{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,5]],"date-time":"2026-07-05T21:52:33Z","timestamp":1783288353593,"version":"3.54.6"},"publisher-location":"New York, NY, USA","reference-count":35,"publisher":"ACM","license":[{"start":{"date-parts":[[2021,12,6]],"date-time":"2021-12-06T00:00:00Z","timestamp":1638748800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2021,12,6]]},"DOI":"10.1145\/3485832.3488026","type":"proceedings-article","created":{"date-parts":[[2021,12,6]],"date-time":"2021-12-06T13:42:32Z","timestamp":1638798152000},"page":"194-206","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":14,"title":["Dicos: Discovering Insecure Code Snippets from Stack Overflow Posts by Leveraging User Discussions"],"prefix":"10.1145","author":[{"given":"Hyunji","family":"Hong","sequence":"first","affiliation":[{"name":"Dept. of Computer Science and Engineering \/ Korea University \/ Computer &amp; Communication Security Lab, Korea University, Republic of Korea"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Seunghoon","family":"Woo","sequence":"additional","affiliation":[{"name":"Dept. of Computer Science and Engineering \/ Korea University \/ Computer &amp; Communication Security Lab, Korea University, Republic of Korea"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Heejo","family":"Lee","sequence":"additional","affiliation":[{"name":"Dept. of Computer Science and Engineering \/ Korea University, Korea University, Republic of Korea"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2021,12,6]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"The Impact of Information Sources on Code Security. In 2016 IEEE Symposium on Security and Privacy (SP). IEEE, 289\u2013305","author":"Acar Yasemin","year":"2016","unstructured":"Yasemin Acar, Michael Backes, Sascha Fahl, Doowon Kim, Michelle\u00a0L Mazurek, and Christian Stransky. 2016. You Get Where You\u2019re Looking for: The Impact of Information Sources on Code Security. In 2016 IEEE Symposium on Security and Privacy (SP). IEEE, 289\u2013305."},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/3196398.3196430"},{"key":"e_1_3_2_1_3_1","unstructured":"BetterProgramming. 2020. Why Code Snippets From Stack Overflow Can Break Your Project. https:\/\/betterprogramming.pub\/why-code-snippets-from-stack-overflow-can-break-your-project-ced579a48ddb"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2020.2994006"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2019.00065"},{"key":"e_1_3_2_1_6_1","unstructured":"Ctags 2021. Universal Ctags. Ctags. https:\/\/github.com\/universal-ctags\/."},{"key":"e_1_3_2_1_7_1","volume-title":"The Impact of Copy&Paste on Android Application Security. In 2017 IEEE Symposium on Security and Privacy (SP). IEEE, 121\u2013136","author":"Fischer Felix","year":"2017","unstructured":"Felix Fischer, Konstantin B\u00f6ttinger, Huang Xiao, Christian Stransky, Yasemin Acar, Michael Backes, and Sascha Fahl. 2017. Stack Overflow Considered Harmful? The Impact of Copy&Paste on Android Application Security. In 2017 IEEE Symposium on Security and Privacy (SP). IEEE, 121\u2013136."},{"key":"e_1_3_2_1_8_1","volume-title":"2019 28th USENIX Security Symposium (Security). 339\u2013356","author":"Fischer Felix","year":"2019","unstructured":"Felix Fischer, Huang Xiao, Ching-Yu Kao, Yannick Stachelscheid, Benjamin Johnson, Danial Razar, Paul Fawkesley, Nat Buckley, Konstantin B\u00f6ttinger, Paul Muntean, and Jens Grossklags. 2019. Stack Overflow Considered Helpful! Deep Learning Security Nudges Towards Stronger Cryptography. In 2019 28th USENIX Security Symposium (Security). 339\u2013356."},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/3447332.3447334"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2018.02.007"},{"key":"e_1_3_2_1_11_1","volume-title":"VUDDY: A Scalable Approach for Vulnerable Code Clone Discovery. In 2017 IEEE Symposium on Security and Privacy (SP). IEEE, 595\u2013614","author":"Kim Seulbae","year":"2017","unstructured":"Seulbae Kim, Seunghoon Woo, Heejo Lee, and Hakjoo Oh. 2017. VUDDY: A Scalable Approach for Vulnerable Code Clone Discovery. In 2017 IEEE Symposium on Security and Privacy (SP). IEEE, 595\u2013614."},{"key":"e_1_3_2_1_12_1","volume-title":"OCTOPOCS: Automatic Verification of Propagated Vulnerable Code Using Reformed Proofs of Concept. In 2021 51st Annual IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN)","author":"Kwon Seongkyeong","year":"2021","unstructured":"Seongkyeong Kwon, Seunghoon Woo, Gangmo Seong, and Heejo Lee. 2021. OCTOPOCS: Automatic Verification of Propagated Vulnerable Code Using Reformed Proofs of Concept. In 2021 51st Annual IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN). IEEE, 174\u2013185."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134072"},{"key":"e_1_3_2_1_14_1","volume-title":"2019 28th USENIX Security Symposium (Security). 1769\u20131786","author":"Lu Kangjie","year":"2019","unstructured":"Kangjie Lu, Aditya Pakki, and Qiushi Wu. 2019. Detecting Missing-Check Bugs via Semantic- and Context-Aware Criticalness and Constraints Inferences. In 2019 28th USENIX Security Symposium (Security). 1769\u20131786."},{"key":"e_1_3_2_1_15_1","volume-title":"SPIDER: Enabling Fast Patch Propagation in Related Software Repositories. In 2020 IEEE Symposium on Security and Privacy (SP). IEEE, 1562\u20131579","author":"Machiry Aravind","year":"2020","unstructured":"Aravind Machiry, Nilo Redini, Eric Camellini, Christopher Kruegel, and Giovanni Vigna. 2020. SPIDER: Enabling Fast Patch Propagation in Related Software Repositories. In 2020 IEEE Symposium on Security and Privacy (SP). IEEE, 1562\u20131579."},{"key":"e_1_3_2_1_16_1","unstructured":"Microsoft. 2019. Microsoft Build C6328. https:\/\/docs.microsoft.com\/en-us\/cpp\/code-quality\/c6328?view=msvc-160"},{"key":"e_1_3_2_1_17_1","unstructured":"MITRE. 2021. CWE-676: Use of Potentially Dangerous Function. https:\/\/cwe.mitre.org\/data\/definitions\/676.html"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813604"},{"key":"e_1_3_2_1_19_1","unstructured":"Google\u00a0Cloud Platform. 2021. Google Bigquery StackOverflow Data. https:\/\/cloud.google.com\/bigquery\/public-data."},{"key":"e_1_3_2_1_20_1","unstructured":"Reddit. 2018. Docker for Windows won\u2019t start if Razer Synapse 3 is running. https:\/\/www.reddit.com\/r\/docker\/comments\/815l9n\/docker_for_windows_wont_start_if_razer_synapse_3\/"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/2884781.2884877"},{"key":"e_1_3_2_1_22_1","unstructured":"Offensive Security. 2021. Exploit Database. https:\/\/www.exploit-db.com\/."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2020.3023664"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2018.2874470"},{"key":"e_1_3_2_1_25_1","volume-title":"Vulnerability: An Empirical Study of Secret Security Patch in OSS. In 49th Annual IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN). IEEE, 485\u2013492","author":"Wang Xinda","year":"2019","unstructured":"Xinda Wang, Kun Sun, Archer Batcheller, and Sushil Jajodia. 2019. Detecting \u201d0-Day\u201d Vulnerability: An Empirical Study of Secret Security Patch in OSS. In 49th Annual IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN). IEEE, 485\u2013492."},{"key":"e_1_3_2_1_26_1","unstructured":"Wikipedia. 2021. Jaccrd index. https:\/\/en.wikipedia.org\/wiki\/Jaccard_index."},{"key":"e_1_3_2_1_27_1","volume-title":"2021 30th USENIX Security Symposium (Security). 3041\u20133058","author":"Woo Seunghoon","year":"2021","unstructured":"Seunghoon Woo, Dongwook Lee, Sunghan Park, Heejo Lee, and Sven Dietrich. 2021. V0Finder: Discovering the Correct Origin of Publicly Reported Software Vulnerabilities. In 2021 30th USENIX Security Symposium (Security). 3041\u20133058."},{"key":"e_1_3_2_1_28_1","volume-title":"CENTRIS: A Precise and Scalable Approach for Identifying Modified Open-Source Software Reuse. In 2021 IEEE\/ACM 43rd International Conference on Software Engineering (ICSE). IEEE, 860\u2013872","author":"Woo Seunghoon","year":"2021","unstructured":"Seunghoon Woo, Sunghan Park, Seulbae Kim, Heejo Lee, and Hakjoo Oh. 2021. CENTRIS: A Precise and Scalable Approach for Identifying Modified Open-Source Software Reuse. In 2021 IEEE\/ACM 43rd International Conference on Software Engineering (ICSE). IEEE, 860\u2013872."},{"key":"e_1_3_2_1_29_1","volume-title":"How do developers utilize source code from stack overflow?Empirical Software Engineering 24, 2","author":"Wu Yuhao","year":"2019","unstructured":"Yuhao Wu, Shaowei Wang, Cor-Paul Bezemer, and Katsuro Inoue. 2019. How do developers utilize source code from stack overflow?Empirical Software Engineering 24, 2 (2019), 637\u2013673."},{"key":"e_1_3_2_1_30_1","volume-title":"2020 29th USENIX Security Symposium (Security). 1165\u20131182","author":"Xiao Yang","year":"2020","unstructured":"Yang Xiao, Bihuan Chen, Chendong Yu, Zhengzi Xu, Zimu Yuan, Feng Li, Binghong Liu, Yang Liu, Wei Huo, Wei Zou, 2020. MVP: Detecting Vulnerabilities using Patch-Enhanced Vulnerability Signatures. In 2020 29th USENIX Security Symposium (Security). 1165\u20131182."},{"key":"e_1_3_2_1_31_1","volume-title":"Modeling and Discovering Vulnerabilities with Code Property Graphs. In 2014 IEEE Symposium on Security and Privacy (SP). IEEE, 590\u2013604","author":"Yamaguchi Fabian","year":"2014","unstructured":"Fabian Yamaguchi, Nico Golde, Daniel Arp, and Konrad Rieck. 2014. Modeling and Discovering Vulnerabilities with Code Property Graphs. In 2014 IEEE Symposium on Security and Privacy (SP). IEEE, 590\u2013604."},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/3274694.3274742"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"crossref","unstructured":"Haoxiang Zhang Shaowei Wang Tse-Hsun Chen and Ahmed\u00a0E Hassan. 2021. Are Comments on Stack Overflow Well Organized for Easy Retrieval by Developers?ACM Transactions on Software Engineering and Methodology (TOSEM) 30 2(2021) 1\u201331.","DOI":"10.1145\/3434279"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/3180155.3180260"},{"key":"e_1_3_2_1_35_1","volume-title":"Analyzing and Supporting Adaptation of Online Code Examples. In 2019 IEEE\/ACM 41st International Conference on Software Engineering (ICSE). IEEE, 316\u2013327","author":"Zhang Tianyi","year":"2019","unstructured":"Tianyi Zhang, Di Yang, Crista Lopes, and Miryung Kim. 2019. Analyzing and Supporting Adaptation of Online Code Examples. In 2019 IEEE\/ACM 41st International Conference on Software Engineering (ICSE). IEEE, 316\u2013327."}],"event":{"name":"ACSAC '21: Annual Computer Security Applications Conference","location":"Virtual Event USA","acronym":"ACSAC '21"},"container-title":["Annual Computer Security Applications Conference"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3485832.3488026","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3485832.3488026","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T19:17:12Z","timestamp":1755890232000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3485832.3488026"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,12,6]]},"references-count":35,"alternative-id":["10.1145\/3485832.3488026","10.1145\/3485832"],"URL":"https:\/\/doi.org\/10.1145\/3485832.3488026","relation":{},"subject":[],"published":{"date-parts":[[2021,12,6]]},"assertion":[{"value":"2021-12-06","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}