{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T12:20:22Z","timestamp":1782994822167,"version":"3.54.5"},"publisher-location":"New York, NY, USA","reference-count":24,"publisher":"ACM","license":[{"start":{"date-parts":[[2014,11,7]],"date-time":"2014-11-07T00:00:00Z","timestamp":1415318400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2014,11,7]]},"DOI":"10.1145\/2663887.2663906","type":"proceedings-article","created":{"date-parts":[[2014,11,11]],"date-time":"2014-11-11T13:40:05Z","timestamp":1415713205000},"page":"51-58","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":31,"title":["An Exploratory Study of White Hat Behaviors in a Web Vulnerability Disclosure Program"],"prefix":"10.1145","author":[{"given":"Mingyi","family":"Zhao","sequence":"first","affiliation":[{"name":"Pennsylvania State University, State College, PA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jens","family":"Grossklags","sequence":"additional","affiliation":[{"name":"Pennsylvania State University, State College, PA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Kai","family":"Chen","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2014,11,7]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Background information available at: http:\/\/en.wikipedia.org\/wiki\/Bugtraq","year":"2014","unstructured":"Bugtraq. Background information available at: http:\/\/en.wikipedia.org\/wiki\/Bugtraq , 2014 . {Online; accessed 03-September-2014}. Bugtraq. Background information available at: http:\/\/en.wikipedia.org\/wiki\/Bugtraq, 2014. {Online; accessed 03-September-2014}."},{"key":"e_1_3_2_1_2_1","volume-title":"Mar.","author":"China's","year":"2014","unstructured":"China's no.1 online travel firm ctrip hit by security scare. Available at: http:\/\/english.cntv.cn\/program\/bizasia\/20140324\/103772.shtml , Mar. 2014 . {Online; accessed 03-September-2014}. China's no.1 online travel firm ctrip hit by security scare. Available at: http:\/\/english.cntv.cn\/program\/bizasia\/20140324\/103772.shtml, Mar. 2014. {Online; accessed 03-September-2014}."},{"key":"e_1_3_2_1_3_1","volume-title":"Available at: http:\/\/en.wikipedia.org\/wiki\/Heartbleed#Affected_services","year":"2014","unstructured":"Heartbleed. Available at: http:\/\/en.wikipedia.org\/wiki\/Heartbleed#Affected_services , 2014 . {Online; accessed 03-September-2014}. Heartbleed. Available at: http:\/\/en.wikipedia.org\/wiki\/Heartbleed#Affected_services, 2014. {Online; accessed 03-September-2014}."},{"issue":"3","key":"e_1_3_2_1_4_1","first-page":"71","article-title":"Software vulnerability markets: Discoverers and buyers. International Journal of Computer","volume":"8","author":"Algarni A.","year":"2014","unstructured":"A. Algarni and Y. Malaiya . Software vulnerability markets: Discoverers and buyers. International Journal of Computer , Information Science and Engineering , 8 ( 3 ): 71 -- 81 , 2014 . A. Algarni and Y. Malaiya. Software vulnerability markets: Discoverers and buyers. International Journal of Computer, Information Science and Engineering, 8(3):71--81, 2014.","journal-title":"Information Science and Engineering"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1007\/11766155_21"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/1835804.1835821"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/1920261.1920299"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-36563-8_14"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/2535813.2535818"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.5555\/2534766.2534790"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4419-6967-5_6"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2011.70"},{"issue":"12","key":"e_1_3_2_1_13_1","first-page":"317","article-title":"The frequency distribution of scientific productivity","volume":"16","author":"Lotka A.","year":"1926","unstructured":"A. Lotka . The frequency distribution of scientific productivity . Journal of Washington Academy Sciences , 16 ( 12 ): 317 -- 323 , 1926 . A. Lotka. The frequency distribution of scientific productivity. Journal of Washington Academy Sciences, 16(12):317--323, 1926.","journal-title":"Journal of Washington Academy Sciences"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1080\/00107510500052444"},{"key":"e_1_3_2_1_15_1","unstructured":"Open Sourced Vulnerability Database (OSVDB). Available at: http:\/\/osvdb.org\/.  Open Sourced Vulnerability Database (OSVDB). Available at: http:\/\/osvdb.org\/."},{"key":"e_1_3_2_1_16_1","volume-title":"2013 Top 10 list. Available at: https:\/\/www.owasp.org\/index.php\/Top_10_2013-Top_10","author":"Application Security Open Web","year":"2013","unstructured":"Open Web Application Security Project (OWASP). 2013 Top 10 list. Available at: https:\/\/www.owasp.org\/index.php\/Top_10_2013-Top_10 , 2013 . {Online; accessed 03-September-2014}. Open Web Application Security Project (OWASP). 2013 Top 10 list. Available at: https:\/\/www.owasp.org\/index.php\/Top_10_2013-Top_10, 2013. {Online; accessed 03-September-2014}."},{"key":"e_1_3_2_1_17_1","volume-title":"Proceedings of the Third Workshop on the Economics of Information Security (WEIS)","author":"Ozment A.","year":"2004","unstructured":"A. Ozment . Bug auctions : Vulnerability markets reconsidered . In Proceedings of the Third Workshop on the Economics of Information Security (WEIS) , Minneapolis, MN , May 2004 . A. Ozment. Bug auctions: Vulnerability markets reconsidered. In Proceedings of the Third Workshop on the Economics of Information Security (WEIS), Minneapolis, MN, May 2004."},{"key":"e_1_3_2_1_18_1","volume-title":"Proceedings of the Fourth Workshop on the Economics of Information Security (WEIS)","author":"Ozment A.","year":"2005","unstructured":"A. Ozment . The likelihood of vulnerability rediscovery and the social utility of vulnerability hunting . In Proceedings of the Fourth Workshop on the Economics of Information Security (WEIS) , Cambridge, MA , June 2005 . A. Ozment. The likelihood of vulnerability rediscovery and the social utility of vulnerability hunting. In Proceedings of the Fourth Workshop on the Economics of Information Security (WEIS), Cambridge, MA, June 2005."},{"key":"e_1_3_2_1_19_1","volume-title":"Proceedings of the 15th USENIX Security Symposium","author":"Ozment A.","year":"2006","unstructured":"A. Ozment and S. Schechter . Milk or wine: Does software security improve with age? In Proceedings of the 15th USENIX Security Symposium , Vancouver, Canada, July- August 2006 . A. Ozment and S. Schechter. Milk or wine: Does software security improve with age? In Proceedings of the 15th USENIX Security Symposium, Vancouver, Canada, July-August 2006."},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/SECURWARE.2010.33"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2005.17"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1016\/0377-0427(87)90125-7"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.5555\/2337223.2337314"},{"key":"e_1_3_2_1_24_1","volume-title":"2011 User Information Leakage Incident in Chinese Websites. Available at: goo.gl\/0UwgkW. {Online","year":"2014","unstructured":"Wikipedia. 2011 User Information Leakage Incident in Chinese Websites. Available at: goo.gl\/0UwgkW. {Online ; accessed 03- September - 2014 }. Wikipedia. 2011 User Information Leakage Incident in Chinese Websites. Available at: goo.gl\/0UwgkW. {Online; accessed 03-September-2014}."}],"event":{"name":"CCS'14: 2014 ACM SIGSAC Conference on Computer and Communications Security","location":"Scottsdale Arizona USA","acronym":"CCS'14","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2014 ACM Workshop on Security Information Workers"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2663887.2663906","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2663887.2663906","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T06:13:34Z","timestamp":1750227214000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2663887.2663906"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2014,11,7]]},"references-count":24,"alternative-id":["10.1145\/2663887.2663906","10.1145\/2663887"],"URL":"https:\/\/doi.org\/10.1145\/2663887.2663906","relation":{},"subject":[],"published":{"date-parts":[[2014,11,7]]},"assertion":[{"value":"2014-11-07","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}