Vulnerability Discovery for All: Experiences of Marginalization in Vulnerability Discovery

Kelsey R. Fulton, Samantha Katcher, Kevin Song, M. Chetty, Michelle L. Mazurek, Chloé Messdaghi, Daniel Votipka
{"title":"Vulnerability Discovery for All: Experiences of Marginalization in Vulnerability Discovery","authors":"Kelsey R. Fulton, Samantha Katcher, Kevin Song, M. Chetty, Michelle L. Mazurek, Chloé Messdaghi, Daniel Votipka","doi":"10.1109/SP46215.2023.10179478","DOIUrl":null,"url":null,"abstract":"Vulnerability discovery is an essential aspect of software security. Currently, the demand for security experts significantly exceeds the available vulnerability discovery workforce. Further, the existing vulnerability discovery workforce is highly homogeneous, dominated by white and Asian men. As such, one promising avenue for increasing the capacity of the vulnerability discovery community is through recruitment and retention from a broader population. Although significant prior research has explored the challenges of equity and inclusion in computing broadly, the competitive and frequently self-taught nature of vulnerability discovery work may create new variations on these challenges. This paper reports on a semi-structured interview study (N = 16) investigating how people from marginalized populations come to participate in vulnerability discovery, whether they feel welcomed by the vulnerability discovery community, and what challenges they face when joining the vulnerability discovery community. We find that members of marginalized populations face some unique challenges, while other challenges common in vulnerability discovery are exacerbated by marginalization.","PeriodicalId":439989,"journal":{"name":"2023 IEEE Symposium on Security and Privacy (SP)","volume":"19 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2023-05-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"6","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2023 IEEE Symposium on Security and Privacy (SP)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/SP46215.2023.10179478","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 6

Abstract

Vulnerability discovery is an essential aspect of software security. Currently, the demand for security experts significantly exceeds the available vulnerability discovery workforce. Further, the existing vulnerability discovery workforce is highly homogeneous, dominated by white and Asian men. As such, one promising avenue for increasing the capacity of the vulnerability discovery community is through recruitment and retention from a broader population. Although significant prior research has explored the challenges of equity and inclusion in computing broadly, the competitive and frequently self-taught nature of vulnerability discovery work may create new variations on these challenges. This paper reports on a semi-structured interview study (N = 16) investigating how people from marginalized populations come to participate in vulnerability discovery, whether they feel welcomed by the vulnerability discovery community, and what challenges they face when joining the vulnerability discovery community. We find that members of marginalized populations face some unique challenges, while other challenges common in vulnerability discovery are exacerbated by marginalization.
漏洞发现:在漏洞发现边缘化的经验
漏洞发现是软件安全的一个重要方面。目前,对安全专家的需求大大超过了可用的漏洞发现劳动力。此外,现有的漏洞发现工作人员高度同质化,主要由白人和亚洲男性组成。因此,增加漏洞发现社区的能力的一个有希望的途径是通过从更广泛的人群中招募和保留。虽然重要的先前研究已经广泛地探索了计算中的公平和包容的挑战,但漏洞发现工作的竞争性和经常自学的性质可能在这些挑战上创造新的变化。本文报告了一项半结构化访谈研究(N = 16),调查了边缘人群如何参与漏洞发现,他们是否感到受到漏洞发现社区的欢迎,以及他们在加入漏洞发现社区时面临哪些挑战。我们发现,边缘化人群面临着一些独特的挑战,而在脆弱性发现中常见的其他挑战则因边缘化而加剧。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信