{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,8,12]],"date-time":"2025-08-12T21:35:48Z","timestamp":1755034548095,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":22,"publisher":"ACM","license":[{"start":{"date-parts":[[2017,9,26]],"date-time":"2017-09-26T00:00:00Z","timestamp":1506384000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2017,9,26]]},"DOI":"10.1145\/3129416.3129440","type":"proceedings-article","created":{"date-parts":[[2017,9,25]],"date-time":"2017-09-25T13:14:14Z","timestamp":1506345254000},"page":"1-10","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":13,"title":["Turning evil regexes harmless"],"prefix":"10.1145","author":[{"given":"Brink","family":"van der Merwe","sequence":"first","affiliation":[{"name":"Stellenbosch University, Stellenbosch, South Africa"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Nicolaas","family":"Weideman","sequence":"additional","affiliation":[{"name":"Stellenbosch University, Stellenbosch, South Africa"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Martin","family":"Berglund","sequence":"additional","affiliation":[{"name":"Stellenbosch University, Stellenbosch, South Africa"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2017,9,26]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-85780-8_8"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.4204\/EPTCS.151.7"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-22360-5_24"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/T-C.1971.223204"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1016\/0304-3975(93)90287-4"},{"key":"e_1_3_2_1_6_1","volume-title":"Retrieved","author":"Cox Russ","year":"2007","unstructured":"Russ Cox . 2007 . Regular Expression Matching Can Be Simple And Fast (but is slow in Java, Perl, PHP, Python, Ruby, ...). (October 2007) . Retrieved October 19, 2016 from https:\/\/swtch.com\/~rsc\/regexp\/regexp1.html Russ Cox. 2007. Regular Expression Matching Can Be Simple And Fast (but is slow in Java, Perl, PHP, Python, Ruby, ...). (October 2007). Retrieved October 19, 2016 from https:\/\/swtch.com\/~rsc\/regexp\/regexp1.html"},{"key":"e_1_3_2_1_7_1","volume-title":"Proceedings of the 12th USENIX Security Symposium, Washington, D.C., USA, August 4--8","author":"Crosby Scott","year":"2003","unstructured":"Scott Crosby and Dan Wallach . 2003 . Denial of Service via Algorithmic Complexity Attacks . In Proceedings of the 12th USENIX Security Symposium, Washington, D.C., USA, August 4--8 , 2003. USENIX Association. Scott Crosby and Dan Wallach. 2003. Denial of Service via Algorithmic Complexity Attacks. In Proceedings of the 12th USENIX Security Symposium, Washington, D.C., USA, August 4--8, 2003. USENIX Association."},{"key":"e_1_3_2_1_8_1","volume-title":"Retrieved","author":"Engelschall Ralf","year":"1997","unstructured":"Ralf Engelschall . 1997 . URL Rewriting Guide. (1997) . Retrieved June 14, 2017 from http:\/\/httpd.apache.org\/docs\/2.0\/misc\/rewriteguide.html Ralf Engelschall. 1997. URL Rewriting Guide. (1997). Retrieved June 14, 2017 from http:\/\/httpd.apache.org\/docs\/2.0\/misc\/rewriteguide.html"},{"volume-title":"Retrieved","year":"2010","key":"e_1_3_2_1_9_1","unstructured":"Google. 2010 . RE2. (2010) . Retrieved June 14, 2017 from https:\/\/github.com\/google\/re2 Google. 2010. RE2. (2010). Retrieved June 14, 2017 from https:\/\/github.com\/google\/re2"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-38631-2_11"},{"key":"e_1_3_2_1_11_1","volume-title":"Retrieved","author":"Kleppmann Martin","year":"2012","unstructured":"Martin Kleppmann . 2012 . Java's hashCode is not safe for distributed systems. (June 2012) . Retrieved June 19, 2017 from https:\/\/martin.kleppmann.com\/2012\/06\/18\/java-hashcode-unsafe-for-distributed-systems.html Martin Kleppmann. 2012. Java's hashCode is not safe for distributed systems. (June 2012). Retrieved June 19, 2017 from https:\/\/martin.kleppmann.com\/2012\/06\/18\/java-hashcode-unsafe-for-distributed-systems.html"},{"volume-title":"Retrieved","year":"2010","key":"e_1_3_2_1_12_1","unstructured":"Microsoft. 2010 . New Tool: SDL Regex Fuzzer. (2010) . Retrieved June 15, 2017 from https:\/\/blogs.microsoft.com\/microsoftsecure\/2010\/10\/12\/new-tool-sdl-regex-fuzzer\/ Microsoft. 2010. New Tool: SDL Regex Fuzzer. (2010). Retrieved June 15, 2017 from https:\/\/blogs.microsoft.com\/microsoftsecure\/2010\/10\/12\/new-tool-sdl-regex-fuzzer\/"},{"key":"e_1_3_2_1_13_1","volume-title":"Retrieved","author":"OWASP.","year":"2016","unstructured":"OWASP. 2016 . The Open Web Application Security Project. (October 2016) . Retrieved October 18, 2016 from https:\/\/www.owasp.org\/index.php\/Regular_expression_Denial_of_Service_-_ReDoS OWASP. 2016. The Open Web Application Security Project. (October 2016). Retrieved October 18, 2016 from https:\/\/www.owasp.org\/index.php\/Regular_expression_Denial_of_Service_-_ReDoS"},{"key":"e_1_3_2_1_14_1","volume-title":"Static Analysis for Regular Expression Exponential Runtime via Substructural Logics. CoRR abs\/1405.7058","author":"Rathnayake Asiri","year":"2014","unstructured":"Asiri Rathnayake and Hayo Thielecke . 2014. Static Analysis for Regular Expression Exponential Runtime via Substructural Logics. CoRR abs\/1405.7058 ( 2014 ). Asiri Rathnayake and Hayo Thielecke. 2014. Static Analysis for Regular Expression Exponential Runtime via Substructural Logics. CoRR abs\/1405.7058 (2014)."},{"key":"e_1_3_2_1_15_1","volume-title":"Retrieved","author":"Rathnayake Asiri","year":"2016","unstructured":"Asiri Rathnayake and Hayo Thielecke . 2016 . RXXR2 regular expression static analyzer. (2016) . Retrieved June 15, 2017 from http:\/\/www.cs.bham.ac.uk\/~hxt\/research\/rxxr2\/ Asiri Rathnayake and Hayo Thielecke. 2016. RXXR2 regular expression static analyzer. (2016). Retrieved June 15, 2017 from http:\/\/www.cs.bham.ac.uk\/~hxt\/research\/rxxr2\/"},{"key":"e_1_3_2_1_16_1","volume-title":"Retrieved","author":"Roichman Alex","year":"2012","unstructured":"Alex Roichman and Adar Weidman . 2012 . Regular Expression Denial of Service. (2012) . Retrieved October 19, 2016 from https:\/\/www.checkmarx.com\/white_papers\/redos-regular-expression-denial-of-service\/ Alex Roichman and Adar Weidman. 2012. Regular Expression Denial of Service. (2012). Retrieved October 19, 2016 from https:\/\/www.checkmarx.com\/white_papers\/redos-regular-expression-denial-of-service\/"},{"key":"e_1_3_2_1_17_1","series-title":"EATCS Monographs on Theoretical Computer Science","volume-title":"Languages and Parsing","author":"Sippu Seppo","year":"1988","unstructured":"Seppo Sippu and Eljas Soisalon-Soininen . 1988. Parsing Theory , Vol. I : Languages and Parsing , volume 15 of EATCS Monographs on Theoretical Computer Science . ( 1988 ). Seppo Sippu and Eljas Soisalon-Soininen. 1988. Parsing Theory, Vol. I: Languages and Parsing, volume 15 of EATCS Monographs on Theoretical Computer Science. (1988)."},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2006.17"},{"volume-title":"Retrieved","year":"2015","key":"e_1_3_2_1_19_1","unstructured":"Snort. 2015. Snort. ( 2015 ). Retrieved October 6, 2015 from http:\/\/www.snort.org Snort. 2015. Snort. (2015). Retrieved October 6, 2015 from http:\/\/www.snort.org"},{"key":"e_1_3_2_1_20_1","volume-title":"Retrieved","author":"Network Status Stack Exchange","year":"2017","unstructured":"Stack Exchange Network Status . 2017 . Outage Postmortem - July 20, 2016. (June 2017) . Retrieved June 14, 2017 from http:\/\/stackstatus.net\/post\/147710624694\/outage-postmortem-july-20--2016 Stack Exchange Network Status. 2017. Outage Postmortem - July 20, 2016. (June 2017). Retrieved June 14, 2017 from http:\/\/stackstatus.net\/post\/147710624694\/outage-postmortem-july-20--2016"},{"key":"e_1_3_2_1_21_1","volume-title":"Regular Expression Static Analysis Project Page. (April","author":"van der Merwe Brink","year":"2016","unstructured":"Brink van der Merwe and Nicolaas Weideman . 2016. Regular Expression Static Analysis Project Page. (April 2016 ). Retrieved April, 30, 2016 from http:\/\/www.cs.sun.ac.za\/~abvdm\/regex.html Brink van der Merwe and Nicolaas Weideman. 2016. Regular Expression Static Analysis Project Page. (April 2016). Retrieved April, 30, 2016 from http:\/\/www.cs.sun.ac.za\/~abvdm\/regex.html"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-40946-7_27"}],"event":{"name":"SAICSIT '17: South African Institute of Computer Scientists and Information Technologists","acronym":"SAICSIT '17","location":"Thaba 'Nchu South Africa"},"container-title":["Proceedings of the South African Institute of Computer Scientists and Information Technologists"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3129416.3129440","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3129416.3129440","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T03:30:15Z","timestamp":1750217415000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3129416.3129440"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,9,26]]},"references-count":22,"alternative-id":["10.1145\/3129416.3129440","10.1145\/3129416"],"URL":"https:\/\/doi.org\/10.1145\/3129416.3129440","relation":{},"subject":[],"published":{"date-parts":[[2017,9,26]]},"assertion":[{"value":"2017-09-26","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}