Big Data. Big Decisions
InformationWeek
Special Coverage Series

Commentary

Mathew J. Schwartz

Mathew J. Schwartz



So You Want To Be A Zero Day Exploit Millionaire?

On the active market for reporting and selling zero day vulnerabilities, you can make big money. But you'll have to answer difficult ethical questions.

Have you discovered a killer zero-day vulnerability in a widely used product? Can the bug be "weaponized," or actively exploited?

Then you could make thousands of dollars or more by selling it to TippingPoint's Zero Day Initiative (ZDI), the iDefense Vulnerability Contributor Program, or one of 20 other legal and public programs that reward bug hunters. Or make even more money--perhaps 10 times as much--by selling it on the black market, or to a defense contractor. In the case of defense contractors, you'll get paid in stages, dependent on there being no public knowledge of the bug for a preset period of time, thus giving their customers time to put the information to use.

More Insights

Webcasts

More >>

White Papers

More >>

Reports

More >>

The reason defense contractors and security firms pay big bucks for this information is because their customers--including governments--then know that their adversaries don't have it. Accordingly, they can take precautions to defend themselves against the vulnerability, or potentially even use it themselves for industrial espionage purposes.

With all of the effort that businesses devote to patching and preventing their corporate networks and systems from being exploited, it might seem surprising that there's a thriving trade in zero-day vulnerabilities, predicated on keeping knowledge of these vulnerabilities out of the public domain. And regardless of whether you think it is right or wrong, the practice exists.

Thankfully, the discovery of high-value bugs is apparently the exception, not the rule. "The problem is that a lot of vulnerabilities today aren't worth being sold," says Marc Maiffret, CTO of eEye. For proof, just peruse the ExploitHub market from NSS Labs, which sells exploits--but only for known vulnerabilities. There you'll currently find lots of exploits worth a few hundred dollars, and one or two involving Oracle database vulnerabilities (of which there's seemingly an endless supply) worth about $1,000. These are hardly big-ticket exploits.

For security researchers with knowledge of a bug that's not worth much, or for researchers who question the ethics of selling any bug information, there are alternatives. Last week, for example, vulnerability information service Secunia launched its Secunia Vulnerability Coordination Reward Program, which formalizes what Secunia says it's been doing informally for some time: It acts as a go-between for security researchers that have discovered a vulnerability in a product, and the vendor of that product. "Many researchers have appreciated that we take out all of the tedious communication with the vendor," says Thomas Kristensen CSO of Secunia. (Any interested security researchers can report their vulnerability to vul@secunia.com.)

The "reward" part of the program is that two top researchers per year will get their hotel and conference fees covered for a security conference, while other top-performers will get some free high-end security merchandise. In return, Secunia sees no remuneration, although will sometimes get a mention--"coordinated by Secunia"--in any resulting security bulletins. So far this year, Secunia has coordinated between researchers and vendors on 234 vulnerabilities, involving 118 security advisories.

Furthermore, in cases where there's a cash reward offered for bugs--for example, from Google--Secunia says that money will go straight to the researcher. But Secunia says it won't coordinate between researchers and programs such as ZDI, because they violate Secunia's bug disclosure policy, which specifies that "there's no disclosure of information to anyone"--including Secunia's customers--"until a vendor chooses to patch the vulnerability, or they've been dragging out the coordination for longer than 12 months," says Kristensen. (After 12 months, Secunia releases the information, though Kristensen said few vendors drag their heels for this long.)

Compared with that type of policy, information on zero-day vulnerabilities that's bought and sold on vulnerability markets may stay in private hands much longer. But, do such practices jeopardize security for the many, while safeguarding just the few? "It's a tradeoff, it's a hard thing, because with any vulnerability like that, you're leaving people potentially at risk," says eEye's Maiffret. "Then when you see the power of zero-day vulnerabilities, such as Stuxnet, taking out the nuclear capabilities of Iran, some people would say that that increased risk is probably worth it."

Stuxnet famously included not one, but an unprecedented four zero-day vulnerabilities to ensure that the malware successfully infiltrated its target. By many accounts, it worked. Still, it's not clear whether Stuxnet's authors discovered the zero-day vulnerabilities themselves, procured them from a legal market, or bought them on the black market.

While the buying and selling of zero-day vulnerabilities sounds alarming, however, it turns out that attackers largely don't bother to exploit them, likely because there are already so many known--but unpatched--vulnerabilities to work with. Furthermore, it's rare that bad guys will independently discover a zero-day vulnerability that's known but hasn't been reported, says Maiffret.

Furthermore, as highlighted by Verizon's Data Breach Investigations Report, patching alone isn't enough to keep a business secure, since by Verizon's count, in 381 attacks, only five vulnerabilities were exploited by attackers. (Notably, however, the report failed to count all-too-common SQL injections as vulnerabilities.)

"We're very much in the day and age where you have to act like there are vulnerabilities you don't know about," says Maiffret. "If your main points of defense are antivirus and making sure that systems are patched, then you're just going to fail. There's just too much out there, both in terms of vulnerabilities and malware."

Accordingly, instead of worrying about exploits for undiscovered bugs, businesses should really "understand the importance of good configuration, and good architecture, and how to minimize your company's attack surface," says Maiffret. "A lot of it isn't sexy stuff," he concedes, since it involves best practices for system and network configuration. Nevertheless, it goes quite a long way to mitigating modern exploits.



Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

BYTE encourages readers to engage in spirited, healthy debate, including taking us to task. However, BYTE moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. BYTE further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.

Follow InformationWeek

By The Numbers

What Are Your Primary Concerns About Using Big Data Software?

Base: 417 respondents at organizations using or planning to deploy data analytics, BI or statistical analysis software
Data: InformationWeek 2013 Analytics, Business Intelligence and Information Management Survey of 541 business technology professionals, October 2012

What Do You Think?

What's your attitude about SQL analysis on top of Hadoop?
We want fast, standard SQL analysis capabilities on Hadoop ASAP
Hadoop is for unstructured data; SQL is for relational databases
We'll give SQL on Hadoop a try, but relational DBs will remain the mainstay
Given strong SQL support on Hadoop, we'd nix the data warehouse
We're not interested in Hadoop
No opinion



Related Content

From Our Sponsor

Five Big Data Challenges and How to Overcome Them with Visual Analytics

Five Big Data Challenges and How to Overcome Them with Visual Analytics

Business leaders often need a visual snapshot of data to quickly grasp and use it. This paper identifies five challenges in presenting data and how visual analytics can resolve them. Solutions are suggested to overcome the challenges of: speed, data clarity, data quality, displaying meaningful results, and dealing with outliers.

Game-Changing Analytics: How IT Executives Can Use Analytics to Create Innovation and Business Success

Game-Changing Analytics: How IT Executives Can Use Analytics to Create Innovation and Business Success

Today's competitive advantage requires a deeper understanding of your business, your market and your customers. As an IT executive, you can drive that knowledge transformation. In this white paper, learn how to make decisions as a strategic business leader and three steps to begin an analytics initiative within your enterprise.

Data Visualization Techniques: From Basics to Big Data with SAS Visual Analytics

Data Visualization Techniques: From Basics to Big Data with SAS Visual Analytics

High-performance data visualization turns sophisticated analyses into meaningful graphics, leading to faster and smarter decision making. In this white paper, learn how visual analytics can transform big data, with additional features such as real-time functionality, mobile compatibility, robust applications for technical groups and accessibility for nontechnical users.

Big Data: Lessons from the Leaders

Big Data: Lessons from the Leaders

Financial performance, competitive advantage, operational efficiency, strategic decision making - every business goal can extract value from big data, and the time for doubt or inaction has long passed. In this Economist Intelligence Unit report, in-depth interviews with data pioneers reveal the link between the effective use of big data and the bottom line among other results.

Decision-Driven Data Management: A Strategy for Better Decisions with Better Data

Decision-Driven Data Management: A Strategy for Better Decisions with Better Data

Which came first, the data or the decision? This white paper makes the case for having a decision in mind, then tailoring big data's volume, variety and velocity to achieve business results such as overcoming customer dissatisfaction or creating well-informed strategies in real time.

Informationweek Reports

Research: The Big Data Management Challenge

Research: The Big Data Management Challenge

The challenge of big data is real, but most organizations don't differentiate 'big data' from traditional data, and nearly 90% of respondents to our survey use conventional databases as the primary means of handling data. We'll help you understand what constitutes big data (it's not just size) and the numerous management challenges it poses.