{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T12:20:23Z","timestamp":1782994823027,"version":"3.54.5"},"publisher-location":"New York, NY, USA","reference-count":35,"publisher":"ACM","license":[{"start":{"date-parts":[[2021,10,11]],"date-time":"2021-10-11T00:00:00Z","timestamp":1633910400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2021,10,11]]},"DOI":"10.1145\/3475716.3484193","type":"proceedings-article","created":{"date-parts":[[2021,10,6]],"date-time":"2021-10-06T11:43:50Z","timestamp":1633520630000},"page":"1-6","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":6,"title":["Why Some Bug-bounty Vulnerability Reports are Invalid?"],"prefix":"10.1145","author":[{"given":"Saman","family":"Shafigh","sequence":"first","affiliation":[{"name":"University of New South Wales, Sydney, NSW, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Boualem","family":"Benatallah","sequence":"additional","affiliation":[{"name":"University of New South Wales, Sydney, NSW, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Carlos","family":"Rodr\u00edguez","sequence":"additional","affiliation":[{"name":"Universidad Cat\u00f3lica Nuestra Se\u00f1ora de la Asunci\u00f3n, Asunci\u00f3n, Paraguay - Visting Fellow, University of New South Wales, Sydney, NSW, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mortada","family":"Al-Banna","sequence":"additional","affiliation":[{"name":"University of New South Wales, Sydney, NSW, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2021,10,11]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"2008. Common types of non-qualifying reports. https:\/\/sites.google.com\/site\/bughunteruniversity\/nonvuln. Google bughunter university.  2008. Common types of non-qualifying reports. https:\/\/sites.google.com\/site\/bughunteruniversity\/nonvuln. Google bughunter university."},{"key":"e_1_3_2_1_2_1","unstructured":"2013. Facebook page was hacked by an unemployed Web developer. https:\/\/www.washingtonpost.com\/news\/the-switch\/wp\/2013\/08\/19\/mark-zuckerbergs-facebook-page-was-hacked-by-an-unemployed-web-developer.Washingtonpost.  2013. Facebook page was hacked by an unemployed Web developer. https:\/\/www.washingtonpost.com\/news\/the-switch\/wp\/2013\/08\/19\/mark-zuckerbergs-facebook-page-was-hacked-by-an-unemployed-web-developer.Washingtonpost."},{"key":"e_1_3_2_1_3_1","unstructured":"2015. Introducing reputation. https:\/\/www.hackerone.com\/blog\/introducing-reputation. HackerOne blog.  2015. Introducing reputation. https:\/\/www.hackerone.com\/blog\/introducing-reputation. HackerOne blog."},{"key":"e_1_3_2_1_4_1","unstructured":"2015. Introducing signal. https:\/\/www.hackerone.com\/blog\/introducing-signal-and-impact. HackerOne blog.  2015. Introducing signal. https:\/\/www.hackerone.com\/blog\/introducing-signal-and-impact. HackerOne blog."},{"key":"e_1_3_2_1_5_1","unstructured":"2016. Improving public bug bounty programs with signal requirements. https:\/\/hackerone.com\/blog\/signal-requirements. HackerOne blog.  2016. Improving public bug bounty programs with signal requirements. https:\/\/hackerone.com\/blog\/signal-requirements. HackerOne blog."},{"key":"e_1_3_2_1_6_1","unstructured":"2018. Safe Harbor for Security Bug Bounty Participants. https:\/\/blog.mozilla.org\/security\/2018\/08\/01\/safe-harbor-for-security-bug-bounty-participants\/. Mozilla blog.  2018. Safe Harbor for Security Bug Bounty Participants. https:\/\/blog.mozilla.org\/security\/2018\/08\/01\/safe-harbor-for-security-bug-bounty-participants\/. Mozilla blog."},{"key":"e_1_3_2_1_7_1","unstructured":"2021. Bug Bounty Programs\". https:\/\/hackerone.com\/bug-bounty-programs \"HackerOne\".  2021. Bug Bounty Programs\". https:\/\/hackerone.com\/bug-bounty-programs \"HackerOne\"."},{"key":"e_1_3_2_1_8_1","unstructured":"2021. Bugcrowd bug bounty platform. https:\/\/bugcrowd.com\/.  2021. Bugcrowd bug bounty platform. https:\/\/bugcrowd.com\/."},{"key":"e_1_3_2_1_9_1","unstructured":"2021. Concrete5 Bug Bounty Program Policy. https:\/\/hackerone.com\/concrete5.  2021. Concrete5 Bug Bounty Program Policy. https:\/\/hackerone.com\/concrete5."},{"key":"e_1_3_2_1_10_1","unstructured":"2021. Hackerone bug bounty platform. https:\/\/hackerone.com.  2021. Hackerone bug bounty platform. https:\/\/hackerone.com."},{"key":"e_1_3_2_1_11_1","unstructured":"2021. Phabricator Bug Bounty Program Policy. https:\/\/hackerone.com\/phabricator.  2021. Phabricator Bug Bounty Program Policy. https:\/\/hackerone.com\/phabricator."},{"key":"e_1_3_2_1_12_1","unstructured":"2021. Signal and Impact. https:\/\/docs.hackerone.com\/hackers\/signal-and-impact.html. HackerOne documentation.  2021. Signal and Impact. https:\/\/docs.hackerone.com\/hackers\/signal-and-impact.html. HackerOne documentation."},{"key":"e_1_3_2_1_13_1","volume-title":"Automated triaging of very large bug repositories. Information and software technology 89","author":"Banerjee Sean","year":"2017","unstructured":"Sean Banerjee , Zahid Syed , Jordan Helmick , Mark Culp , Kenneth Ryan , and Bojan Cukic . 2017. Automated triaging of very large bug repositories. Information and software technology 89 ( 2017 ), 1--13. Sean Banerjee, Zahid Syed, Jordan Helmick, Mark Culp, Kenneth Ryan, and Bojan Cukic. 2017. Automated triaging of very large bug repositories. Information and software technology 89 (2017), 1--13."},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1007\/11766155_21"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE-C.2017.27"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-36563-8_14"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/3091478.3091517"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2015.11.006"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1287\/mnsc.1040.0357"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-45741-3_9"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1093\/cybsec\/tyx008"},{"key":"e_1_3_2_1_22_1","first-page":"291","article-title":"Method and system for validating a vulnerability submitted by a tester in a crowdsourcing environment","volume":"10","author":"Marquez Antonio Rene","year":"2019","unstructured":"Antonio Rene Marquez , Sergio Romulo Salazar , and Nathan Sportsman . 2019 . Method and system for validating a vulnerability submitted by a tester in a crowdsourcing environment . US Patent 10 , 291 ,643. Antonio Rene Marquez, Sergio Romulo Salazar, and Nathan Sportsman. 2019. Method and system for validating a vulnerability submitted by a tester in a crowdsourcing environment. US Patent 10,291,643.","journal-title":"US Patent"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSR.2009.5069491"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-017-9541-1"},{"key":"e_1_3_2_1_25_1","volume-title":"Proceedings of the Sixteenth International Conference on Software Engineering & Knowledge Engineering. Citeseer.","author":"Murphy G","year":"2004","unstructured":"G Murphy and D Cubranic . 2004 . Automatic bug triage using text categorization . In Proceedings of the Sixteenth International Conference on Software Engineering & Knowledge Engineering. Citeseer. G Murphy and D Cubranic. 2004. Automatic bug triage using text categorization. In Proceedings of the Sixteenth International Conference on Software Engineering & Knowledge Engineering. Citeseer."},{"key":"e_1_3_2_1_26_1","volume-title":"Third workshop on the economics of information security. 19--26","author":"Ozment Andy","year":"2004","unstructured":"Andy Ozment . 2004 . Bug auctions: Vulnerability markets reconsidered . In Third workshop on the economics of information security. 19--26 . Andy Ozment. 2004. Bug auctions: Vulnerability markets reconsidered. In Third workshop on the economics of information security. 19--26."},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2005.17"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.5555\/2831143.2831209"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.5555\/647333.722747"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/APNOMS.2016.7737235"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSME.2017.14"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/1852666.1852699"},{"key":"e_1_3_2_1_33_1","volume-title":"Automatic bug triage using semi-supervised text classification. arXiv preprint arXiv:1704.04769","author":"Xuan Jifeng","year":"2017","unstructured":"Jifeng Xuan , He Jiang , Zhilei Ren , Jun Yan , and Zhongxuan Luo . 2017. Automatic bug triage using semi-supervised text classification. arXiv preprint arXiv:1704.04769 ( 2017 ). Jifeng Xuan, He Jiang, Zhilei Ren, Jun Yan, and Zhongxuan Luo. 2017. Automatic bug triage using semi-supervised text classification. arXiv preprint arXiv:1704.04769 (2017)."},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICPC.2017.28"},{"key":"e_1_3_2_1_35_1","volume-title":"The HCOMP Workshop on Mathematical Foundations of Human Computation","author":"Zhao Mingyi","year":"2016","unstructured":"Mingyi Zhao , Aron Laszka , Thomas Maillart , and Jens Grossklags . 2016 . Crowdsourced security vulnerability discovery: Modeling and organizing bug-bounty programs . In The HCOMP Workshop on Mathematical Foundations of Human Computation , Austin, TX, USA. Mingyi Zhao, Aron Laszka, Thomas Maillart, and Jens Grossklags. 2016. Crowdsourced security vulnerability discovery: Modeling and organizing bug-bounty programs. In The HCOMP Workshop on Mathematical Foundations of Human Computation, Austin, TX, USA."}],"event":{"name":"ESEM '21: ACM \/ IEEE International Symposium on Empirical Software Engineering and Measurement","location":"Bari Italy","acronym":"ESEM '21","sponsor":["SIGSOFT ACM Special Interest Group on Software Engineering","IEEE CS"]},"container-title":["Proceedings of the 15th ACM \/ IEEE International Symposium on Empirical Software Engineering and Measurement (ESEM)"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3475716.3484193","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3475716.3484193","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T20:48:18Z","timestamp":1750193298000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3475716.3484193"}},"subtitle":["Study of bug-bounty reports and developing an out-of-scope taxonomy model"],"short-title":[],"issued":{"date-parts":[[2021,10,11]]},"references-count":35,"alternative-id":["10.1145\/3475716.3484193","10.1145\/3475716"],"URL":"https:\/\/doi.org\/10.1145\/3475716.3484193","relation":{},"subject":[],"published":{"date-parts":[[2021,10,11]]},"assertion":[{"value":"2021-10-11","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}