Demo Series 13 minJun 5, 2024

Benefits of Bug Bounty and How to Go Next Level

When evaluating potential bug bounty programs to get more eyes on target, there are some mission-critical features you can't miss. This Cut to the Chase demo describes how Synack can fulfill some bug bounty use cases while providing additional analytics, security and control of an…

Justine Salisbury Sr. Product Marketing Manager, Synack
Wade Lance Global Field CISO, Synack

Overview

Full transcript

Read transcript

Hello, and welcome to the next installment of Cut to the Chase. Here at SYNACK, we produce these videos a way for people to quickly learn about various topics in the security and security testing space. I'm joined today by one of our senior product marketing managers, Justine Salisbury. Justine, say hi. Hello. That's I expected you to say hi, Justine. Right? You know? Say hi, Justine. Anyway, today's topic, which we're very excited, I'm gonna give you a brief overview of some of the

concepts related to bug bounty and how bug bounty programs work. And then Justine is gonna show us some concepts in the system about how we do it from the Synapse side. So if you're curious about bug bounty, you've landed in the right place today. Bug bounty programs are very powerful way and people get excited about them for good reason. A couple of those reasons would be this. People are very interested in getting threat researchers and white hat hackers, if you will,

security researchers to look at their environments in production. Most bug bounty programs focus on production environments. There are some that look at staging environments, but this idea of having a diverse global community of researchers look at your environment in a way that the attacking community would is an extremely powerful capability. So people go down the path of bug bounty because they're interested in this diversity of perspectives.

They're interested in incentivized researching, right? There's an incentive in bug bounty programs built into compensate people for their work, to help organizations find vulnerabilities. So that's a powerful tool. I would say that people also engage Bug Bounty because they're also interested in Typically you'll hear people talk about this idea of continuous testing, human driven continuous testing, making these sites available. And so those are some of the drivers why we like bug bounty,

why bug bounty makes a lot of sense. There are however, frictions to a bug bounty process, which may not always jump out at people until you actually get involved. And some of the friction elements look like this. When you open a bug bounty program, you're going to get a, in some cases, pretty strong stream of suggested vulnerabilities, potential vulnerabilities that your organization typically will need to triage. Now, some bug bounty providers also provide the triage.

So you wanna look at that if you're considering it, but that flood can be a lot if you're new to the bug bounty space. Another element in it is people will get excited about bug bounty providing continuous coverage. But what you find when you actually analyze a lot of bug bounty solutions is that the testing isn't actually continuous. It's continuously available for tests, but that's not the same as it continuously being tested. The other thing is you don't actually have,

in a lot of cases, consistent coverage. No one's really incentivized to make sure they're going application by application, infrastructure by infrastructure and doing a comprehensive look at the environment. Another thing people find in bug bounty is that the payment side of the house can fluctuate wildly. So you may send aside a certain amount of money for your bug bounty incentive program. If that gets used up in very short order, now you're having to go back to leadership and ask for additional budget or suspend the program.

That fluctuation can be troubling. And I guess the last thing that hits people is that, you know, bug bounty programs can be quite a bit of a hassle for your security operations and monitoring team in that now you've got external assets coming in and testing your infrastructure. Supposedly they're, you know, they're not nefarious nor malicious, but either way you put your SOC team in a

position where they have to differentiate this traffic. And it does provide an out for someone who gets caught, their hands in the cookie jar and say, Oh, I'm just part of your bug bounty program. It's like really, where are you? You know, so may find yourself in those spaces. So at SYNNAC, when we do testing for our customers, we'd like to think of it, one way to think of it is a private bug bounty program where we've done all the work to vet all the researchers, they're all background check,

skills checked to validate that they are in fact qualified to look at the environments that they're looking at. We also flatten out your cost process, right? So you pay a fixed fee for the testing, but the researchers are all incentivized. So we handle those fluctuations, but our customers get a very consistent, very predictable cost structure, but they get the value of a diversity. We have fifteen hundred researchers in ninety different countries. So you get that diversity of perspective and that incentivized research, but

you're paying a very predictable, very normalized cost. And then I guess one of the last things is that we always handle all of the triage, all of the flow of vulnerabilities, suspected vulnerabilities from the automated research, the automated scanning that we do, and then also the human driven processes. We triage all that and normalize it before it goes to you. So it's an easily consumable package. So that's why we like to think of SYNNAC as really kind of a private managed bug bounty, if you will,

all the benefits of bug bounty without all the pain. But here to talk about more is Justine, who's gonna show us some of these concepts in the SYNNAC platform. Thanks so much, Wade. So I'm just gonna talk through what some of these features look like in the Sync platform and how they differentiate from how bug bounties typically run. So just to start things off, what we're gonna do is we're going to show you how we

triage vulnerabilities and what's involved with that process. So, when we receive different vulnerabilities from assessments we're running, you'll see them come in in real time. So they'll come in through this vulnerabilities tab, and what happens before they even get to this tab is that our VULN Ops team actually goes in and triages every single vulnerability that comes through to make sure it's not one you already have that you've reported, and to make sure that the vulnerability report makes sense, they've been able to reproduce that vulnerability,

and that the information there is correct. So just to run you through what an example vulnerability report looks like, this would be an example right here. So you can see here's the impact of the vulnerability written about. And then also we have vulnerability locations, so you know where exactly to find that particular vulnerability. Here are the steps to reproduce the vulnerability. And a recommended fix,

so you know how to address that vulnerability and the CVSS score. So that way you can figure out how to prioritize it with the other vulnerabilities that are coming through. And then patch verification. So once your team has had a chance to address that vulnerability, you can request a patch verification automatically right from the portal. Which by the way, happens to be one of the most popular capabilities in the SYNNAC platform, right? Because we say this all the time, you know, security testing is not about finding vulnerabilities.

It's about demonstrating that you don't have them, right? So organizations and teams, they patch, they put in mitigating controls, and it's really important that that be tested to validate. Sometimes organizations are very surprised at the level of accuracy in that and we can help them validate those findings. That's right. And then here we have our suspected vulnerabilities. So these are vulnerabilities that are coming in through the scanner that are triaged by our Cenac Red Team to see if

they're exploitable or not. And then if they are exploitable, appear in the exploitable vulnerabilities tab. You can see where they all are in their triage process here, and you can look at any of these vulnerabilities that are submitted through our scanner as well. And then on the coverage side, so WeiDed made the point that you don't really know, how much researchers are testing your attack surface, if it's continuous or not, what applications they're testing as part of that bug bounty program.

A lot of the scope of bug bounty programs is very wide, so it's hard to know how much testing activity each of those, assets are getting. So here in Synapse portal, you can see we have a coverage tab both for our web and API tests and our host tests. And if you go into a particular domain or path, you can see here how many hits that particular domain had. You can see classified attack traffic, so what types of attacks researchers are trying and if

they found any bones on that particular asset. So this is a very helpful way to just see how much, each of your assets is being tested at that time. And you have, reporting to prove that it's happened, and this is all happening because all of the researchers' traffic is audit is audited through Synact. So we use a VPN to capture I use full packet capture to capture all that attack traffic and have it here for you to view easily in the Synact platform.

You can also see how many researchers are working across all the assets that you have under assessments. So here you have SRT insights, and this shows how many researchers have signed up. So similar to what Wade was saying about researchers working in Bug Bounty, we have a community of about fifteen hundred researchers that work across our various assessments through their researcher portal. So you can see here if they've logged in and spent some time

on your particular assessment. And then you can see how many hours total they've spent testing your assets as well. So these are very helpful. Go ahead, Edwin. So if I'm understanding that correctly, that would suggest that in this environment, and it's a demonstration environment, but the message there is that in this environment, a hundred and ninety two researchers have signed up to do testing in this environment and they've generated fifteen hundred and seventy seven hours of testing in this environment. Is that That's correct.

Yeah. Great. Great visibility. Yeah. Great visibility. So you get the advantages of Bug Bounty of having a lot of different diverse talent who, you know, various TTPs testing your environment, but you don't have that unvetted nature. So you know, that the researchers who are testing have been vetted, both for trust and skill, so you know that you can trust them. And then on the assessment side, you can start and stop an assessment at any time,

which also makes it different from traditional bug bounty where maybe you're starting to get too many bones, you can't take you know, you can't remediate that number fast enough, but but you have no way to stop the engagement. You can stop it at any time via the Synack platform. And then you also have, IPs that you can white list to make sure that you know you're not accidentally blocking researchers who are trying to test your environment. And you also know based on source IP address who is a researcher with Synack and who could be an adversary.

So that does set us apart from traditional bug bounty. Yeah. I know that that that capability is very popular with the SOC teams. They know that the only source IPs in this case are listed here. So any traffic coming from these IPs, those are SYNACK red team researchers than anybody, anybody else hitting their environment, those are threats they need to be concerned about. And that about wraps it up for the SYNACT differentiators from Bug Bounty. If you have any questions, feel free to reach out or Wade or I,

and we're happy to explain more about the differentiators. Thanks, Justine. Thanks, Wade. Take care. Bye.

Speakers

Justine Salisbury

Synack

Sr. Product Marketing Manager

Wade Lance

Synack

Global Field CISO

Next step

Run the test instead of evaluating the idea.

Define a scope, run a Sara AI pentest against it, and see which findings are confirmed as real and exploitable. Then compare that with what your current testing returns.