Ben Stock - Large Scale Web Vulnerability Notification

Опубликовано: 23 Март 2026
на канале: Owasp Göteborg
241
3

Title: Hey, You Have a Problem: On the Feasibility of Large-Scale Web Vulnerability Notification
Large-scale discovery of thousands of vulnerable Web sites has become a frequent event, thanks to recent advances in security research and the rise in maturity of Internet-wide scanning tools. The issues related to disclosing the vulnerability information to the affected parties, however, have only been treated as a side note in prior research.
In our work, we systematically examined the feasibility and efficacy of large-scale notification campaigns. For this, we comprehensively surveyed existing communication channels and evaluated their usability in an automated notification process. Using a data set of over 44,000 vulnerable Web sites, we measured success rates, both with respect to the total number of fixed vulnerabilities and to reaching responsible parties, with the following highlevel results: Although our campaign had a statistically significant impact compared to a control group, the increase in the fix rate of notified domains is marginal.
If a notification report is read by the owner of the vulnerable application, the likelihood of a subsequent resolution of the issues is sufficiently high: about 40%. But, out of 35,832 transmitted vulnerability reports, only 2,064 (5.8%) were actually received successfully, resulting in an unsatisfactory overall fix rate, leaving 74.5% of Web applications exploitable after our month-long experiment. Thus, we conclude that currently no reliable notification channels exist, which significantly inhibits the success and impact of large-scale notification.
In this talk, I will not only share the insights of our work, but would also like to hear from security professionals about their thoughts regarding the issues associated with a large-scale notification of vulnerable sites.

Speaker: Ben Stock
Ben Stock is a postdoctoral researcher at the Center for IT-Security, Privacy and Accountability (CISPA) in Saarbruecken. Apart from having a background in malware analysis, Ben focussed on Web security for his PhD thesis, covering different client-side security challenges. His research nowadays not only focusses on the detection and mitigation of Web vulnerabilities as well as the general area of network security, but more broadly also on how large-scale detection of vulnerabiltiies can be transformed into large-scale fixing of the discovered vulnerabilities. In his spare time, he also enjoys the challenges brought up in Capture the Flag competitions.