Abstract

Bug bounty programs encourage security researchers to responsibly disclose software vulnerabilities by offering financial rewards, recognition, and opportunities to build long-term relationships with organizations. However, vulnerability discovery also creates competing incentives. A researcher may report a vulnerability through an official program, exploit it for passive income, trade information with other actors, delay disclosure, or seek compensation through alternative markets. These decisions are shaped by the expected value of rewards, perceived fairness of company responses, reputation benefits, competition, and the risk of penalties. Because directly observing these choices in real-world bug bounty programs presents ethical, legal, and practical challenges, controlled environments are needed to study how incentive structures influence disclosure behavior. This thesis presents HexaHive, a Discord-based serious game that simulates a vulnerability-bounty economy in a controlled multiplayer environment. HexaHive allows participants to search for vulnerabilities, gather information about their severity and impact, report findings to simulated companies, exploit vulnerabilities for recurring income, trade information, negotiate rewards, and build reputation. The system uses game-theoretic concepts through a reporting-versus-exploitation decision model, Ultimatum-style and Dictator-style reward mechanisms, reputation-based delayed benefits, and deterrence-based penalties for exploitative behavior. By recording player actions and outcomes, HexaHive provides a framework for studying strategic vulnerability-disclosure decisions without exposing real organizations or users to harm.

Publication Date

2026

Document Type

Thesis

Student Type

Graduate

Degree Name

Software Engineering (MS)

Department, Program, or Center

Software Engineering, Department of

College

College of Science

Advisor

Andy Meneely

Advisor/Committee Member

Christina Newman

Campus

RIT – Main Campus

Share

COinS