Threat Intelligence

12/12/2018
04:00 PM
Connect Directly
Twitter
LinkedIn
Google+
RSS
E-Mail
50%
50%

Bug Hunting Paves Path to Infosec Careers

Ethical hackers use bug bounty programs to build the skills they need to become security professionals.

Current and future cybersecurity professionals are using bug bounty programs to gain skills they can use to become security analysts, CISOs, or, in some cases, full-time vulnerability hunters.

As part of its 2018 "Inside the Mind of a Hacker" report, researchers at Bugcrowd polled 65,000 hackers from around the world to better understand who they are, what motivates them, and the sustainability of a hacker career. Most (81%) respondents credit bug hunting with helping them land a job in the security field, and many continue to use it to supplement full-time roles.

Five to 10 years ago, there weren't enough bug bounty programs to turn the practice into a full-time position, says Jason Haddix, vice president of researcher growth at Bugcrowd. Now there is more opportunity: The top 50 hackers' average yearly payout is $145,000, with over 600 valid submissions. The average payout per bug across the platform is $783.

Still, more people prefer to bug hunt on the side while working other jobs or attending university. Students spend 10 to 20 hours per week on ethical hacking, Haddix explains, and 66% of all Bugcrowd respondents spend up to 10 hours per week bug hunting. The practice is giving them valuable skills they can use to help fill the growing security talent gap.

"One of the things that was cool about this report was the amount the hunters are using this experience – finding vulnerabilities and bug bounties – to find jobs in security," Haddix says. It's an interesting educational path in a field where traditional college programs struggle to keep up.

Nearly 41% of bug hunters teach themselves and 43% use blogs and online resources to learn the skills they need. It's a highly motivated group: Nearly 32% want to be full-time bug hunters, 15% aspire to be security engineers at major tech companies, and 6% are training to be CISOs.

The Best Education Is Experience
You don't need a lot of experience to get into ethical hacking, Haddix points out. While 41.5% of hackers polled have three or more years of professional security experience, close to 30% only have one to two years, and 14.3% have no security experience at all. Bugcrowd's hackers are relatively young, with nearly all (94%) between the ages of 18 to 44 and 71.5% between the ages of 18 and 29.

Higher education is still popular; 80% of respondents have attended college. But the percentage of those with a master's degree (18%) matches the percentage of those who have a high school education or less. "Formal education is becoming the road less traveled," Bugcrowd reports. Bug hunters have both the skills and experience companies look for in security job candidates.

"It's powerful to say, 'Instead of taking a certification or class, I found a critical vulnerability on a Fortune 500 company,'" Haddix explains. What's more, they can offer proof of their expertise with a bug disclosure or status on a leaderboard. It goes "leaps farther" than a certification, he says.

The most prominent skill bug hunters learn is Web application hacking, which Haddix says makes up the biggest portion of today's bug bounties. For those getting started, learning Web application testing is a good gateway into ethical hacking – and where the most opportunity is. Most university courses don't dig into Web hacking, he adds, and online resources provide wannabe hackers with fake vulnerable applications they can dig into for practice.

"Practical experience is the one thing you seem to lack in today's security researchers," Haddix adds. "We need people with experience. New people are having a hard time getting into security."

Related Content:

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
New Free Tool Scans for Chrome Extension Safety
Dark Reading Staff 2/21/2019
Making the Case for a Cybersecurity Moon Shot
Adam Shostack, Consultant, Entrepreneur, Technologist, Game Designer,  2/19/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
5 Emerging Cyber Threats to Watch for in 2019
Online attackers are constantly developing new, innovative ways to break into the enterprise. This Dark Reading Tech Digest gives an in-depth look at five emerging attack trends and exploits your security team should look out for, along with helpful recommendations on how you can prevent your organization from falling victim.
Flash Poll
How Enterprises Are Attacking the Cybersecurity Problem
How Enterprises Are Attacking the Cybersecurity Problem
Data breach fears and the need to comply with regulations such as GDPR are two major drivers increased spending on security products and technologies. But other factors are contributing to the trend as well. Find out more about how enterprises are attacking the cybersecurity problem by reading our report today.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-10078
PUBLISHED: 2019-02-23
Vembu StoreGrid 4.4.x has XSS in interface/registercustomer/onlineregsuccess.php, interface/registerreseller/onlineregfailure.php, interface/registerclient/onlineregfailure.php, and interface/registercustomer/onlineregfailure.php.
CVE-2014-10079
PUBLISHED: 2019-02-23
In Vembu StoreGrid 4.4.x, the front page of the server web interface leaks the private IP address in the "ipaddress" hidden form value of the HTML source code, which is disclosed because of incorrect processing of an index.php/ trailing slash.
CVE-2018-20785
PUBLISHED: 2019-02-23
Secure boot bypass and memory extraction can be achieved on Neato Botvac Connected 2.2.0 devices. During startup, the AM335x secure boot feature decrypts and executes firmware. Secure boot can be bypassed by starting with certain commands to the USB serial port. Although a power cycle occurs, this d...
CVE-2019-9037
PUBLISHED: 2019-02-23
An issue was discovered in libmatio.a in matio (aka MAT File I/O Library) 1.5.13. There is a buffer over-read in the function Mat_VarPrint() in mat.c.
CVE-2019-9038
PUBLISHED: 2019-02-23
An issue was discovered in libmatio.a in matio (aka MAT File I/O Library) 1.5.13. There is an out-of-bounds read problem with a SEGV in the function ReadNextCell() in mat5.c.