Security exchange trades zero-day flaws

Swiss laboratory launches marketplace for security research

Robert Jaques

A vendor-independent Swiss laboratory is aiming to allow hackers and security specialists to sell vulnerability data to security vendors and software companies.

WSLabi claims that its offering is the first zero-day vulnerability security research exchange. 

Advertisement

Herman Zampariolo, chief executive at WSLabi, said: "We set up this portal for selling security research because, although there are many researchers out there who discover vulnerabilities, very few are able or willing to report it to the 'right' people due to the fear of it being exploited."

Zampariolo added that, although researchers had analysed around 7,000 publicly disclosed vulnerabilities last year, the number of new vulnerabilities found in code could be as high as 139,362 a year.

"Our intention is that the marketplace facility on WSLabi will enable security researchers to get a fair price for their findings and ensure that they will no longer be forced to give them away for free or sell them to cyber-criminals," he said.

Researchers can submit their findings to the exchange once they have registered. WSLabi will then verify the research by analysing and replicating it at their independent testing laboratories.

WSLabi will then package the findings with a proof of concept, which can then be sold to the marketplace.

Roberto Preatoni, strategic director at WSLabi, said: "Before we have even launched the marketplace there are already three new vulnerabilities available from security researchers.

"The vulnerability research is associated with Linux, Yahoo Messenger and SquirrelMail.

"This shows that this venture is filling a gap within the security research market, a place where security researchers are confident that they will get the right value for their findings."

Researchers and buyers will have to identify themselves to WSLabi to ensure that they are legitimate.

Researchers cannot submit security research material which comes from an illegal source or activity.

Buyers will be carefully vetted before being granted access to the auction platform so that the risk of selling the 'right stuff' to the 'wrong people' is minimised.

The marketplace will be free to use for the first six months for researchers and buyers.

Even though all parties will have to identify themselves to WSLabi, no personal information will be disclosed or held in the public domain. Each buyer and seller will have a nickname under which they will trade.

The exchange also aims to compile a global database of "every piece of IT security research ever found".

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

Related whitepapers

Related jobs

Most watched

iPhone

Video Review: iPhone 3GS

We put Apple's latest iPhone through its paces

V3.co.uk weekly debrief, 5 Feb 2010

This week we cover the continuing controversy surrounding the Orange T-Mobile deal

Analysis and Reports

Using managed services to protect mobile data users from the latest security threats

Counting the cost of data security: the benefits of secured mobile services

Shifting Disaster Recovery targets with SharePoint and SQL server configurations

Using a hostbased recovery system for mission-critical systems

Poll

Adobe Flash poll

Adobe Flash poll

Do you agree with Steve Jobs about Flash being buggy?

View poll results

Advertisement

White paper library

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you over 6,000 white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Spotlight

Windows 7

Microsoft denies Windows 7 battery problems

Replacement warning functioning normally, claims software giant

Safer Internet Day

Safer Internet Day highlights online threats

Annual initiative warns of phishing, ID theft and social network...

AMD Fusion

AMD details Fusion innovations at ISSCC

Forthcoming chip with four CPU and one GPU cores will...

MSI Wind U135

Review: MSI Wind U135 netbook

A decent netbook incorporating the latest Intel technology in a...

Primary Navigation