Security exchange trades zero-day flaws

  • Email a Friend
  • Print Page
Security exchange trades zero-day flaws
By Robert Jaques
Jul 6, 2007 11:46 AM
Tags: Security | exchange | trades | zero-day | flaws

Swiss laboratory launches marketplace for security research.

A vendor-independent Swiss laboratory is aiming to allow hackers and security specialists to sell vulnerability data to security vendors and software companies.

WSLabi claims that its offering is the first zero-day vulnerability security research exchange. 

Herman Zampariolo, chief executive at WSLabi, said: "We set up this portal for selling security research because, although there are many researchers out there who discover vulnerabilities, very few are able or willing to report it to the 'right' people due to the fear of it being exploited."

Zampariolo added that, although researchers had analysed around 7,000 publicly disclosed vulnerabilities last year, the number of new vulnerabilities found in code could be as high as 139,362 a year.

"Our intention is that the marketplace facility on WSLabi will enable security researchers to get a fair price for their findings and ensure that they will no longer be forced to give them away for free or sell them to cyber-criminals," he said.

Researchers can submit their findings to the exchange once they have registered. WSLabi will then verify the research by analysing and replicating it at their independent testing laboratories.

WSLabi will then package the findings with a proof of concept, which can then be sold to the marketplace.

Roberto Preatoni, strategic director at WSLabi, said: "Before we have even launched the marketplace there are already three new vulnerabilities available from security researchers.

"The vulnerability research is associated with Linux, Yahoo Messenger and SquirrelMail.

"This shows that this venture is filling a gap within the security research market, a place where security researchers are confident that they will get the right value for their findings."

Researchers and buyers will have to identify themselves to WSLabi to ensure that they are legitimate.

Researchers cannot submit security research material which comes from an illegal source or activity.

Buyers will be carefully vetted before being granted access to the auction platform so that the risk of selling the 'right stuff' to the 'wrong people' is minimised.

The marketplace will be free to use for the first six months for researchers and buyers.

Even though all parties will have to identify themselves to WSLabi, no personal information will be disclosed or held in the public domain. Each buyer and seller will have a nickname under which they will trade.

The exchange also aims to compile a global database of "every piece of IT security research ever found".

Copyright © 2009 vnunet.com


 
Comments

Be the first to comment on this article.
Thoughts on this article? Add a comment below.
Comment:
Want to participate in the discussion?
Or log in now to comment
 
 
Top Stories
Basslink lights up with commercial traffic
Calls for second independent cable.
 
Bluetooth "Big Brother" tracks festival-goers
Might have retail and security applications.
 
Huawei considers Australian 4G lab
But dollars depend on demand.
 
Exclusive Data Centre - Sponsored Content by Microsoft

Latest Comments

""The researchers will only track the devices' MAC address -- a number that identifies each ..."
by forcedregsucks Jul 6, 2009 9:34 PM
 
" Erin Kutz wrote: A tiny fraction of those who use the fast-growing social network phenomenon ..."
by Slatts Jul 6, 2009 8:58 AM
 
"I'm thinking there was some robust discussion in the Sawers household when Sir John got home ..."
by Slatts Jul 6, 2009 8:41 AM
 
"Well... that seems disturbing but I just can't seem to put my finger on why. I think it just ..."
by Slatts Jul 6, 2009 8:35 AM
 
"I'm kind of assuming that the water was used in water cooled condensers for the air-conditioning...."
by Slatts Jul 2, 2009 8:54 PM

Polls

What will you do when your iPhone contract comes up for renewal?




   |   View results
Retain my current service provider
  11%
 
Switch to a cheaper plan
  18%
 
Switch to a better network
  17%
 
Switch to whoever offers free tethering
  18%
 
Change handset altogether
  35%
TOTAL VOTES: 208

Vote