Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

10/22/2019
09:00 AM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

Bugcrowd Enters the IT Asset Discovery Business

New service searches for errant or vulnerable devices on the Internet.

Bug bounty program provider Bugcrowd today added a new service in which selected white-hat hackers help root out an organization's exposed and vulnerable network devices on the Internet.

The new Attack Surface Management (ASM) service also analyzes the risks these devices pose and provides remediation recommendations for the findings.

Mapping and amassing a full inventory of devices on a network sounds like an obvious practice, but most organizations struggle to get a handle on what's living on their network — a problem exacerbated by the explosion of mobile and Internet of Things devices in the typical enterprise — and how attackers could abuse them if they're vulnerable or misconfigured.

Casey Ellis, founder, chairman, and CTO of Bugcrowd, says ASM differs from traditional asset discovery tools in that it focuses on the Internet view of the devices rather than on an internal network view. "We're at a point right now where pretty much everyone is part of the way in migration to the cloud, which means you can't really find" everything, he notes. "We're doing it for them."

Bugcrowd, which launched in 2012 as a crowdsourcing model for finding vulnerabilities in software, offers bug bounty, vulnerability disclosure programs, and penetration testing. The company relies on vetted independent security researchers to discover security weaknesses.

"This [new ASM offering] doubles down that we're not just focused on bug bounties and vulnerability disclosure. ... There are more things we can do with the crowd. This cements us bringing this crowdsourced security approach" more widely, he notes.

ASM's rollout comes on the heels of Metasploit creator and renowned security expert HD Moore's recent rollout of his new IT asset discovery tool, Rumble Network Discovery, which detects an organization's devices and their status on a network without requiring administrative access to reach them.

While Discovery maps out devices from the inside of an organization's network, Bugcrowd's ASM detects asset exposure on the public Internet. "The thing HD is solving first is the idea of an internal view of a corporate network, something [he's] beginning to address from the inside-out. We're taking it from the outside-in," Ellis says.

ASM will essentially provide a benchmark of network assets and can be set to detect devices on a continuous basis, he says. New devices are often placed on the Internet outside the purview of the security team, he notes, and that makes it difficult to keep tabs on them.

Moore, founder and CEO of Critical Research Corp., says Bugcrowd's new service should augment the bug bounty program as well. "Many bounty programs are limited by unrealistically small scopes because the folks running the program aren't aware of how much stuff they have exposed to the Internet," he says. "This should be a good thing for Bugcrowd, as it gives the crowd more things to look at, and great for their customers, as they get visibility into their overall exposure, and not just what they happen to know about."

Moore, who serves on Bugcrowd's advisory board, notes that there are several other vendors currently monitoring the external attack surface, including Censys.io, Asset Note, Expanse.co, RiskRecon, and BitDiscovery. "In the case of Asset Note, the team started the company as the result of doing bug bounty work and realizing how big the gap was between perceived and actual exposure for most organizations," he says. "Visibility is a big deal for security and it's great to see another company making Internet-wide asset discovery part of their platform."

Profiles and Context
Ellis notes that many organizations today merely consult DNS records for tracking any external weaknesses of their devices. But those lists only contain the systems they know about, he says.

Bugcrowd's new asset discovery service stops short of exploiting any vulnerable devices it discovers, he says. It's more about profiling the assets and providing context on how risky it is and what would happen if it were attacked.

ASM's findings can be used in Bugcrowd's bug bounty and penetration testing programs for more targeted testing, the company says.

Related Content:

This free, all-day online conference offers a look at the latest tools, strategies, and best practices for protecting your organization’s most sensitive data. Click for more information and, to register, here.

Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Why Cyber-Risk Is a C-Suite Issue
Marc Wilczek, Digital Strategist & CIO Advisor,  11/12/2019
Unreasonable Security Best Practices vs. Good Risk Management
Jack Freund, Director, Risk Science at RiskLens,  11/13/2019
6 Small-Business Password Managers
Curtis Franklin Jr., Senior Editor at Dark Reading,  11/8/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Navigating the Deluge of Security Data
In this Tech Digest, Dark Reading shares the experiences of some top security practitioners as they navigate volumes of security data. We examine some examples of how enterprises can cull this data to find the clues they need.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-18986
PUBLISHED: 2019-11-15
Pimcore before 6.2.2 allow attackers to brute-force (guess) valid usernames by using the 'forgot password' functionality as it returns distinct messages for invalid password and non-existing users.
CVE-2019-18981
PUBLISHED: 2019-11-15
Pimcore before 6.2.2 lacks an Access Denied outcome for a certain scenario of an incorrect recipient ID of a notification.
CVE-2019-18982
PUBLISHED: 2019-11-15
bundles/AdminBundle/Controller/Admin/EmailController.php in Pimcore before 6.3.0 allows script execution in the Email Log preview window because of the lack of a Content-Security-Policy header.
CVE-2019-18985
PUBLISHED: 2019-11-15
Pimcore before 6.2.2 lacks brute force protection for the 2FA token.
CVE-2019-18928
PUBLISHED: 2019-11-15
Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connection.