{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T06:52:33Z","timestamp":1782802353307,"version":"3.54.5"},"publisher-location":"New York, NY, USA","reference-count":53,"publisher":"ACM","license":[{"start":{"date-parts":[[2022,4,25]],"date-time":"2022-04-25T00:00:00Z","timestamp":1650844800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"National Cyber Security Centre","award":["NA"],"award-info":[{"award-number":["NA"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2022,4,25]]},"DOI":"10.1145\/3477314.3506968","type":"proceedings-article","created":{"date-parts":[[2022,5,7]],"date-time":"2022-05-07T00:37:36Z","timestamp":1651883856000},"page":"1465-1474","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":4,"title":["A longitudinal study of hacker behaviour"],"prefix":"10.1145","author":[{"given":"Thomas","family":"Walshe","sequence":"first","affiliation":[{"name":"University of Oxford"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Andrew","family":"Simpson","sequence":"additional","affiliation":[{"name":"University of Oxford"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2022,5,6]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Pacific Asia Conference on Information Systems (PACIS).","author":"Al-Banna Mortada","year":"2018","unstructured":"Mortada Al-Banna, Boualem Benatallah, Daniel Schlagwein, Moshe C Barukh, and Elisa Bertino. 2018. Friendly Hackers to the Rescue: How Organizations Perceive Crowdsourced Vulnerability Discovery. In Pacific Asia Conference on Information Systems (PACIS)."},{"key":"e_1_3_2_1_2_1","first-page":"71","article-title":"Software vulnerability markets: Discoverers and buyers. International Journal of Computer","volume":"8","author":"Algarni Abdullah","year":"2014","unstructured":"Abdullah Algarni and Yashwant Malaiya. 2014. Software vulnerability markets: Discoverers and buyers. International Journal of Computer, Information Science and Engineering 8, 3 (2014), 71--81.","journal-title":"Information Science and Engineering"},{"key":"e_1_3_2_1_3_1","volume-title":"Proceedings of the International Conference on Security and Management (SAM). The Steering Committee of The World Congress in Computer Science, Computer ..., 1.","author":"Algarni Abdullah M","year":"2013","unstructured":"Abdullah M Algarni and Yashwant K Malaiya. 2013. Most successful vulnerability discoverers: Motivation and methods. In Proceedings of the International Conference on Security and Management (SAM). The Steering Committee of The World Congress in Computer Science, Computer ..., 1."},{"key":"e_1_3_2_1_4_1","volume-title":"Retrieved","author":"BSIMM.","year":"2018","unstructured":"BSIMM. 2018. BSIMM9: Building Security in Maturity Model version 9. Retrieved December 18, 2019 from https:\/\/www.bsimm.com\/download\/"},{"key":"e_1_3_2_1_5_1","volume-title":"Retrieved","year":"2018","unstructured":"Bugcrowd. 2018. Bugcrowd: State of bug bounties. Retrieved July 15, 2019 from https:\/\/www.bugcrowd.com\/resources\/reports\/state-of-bug-bounty-2018\/"},{"key":"e_1_3_2_1_6_1","volume-title":"Retrieved","year":"2021","unstructured":"Bugcrowd. 2021. Bugcrowd University. Retrieved May 10, 2021 from https:\/\/www.bugcrowd.com\/hackers\/bugcrowd-university\/"},{"key":"e_1_3_2_1_8_1","volume-title":"Retrieved","year":"2021","unstructured":"Crunchbase. 2021. Bugcrowd Financials. Retrieved February 10, 2021 from https:\/\/www.crunchbase.com\/organization\/bugcrowd\/company_financials"},{"key":"e_1_3_2_1_9_1","volume-title":"Retrieved","year":"2021","unstructured":"Crunchbase. 2021. HackerOne company financials. Retrieved May 10, 2021 from https:\/\/www.crunchbase.com\/organization\/hackerone\/company_financials"},{"key":"e_1_3_2_1_10_1","volume-title":"Retrieved","year":"2021","unstructured":"Crunchbase. 2021. HackerOne Financials. Retrieved February 10, 2021 from https:\/\/www.crunchbase.com\/organization\/hackerone\/company_financials"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/2145204.2145355"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/2535813.2535818"},{"key":"e_1_3_2_1_13_1","volume-title":"An Empirical Study of Vulnerability Rewards Programs. In USENIX Security Symposium. 273--288","author":"Finifter Matthew","year":"2013","unstructured":"Matthew Finifter, Devdatta Akhawe, and David Wagner. 2013. An Empirical Study of Vulnerability Rewards Programs. In USENIX Security Symposium. 273--288."},{"key":"e_1_3_2_1_14_1","volume-title":"Climbing up the Leaderboard: An Empirical Study of Applying Gamification Techniques to a Computer Programming Class. Electronic Journal of e-learning 14, 2","author":"Fotaris Panagiotis","year":"2016","unstructured":"Panagiotis Fotaris, Theodoros Mastoras, Richard Leinfellner, and Yasmine Rosunally. 2016. Climbing up the Leaderboard: An Empirical Study of Applying Gamification Techniques to a Computer Programming Class. Electronic Journal of e-learning 14, 2 (2016), 94--110."},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/3091478.3091517"},{"key":"e_1_3_2_1_16_1","volume-title":"Retrieved","year":"2021","unstructured":"Google. 2021. Vulnerability Reward Program: 2020 Year in Review. Retrieved February 10, 2021 from https:\/\/security.googleblog.com\/2021\/02\/vulnerability-reward-program-2020-year.html"},{"key":"e_1_3_2_1_17_1","volume-title":"Retrieved","author":"Government US","year":"2017","unstructured":"US Government. 2017. United States Government: Vulnerabilities Equities Policy and Processfor the United States Government. Retrieved September 27, 2019 from https:\/\/www.whitehouse.gov\/sites\/whitehouse.gov\/files\/images\/External%20-%20Unclassified%20VEP%20Charter%20FINAL.PDF"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"crossref","unstructured":"Audrey Guinchard. 2017. The Computer Misuse Act 1990 to Support Vulnerability Research? Proposal for a Defence for Hacking as a Strategy in the Fight against Cybercrime. (2017).","DOI":"10.2139\/ssrn.2946763"},{"key":"e_1_3_2_1_19_1","volume-title":"Retrieved","author":"Gurfinkel Dan","year":"2020","unstructured":"Dan Gurfinkel. 2020. Facebook: Marking the 10th Anniversary of Our Bug Bounty Program. Retrieved February 10, 2021 from https:\/\/about.fb.com\/news\/2020\/11\/bug-bounty-program-10th-anniversary\/"},{"key":"e_1_3_2_1_20_1","volume-title":"Retrieved","year":"2019","unstructured":"HackerOne. 2019. HackerOne: 188 fascinating facts. Retrieved February 25, 2019 from https:\/\/www.hackerone.com\/blog\/118-Fascinating-Facts-HackerOnes-Hacker-Powered-Security-Report-2018"},{"key":"e_1_3_2_1_21_1","volume-title":"Retrieved","year":"2019","unstructured":"HackerOne. 2019. HackerOne: The 2019 hacker report. Retrieved September 23, 2019 from https:\/\/www.hackerone.com\/sites\/default\/files\/2019-02\/the-2019-hacker-report_3.pdf"},{"key":"e_1_3_2_1_22_1","volume-title":"Retrieved","year":"2020","unstructured":"HackerOne. 2020. Amazon Vulnerability Research Program. Retrieved February 10, 2021 from https:\/\/hackerone.com\/amazonvrp?type=team"},{"key":"e_1_3_2_1_23_1","volume-title":"Retrieved","year":"2020","unstructured":"HackerOne. 2020. HackerOne: The 2020 hacker report. Retrieved February 10, 2021 from https:\/\/www.hackerone.com\/resources\/reporting\/the-2020-hacker-report"},{"key":"e_1_3_2_1_24_1","volume-title":"Retrieved","year":"2020","unstructured":"HackerOne. 2020. Tencent. Retrieved February 10, 2021 from https:\/\/hackerone.com\/tencent?type=team"},{"key":"e_1_3_2_1_25_1","volume-title":"Retrieved","year":"2021","unstructured":"HackerOne. 2021. Hacker101. Retrieved May 10, 2021 from https:\/\/www.hackerone.com\/for-hackers\/hacker-101"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISDA.2005.85"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/ESEM.2017.34"},{"key":"e_1_3_2_1_28_1","volume-title":"Retrieved","author":"Hern Alex","year":"2019","unstructured":"Alex Hern. 2019. The Guardian: Apple to pay hackers more than $1m to find security flaws. Retrieved September 10, 2019 from https:\/\/www.theguardian.com\/technology\/2019\/aug\/12\/apple-hackers-black-hat-conference"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICON.2004.1409210"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1201\/1086\/44797.13.5.20041101\/84907.5"},{"key":"e_1_3_2_1_31_1","volume-title":"Network externalities, competition, and compatibility. The American economic review 75, 3","author":"Katz Michael L","year":"1985","unstructured":"Michael L Katz and Carl Shapiro. 1985. Network externalities, competition, and compatibility. The American economic review 75, 3 (1985), 424--440."},{"key":"e_1_3_2_1_32_1","first-page":"753","article-title":"Bugs in the Market: Creating a Legitimate, Transparent, and Vendor-Focused Market for Software Vulnerabilities","volume":"58","author":"Kesan Jay P","year":"2016","unstructured":"Jay P Kesan and Carol M Hayes. 2016. Bugs in the Market: Creating a Legitimate, Transparent, and Vendor-Focused Market for Software Vulnerabilities. Ariz. L. Rev. 58 (2016), 753.","journal-title":"Ariz. L. Rev."},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.1997.595443"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1609\/hcomp.v3i1.13226"},{"key":"e_1_3_2_1_35_1","volume-title":"Retrieved","author":"Leyden John","year":"2016","unstructured":"John Leyden. 2016. The Register: Fatigue fears over bug bounty programs. Retrieved August 27, 2020 from https:\/\/www.theregister.com\/2016\/11\/09\/bug_bounty_fatigue_fears\/"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1093\/cybsec\/tyx008"},{"key":"e_1_3_2_1_37_1","volume-title":"Bug Bounty Programs for Cybersecurity: Practices, Issues, and Recommendations","author":"Malladi Suresh S","year":"2019","unstructured":"Suresh S Malladi and Hemang C Subramanian. 2019. Bug Bounty Programs for Cybersecurity: Practices, Issues, and Recommendations. IEEE Software (2019)."},{"key":"e_1_3_2_1_38_1","volume-title":"Ekaprana Wijaya, et al.","author":"Marutho Dhendra","year":"2018","unstructured":"Dhendra Marutho, Sunarna Hendra Handaka, Ekaprana Wijaya, et al. 2018. The determination of cluster number at k-mean using elbow method and purity evaluation on headline news. In 2018 International Seminar on Application for Technology of Information and Communication. IEEE, 533--538."},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1080\/23738871.2018.1546883"},{"key":"e_1_3_2_1_40_1","volume-title":"Retrieved","year":"2021","unstructured":"Microsoft. 2021. Bug Bounty Program. Retrieved February 10, 2021 from https:\/\/www.microsoft.com\/en-us\/msrc\/bounty"},{"key":"e_1_3_2_1_41_1","volume-title":"Retrieved","author":"Mougoue Ernest","year":"2016","unstructured":"Ernest Mougoue. 2016. Synopsys: Secure SDLC 101. Retrieved July 21, 2019 from https:\/\/www.synopsys.com\/blogs\/software-security\/secure-sdlc\/"},{"key":"e_1_3_2_1_42_1","volume-title":"Proposal of a Novel Bug Bounty Implementation Using Gamification. arXiv preprint arXiv:2009.10158","author":"O'Hare Jamie","year":"2020","unstructured":"Jamie O'Hare and Lynsay A Shepherd. 2020. Proposal of a Novel Bug Bounty Implementation Using Gamification. arXiv preprint arXiv:2009.10158 (2020)."},{"key":"e_1_3_2_1_43_1","volume-title":"Third Workshop on the Economics of Information Security. 19--26","author":"Ozment Andy","year":"2004","unstructured":"Andy Ozment. 2004. Bug auctions: Vulnerability markets reconsidered. In Third Workshop on the Economics of Information Security. 19--26."},{"key":"e_1_3_2_1_44_1","volume-title":"Retrieved","author":"Pistilli Melissa","year":"2020","unstructured":"Melissa Pistilli. 2020. 10 Top Technology Stocks by Market Cap. Retrieved February 10, 2021 from https:\/\/investingnews.com\/daily\/tech-investing\/top-technology-stocks\/"},{"key":"e_1_3_2_1_45_1","volume-title":"Hidden Markov models fundamentals. CS229 Section Notes 1","author":"Ramage Daniel","year":"2007","unstructured":"Daniel Ramage. 2007. Hidden Markov models fundamentals. CS229 Section Notes 1 (2007)."},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1007\/s12130-999-1026-0"},{"key":"e_1_3_2_1_47_1","unstructured":"Brent R Rowe and Michael P Gallaher. 2006. Private sector cyber security investment strategies: An empirical analysis. In The fifth workshop on the economics of information security (WEIS06)."},{"key":"e_1_3_2_1_48_1","volume-title":"Retrieved","year":"2017","unstructured":"Samsung. 2017. Samsung Group: Get up to $200,000 by reporting vulnerabilities. Retrieved September 10, 2019 from https:\/\/seap.samsung.com\/content\/samsung-bug-bounty-get-200000-reporting-vulnerabilities"},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-04989-7_13"},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00003"},{"key":"e_1_3_2_1_51_1","volume-title":"An Empirical Study of Bug Bounty Programs. In 2020 IEEE 2nd International Workshop on Intelligent Bug Fixing (IBF). IEEE, 35--44","author":"Walshe Thomas","year":"2020","unstructured":"Thomas Walshe and Andrew Simpson. 2020. An Empirical Study of Bug Bounty Programs. In 2020 IEEE 2nd International Workshop on Intelligent Bug Fixing (IBF). IEEE, 35--44."},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.3390\/j2020016"},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1145\/2663887.2663906"},{"key":"e_1_3_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813704"}],"event":{"name":"SAC '22: The 37th ACM\/SIGAPP Symposium on Applied Computing","location":"Virtual Event","acronym":"SAC '22","sponsor":["SIGAPP ACM Special Interest Group on Applied Computing"]},"container-title":["Proceedings of the 37th ACM\/SIGAPP Symposium on Applied Computing"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3477314.3506968","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3477314.3506968","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T20:18:33Z","timestamp":1750191513000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3477314.3506968"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,4,25]]},"references-count":53,"alternative-id":["10.1145\/3477314.3506968","10.1145\/3477314"],"URL":"https:\/\/doi.org\/10.1145\/3477314.3506968","relation":{},"subject":[],"published":{"date-parts":[[2022,4,25]]},"assertion":[{"value":"2022-05-06","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}