Real Time Communications Industry News

TMCNet:  Veracode Studies the Effectiveness of Bug Bounty Programs [Professional Services Close - Up]

[February 01, 2013]

Veracode Studies the Effectiveness of Bug Bounty Programs [Professional Services Close - Up]

(Professional Services Close - Up Via Acquire Media NewsEdge) Veracode, Inc., a company focusing on cloud-based application security testing, has released an infographic that examines the success of bug bounty programs.

According to a release, the past decade has witnessed major growth in demand for bug hunters, with online giants such as Google, Mozilla, Facebook, and PayPal turning to bug bounty programs to improve the security of their products. Organizations are currently paying security researchers anywhere from hundreds to tens of thousands of dollars per vulnerability; however, this approach still leaves many applications vulnerable to attacks.


Veracode's infographic, titled "Can Bug Hunters Keep the Internet Safe " takes a look at which companies are relying on bounty programs for security findings, and compares market rates for discovering and reporting different types of vulnerabilities. In addition to paid bounty programs, the infographic details which companies have implemented unpaid bug hunting or responsible disclosure programs.

The infographic uses data from Veracode scans to demonstrate the current state of security in vendor-supplied web applications and concludes with Veracode's recommendations for creating effective vendor application security testing programs.

"The fact that we're seeing all of these bug bounty programs shows that more organizations are getting serious about security, which is a positive sign." said Chris Eng, vice president of research, Veracode. "But implementing a bounty program is only one step towards creating a comprehensive security program." Veracode recommends developing a programmatic approach to vendor software security that is built on thorough policies, open communication, vendor education, and collaboration between vendors and enterprises.

More information: www.veracode.com/blog/2013/01/can-bug-hunters-keep-the-internet- safe-infographic www.veracode.com ((Comments on this story may be sent to newsdesk@closeupmedia.com)) (c) 2013 ProQuest Information and Learning Company; All Rights Reserved.

[ Back To Real Time Communications's Homepage ]

Featured Videos

GenView Real Time Session Manager Demo

Session-based VoIP and rich media services such as video can place unique demands on the network.

GENBAND SPiDR - WebRTC Gateway

Contact GENBAND about the SPiDRâ„¢ WebRTC Gateway by clicking here.

A videoconference that calls you

On the busiest of days, who has time to stop and search for that bridge information, to have to dial or hope the link works...only to wait for the chairperson to arrive?

Call Grabber Demo

Move calls seamlessly between phones, soft clients and mobile devices at the push of a button.

Hosted Unified Communications

GENBAND's Hosted Unified Communications is a SMART OFFICE™ solution that enables voice over broadband to Business users, providing flexible migration from legacy services, supporting full regulatory features, and offering advanced services.

Featured Whitepapers

Is Your Network Ready for the Internet of Everything?

The telephone industry is undergoing a dramatic transformation that began with the introduction of IP-based data networks in the early 1990s and then with Voice over Internet Protocol (VoIP) in the late 1990s, and it now includes all forms ofvoice, video, and messaging communications.

Building a Secure and Scalable Multimedia IP Exchange

As fixed and mobile operators increasingly move to IP-based networks, the complexity required to interconnect these networks grows dramatically. Faced with increasing competition from all corners and constant challenge to grow revenues, operators are struggling with the variety and disparities in partner and customer networks.

How Carriers Can Optimize for LTE Roaming

Connectivity between mobile network operators (MNO) in 4G LTE is much more complex than it was in legacy networks.This complexity is primarily due to the change in focus. LTE is not a voice-focused roaming environment, but rather a datacentric environment.

Featured Case Studies

CASE STUDY: Real Time Communications Made Easy Via The Mobile Web

HubRTC offers the world's first WebRTC communication as a service to small and medium businesses, combining browser-based voice, video and messaging over WiFi that works on personal computers and Android smartphones and tablets. Their basic and premium solutions work with existing PBX applications servers, and support rich feature sets including voice mail and visual voice mail, audio and video conferencing, all for a fraction of the cost of old fashioned "phone systems." They have combined their Real Time Communications experts with software, devices and accessories, and cloud platforms to deliver a true office-on-the-run.

CASE STUDY: TW Telecom Accelerates Market Adoption of SIP Trunking Services

tw telecom is one of the top three largest providers of Business Ethernet in the US, connecting approximately 20,000 commercial buildings and third-party data centers to its national fiber network.

CASE STUDY: Embedding Real-Time Communications Into Digital Interactive Publishing Platforms

X-Factor Communications (XFC) is a premium provider of easy-to-use, interactive digital media software and services delivering single point publishing of Mass Notifications, advisories, emergency messages, rich informational content and advertising to any connected device.

Featured Webinars

WebRTC Applications for Service Providers using GENBAND'S SPiDR Gateway


GENBAND's SPiDR WebRTC Gateway provides an intelligent bridge between SIP/IMS based VoIP networks and the open ecosystem of the Internet. WebRTC holds great promise to revolutionize the nature of our daily communications. But what should you, as a service provider, be doing today to take advantage of this movement?

Best Practices in Deploying Hosted IP Telephony


Speaker: Sara Hughes and Mitch Layman

LTE, How Can You Accelerate The Payback? Diameter Signaling Controller


Speaker: Ashish Jain - Director Solutions Marketing