Feeds

Firm offers to patent security fixes

Cash from chaos

Build a business case: developing custom apps

The market for software vulnerabilities just got even more complex with the arrival of a firm that offers security researchers a chance to profit from their work by patenting security fixes.

Intellectual Weapons offers a revenue split with researchers who embark on what it admits is an ambitious strategy. It claims rival schemes offer only a fraction of the income its approach, which it defends as ethical, offers.

Any old flaw

Schemes such as iDefense's Vulnerability Contributor Program and 3Com's Zero-Day Initiative offer flaw finders a chance to get paid for their work. In return, security firms get the chance to add protection for upcoming flaws to their products, a useful "value-add" in the highly competitive security tools marketplace. Payments vary but tend to max out at around $10,000.

For flaw finders with the right contacts, sales to government agencies might fetch as much as $50,000 or more, depending on the vulnerability. Selling flaws direct to hackers through the underground black market in flaws offers an even greater potential (albeit illicit) reward.

Governments, much less black-hat hackers, are unlikely to disclose vulnerabilities to suppliers since the value of flaws to them is measured by their longevity and effectiveness as a tool to break into systems.

Weapons of flaw

IP property outfit Intellectual Weapons works with researchers to obtain and enforce patents relating to fixes for security vulnerabilities. The scheme works by attempting to license the fix to suppliers of vulnerable products, their competitors, and vulnerability protection firms.

Intellectual Weapons said it fully expects "major battles" in enforcing its IP, which is just as well since the firm's business plan puts it toe to toe with Microsoft's formidable team of lawyers. Security researchers need perseverance in order to stand a chance of scoring half the revenues from licensing offered by the firm.

Security researchers approaching Intellectual Weapons need to have big cajones, the firm advises. Intellectual Weapons said it developed an approach to streamlining the patent application and licensing process, but admits it is still far from straightforward.

"If this sounds too daunting, you are free to give your discoveries to your employer, help vendors secure their products for free, show off to your friends, grovel for security jobs, or sell your raw discoveries to middlemen for a fraction of their true value. We only want people who dare to play for high stakes," it said.

Intellectual Weapons is only interested in original vulnerabilities, discovered without resorting to illegality. Its preference is for security fixes that are difficult to "design around" and innovative, such that it's more likely to be granted a speedy patent. Technical elegance or other more general security imperatives don't really come into it.

The firm quotes examples of smaller firms who've come ahead of IT giants in patent fights to support its business model, which it claims is more akin to traditional "responsible disclosure" than the "patent trolls" its detractors might compare it to. The firm is yet to come up with examples of its own.

More about the firm can be found here. ®

Endpoint data privacy in the cloud is easier than you think

More from The Register

next story
Microsoft's Euro cloud darkens: US FEDS can dig into foreign servers
They're not emails, they're business records, says court
'Things' on the Internet-of-things have 25 vulnerabilities apiece
Leaking sprinklers, overheated thermostats and picked locks all online
iWallet: No BONKING PLEASE, we're Apple
BLE-ding iPhones, not NFC bonkers, will drive trend - marketeers
Multipath TCP speeds up the internet so much that security breaks
Black Hat research says proposed protocol will bork network probes, flummox firewalls
Only '3% of web servers in top corps' fully fixed after Heartbleed snafu
Just slapping a patched OpenSSL on a machine ain't going to cut it, we're told
Plug and PREY: Hackers reprogram USB drives to silently infect PCs
BadUSB instructs gadget chips to inject key-presses, redirect net traffic and more
How long is too long to wait for a security fix?
Synology finally patches OpenSSL bugs in Trevor's NAS
Israel's Iron Dome missile tech stolen by Chinese hackers
Corporate raiders Comment Crew fingered for attacks
prev story

Whitepapers

7 Elements of Radically Simple OS Migration
Avoid the typical headaches of OS migration during your next project by learning about 7 elements of radically simple OS migration.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Solving today's distributed Big Data backup challenges
Enable IT efficiency and allow a firm to access and reuse corporate information for competitive advantage, ultimately changing business outcomes.
A new approach to endpoint data protection
What is the best way to ensure comprehensive visibility, management, and control of information on both company-owned and employee-owned devices?