Home > Security News > VeriSign raises stakes in battle for threat intelligence
Security News:
EMAIL THIS

VeriSign raises stakes in battle for threat intelligence

By Bill Brenner, News Writer
27 Jul 2005 | SearchSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

VeriSign Inc. vowed to expand iDefense's Vulnerability Contributor Program (VCP) when it purchased the Reston, Va.-based security firm earlier this month. Then an Austin-based competitor launched its own program to pay researchers for vulnerability intelligence.

Tuesday, one day after 3Com and its TippingPoint division unveiled its Zero-Day Initiative (ZDI), Mountain View, Calif.-based VeriSign upped the ante, announcing big increases in what it will pay researchers for details on new security holes.

"Effective immediately, we will be doubling our standard pricing structure for vulnerability submissions," Michael Sutton, director of the iDefense Labs, said in a e-mail message to SearchSecurity.com. "As well, we are increasing the value of the incentive and retention reward programs and launching a new growth reward program."
Related Links

Will iDefense keep looking underground for flaws?

Is paying for vulnerability information the right approach?

Sutton noted in a follow-up phone interview Wednesday that both companies timed their announcements with the start of this week's Black Hat Briefings in Las Vegas and that "certainly [3Com] is competing with us."

Since a researcher's pay depends on what he or she delivers to either program, Sutton said it's hard to say which company is offering the sweeter financial incentives. But, he added, "For us the big picture is about trust and experience. I'm surprised it took three years for someone to start a competing program. The fact that we have three years of experience speaks for itself. I welcome the competition. It legitimizes what we do."

Sutton believes other security firms have been reluctant to follow suit for fear that their programs wouldn't work. "I think people were nervous," he said. "But we've proven it can be done well." He added that VeriSign's program has the edge because underground researchers already know they can trust it. "When a new person comes in there's hesitation," he said. "They want to know the company will follow through. We have a track record."

That said, Sutton left no doubt that VeriSign is taking 3Com's program seriously. "We know it's competition and we have to stay on top of things," he said. "No doubt about it -- we'll be competing on the financial front as well."

3Com spokeswoman Laura Craddick predicted the Zero-Day Initiative will stand the test of time because, unlike the VCP approach, her company will freely share its intelligence with the information security community.

"We are not reselling the information," she said. "We're giving it to the security community -- including other security companies -- for the greater good. People pay iDefense for the information they have. That's their business model. Our business model is that we protect people."

Joseph Payne, formerly iDefense's president and COO and now VeriSign's VP of intelligence, shrugged off Craddick's comments.

"One of our strengths is that we do make money by distributing intelligence," he said. "Because people are willing to pay for our intelligence, we can invest in the people and programs to expand our efforts. Arguing that free is better doesn't make sense to me. You have to have money to invest in the programs. And customers hold us to a high standard because they're paying for our services."

Details of VCP expansion
The VCP incentive program rewards the top three contributors for each quarter. Under the old pricing structure, the top three earned $3,000, $2,000 and $1,000, respectively. Now the top two will earn $5,000 and $3,000, respectively. The pay for the third-biggest quarterly contribution will remain at $1,000.

The retention program rewards the top five contributors each year. Under the old pricing structure, the top five contributors earned $5,000, $4,000, $3,000, $2,000 and $1,000, respectively. Now they'll earn $10,000, $8,000, $6,000, $4,000 and $2,000, respectively.

The new growth program will reward contributors that continue to increase their level of VCP participation, Sutton said. Under the program:

  • Any contributor with at least five submissions in the current year will be eligible to participate.
  • A contributor's submissions over the past 12 months will be compared to submissions in the 12 months before that.
  • Those who make the grade will be paid annually.
  • An individual must have been a VCP contributor for at least two years prior to the reward date in order to participate.
  • The program will cover a July 1 to June 30 period, with the first payment covering July 1, 2005 to June 30, 2006.
  • Contributors with submissions in the current year that equal or exceed submissions from the past year will receive a lump sum payment equal to 50% of all current year submissions.
  • Contributors with submissions in the current year that equal or exceed twice the submissions from the past year will receive a lump sum payment equal to 100% of all current year submissions.
  • Contributors with current year submissions that are equal or double past year submissions will receive a lump sum payment appropriately pro-rated between 50-100% of all current year submissions.

Details of the Zero-Day Initiative
Under 3Com's Zero-Day Initiative, the amount of the reward will depend on the severity of the security hole discovered, the firm said, adding that it will inform the maker of a flawed product when glitches are found while also updating its own security products.

Members of the ZDI program earn points each time 3Com purchases their vulnerability submission. The structure is similar to airline frequent flyer miles in that members accrue points each year on a dollar-for-dollar basis based on the aggregate dollar amount paid for vulnerability submissions during that calendar year.

"For instance, if the Zero Day Initiative buys your vulnerability for $5,000, then you receive 5,000 points for that submission," the company said on its Web site. "For all of calendar year 2005, if you received 31,000 points, then for calendar year 2006 you will be considered to have ZDI Gold status."

The levels of ZDI reward membership are:

  • Bronze, worth 10,000 reward points;
  • Silver, worth 20,000 points;
  • Gold, worth 35,000 points; and
  • Platinum, worth 50,000 points.

Bronze status includes a 10% automatic bonus on all vulnerability submissions over the next calendar year and a one-time bonus of $1,000. Silver status includes a 15% automatic bonus and a 125% ZDI reward points multiplier on all vulnerability submissions over the next calendar year, as well as a one-time bonus of $5,000 and paid travel and registration to attend DEFCON in Las Vegas.

Gold status includes a 20% automatic bonus on all vulnerability submissions over the next calendar year, a 150% ZDI reward points multiplier on all vulnerability submissions over the next calendar year; a one-time bonus of $10,000; and the same DEFCON travel package. Platinum status raises the automatic bonus to 25%, reward points multiplier to 200%, one-time bonus to $20,000 and both Black Hat and DEFCON travel awards.

Tags: Vulnerability Risk AssessmentSecurity Industry Market Trends, Predictions and ForecastsVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Vulnerability Risk Assessment
Screencast: How to launch an OpenVAS scan
Trusteer CEO criticizes Adobe, touts better patch deployments
Patch management study shows IT taking significant risks
Vulnerability mitigation study shows need for faster patching
Microsoft to issue security report card, new tool at Black Hat
Newest malware threats
Are Web application penetration tests still important?
PCI compliance requirement 6: Systems and applications
Cybercrime and threat management
McAfee to acquire Solidcore Systems for whitelisting
Vulnerability Risk Assessment Research

Security Industry Market Trends, Predictions and Forecasts
M86 buys Web security gateway vendor Finjan
Information Security Decisions 2009: Presentation downloads
Bruce Schneier on outsourcing, awareness training
Marcus Ranum on cyberwarfare, infosec careers
McAfee survey finds faults in midmarket enterprise security
Email archiving vendor sues Gartner over Magic Quadrant
Information Security magazine October issue PDF
Editor's Desk: Security 7 Winners Chronicle Trends That Shape The Industry
Information Security magazine Security 7 Award winners
Security Squad: Privacy gone awry
Security Industry Market Trends, Predictions and Forecasts Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
gray hat  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts