions that ensure optimal and cost-effective protection of critical information assets.



Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

Dark Reading encourages readers to engage in spirited, healthy debate, including taking us to task. However, Dark Reading moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. Dark Reading further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
Subscribe to RSS



Vulnerability Management Reports

report Choosing the Right Vulnerability Scanner for Your Organization
Vulnerability scanners can be used to help detect and fix systemic problems in an organization's security program and monitor the effectiveness of security controls. However, a vulnerability scanner can improve the organization?s security posture only when it is used as part of a vulnerability management program, in which products, processes and people are working together to find, identify, prioritize and mitigate threats. Here are some tips on choosing and implementing vulnerability scanners in your enterprise.

report Using Google to Find Vulnerabilities In Your IT Environment
Attackers are increasingly using a simple method for finding flaws in websites and applications: they Google them. Using Google code search, hackers can identify crucial vulnerabilities in application code strings, providing the entry point they need to break through application security. Sound scary? It is, but there is good news: You can use these same methods to find flaws before the bad guys do. In this special report, we outline methods for using search engines such as Google and Bing to identify vulnerabilities in your applications, systems and services--and to fix them before they can be exploited.

report Security Pro's Guide to Patch Management
It's no longer sufficient to patch just Windows, Office and IE. With the massive array of applications now residing on enterprise PCs, and the proliferation of mobile and cloud-based applications, your business is far too vulnerable to exploitation unless you have a solid strategy for patch prioritization, deployment and quality assurance. Follow these steps to put your plan in place.

Other reports from the Vulnerability Management Tech Center:




Featured Webcasts
Featured Whitepapers
Featured Reports