{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,21]],"date-time":"2026-07-21T03:57:15Z","timestamp":1784606235222,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":37,"publisher":"ACM","license":[{"start":{"date-parts":[[2022,8,23]],"date-time":"2022-08-23T00:00:00Z","timestamp":1661212800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2022,8,23]]},"DOI":"10.1145\/3538969.3544416","type":"proceedings-article","created":{"date-parts":[[2022,8,17]],"date-time":"2022-08-17T23:41:40Z","timestamp":1660779700000},"page":"1-10","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":7,"title":["A Quantitative Assessment of the Detection Performance of Web Vulnerability Scanners"],"prefix":"10.1145","author":[{"given":"Emma","family":"Lavens","sequence":"first","affiliation":[{"name":"imec - DistriNet, KU Leuven, Belgium"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Pieter","family":"Philippaerts","sequence":"additional","affiliation":[{"name":"imec - DistriNet, KU Leuven, Belgium"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Wouter","family":"Joosen","sequence":"additional","affiliation":[{"name":"imec - DistriNet, KU Leuven, Belgium"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2022,8,23]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Evaluation of Web Application Vulnerability Scanner for Modern Web Application. In 2021 International Conference on Artificial Intelligence and Computer Science Technology (ICAICST). IEEE, 200\u2013204","author":"Al\u00a0Anhar Azwar","year":"2021","unstructured":"Azwar Al\u00a0Anhar and Yohan Suryanto. 2021. Evaluation of Web Application Vulnerability Scanner for Modern Web Application. In 2021 International Conference on Artificial Intelligence and Computer Science Technology (ICAICST). IEEE, 200\u2013204."},{"key":"e_1_3_2_1_2_1","article-title":"An analysis of the Effectiveness of Black-box Web Application Scanners in Detection of Stored XSSI Vulnerabilities","volume":"4","author":"Alassmi Shafi","year":"2012","unstructured":"Shafi Alassmi, Pavol Zavarsky, Dale Lindskog, Ron Ruhl, Ahmed Alasiri, Muteb Alzaidi, 2012. An analysis of the Effectiveness of Black-box Web Application Scanners in Detection of Stored XSSI Vulnerabilities. International Journal of Information Technology and Computer Science 4, 1(2012).","journal-title":"International Journal of Information Technology and Computer Science"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1002\/spe.2870"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2015.30"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-78120-0_4"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2010.27"},{"key":"e_1_3_2_1_7_1","volume-title":"Proceedings of ITASEC(2017)","author":"Burato Elisa","year":"2017","unstructured":"Elisa Burato, Pietro Ferrara, and Fausto Spoto. 2017. Security analysis of the OWASP benchmark with Julia. Proceedings of ITASEC(2017)."},{"key":"e_1_3_2_1_8_1","unstructured":"Shay Chen. [n.d.]. The Web Application Vulnerability Scanner Evaluation Project (WAVSEP). https:\/\/github.com\/sectooladdict\/wavsep. accessed on 20-Apr-2022."},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/SAI.2014.6918247"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-14215-4_7"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2006.113"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISI.2017.8004879"},{"key":"e_1_3_2_1_13_1","volume-title":"Estimation of the Youden Index and its associated cutoff point. Biometrical Journal: Journal of Mathematical Methods in Biosciences","author":"Fluss Ronen","year":"2005","unstructured":"Ronen Fluss, David Faraggi, and Benjamin Reiser. 2005. Estimation of the Youden Index and its associated cutoff point. Biometrical Journal: Journal of Mathematical Methods in Biosciences (2005), 458\u2013472."},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1109\/PRDC.2007.55"},{"key":"e_1_3_2_1_15_1","unstructured":"The\u00a0OWASP Foundation. [n.d.]. OWASP Top 10 2007. https:\/\/owasp.org\/www-pdf-archive\/OWASP_Top_10_2007.pdf. accessed on 15-Jun-2022."},{"key":"e_1_3_2_1_16_1","volume-title":"Benchmarking Approach to Compare Web Applications Static Analysis Tools Detecting OWASP Top Ten Security Vulnerabilities. Computers, Materials and Continua 64","author":"Higuera Juan","year":"2020","unstructured":"Juan Higuera, Javier Higuera, Juan Montalvo, Javier Villalba, and Juan P\u00e9rez. 2020. Benchmarking Approach to Compare Web Applications Static Analysis Tools Detecting OWASP Top Ten Security Vulnerabilities. Computers, Materials and Continua 64 (2020)."},{"key":"e_1_3_2_1_17_1","first-page":"11068","article-title":"Performance evaluation of web application security scanners for prevention and protection against vulnerabilities","volume":"12","author":"Idrissi S.E.","year":"2017","unstructured":"S.E. Idrissi, N. Berbiche, F. Guerouate, and M. Shibi. 2017. Performance evaluation of web application security scanners for prevention and protection against vulnerabilities. International Journal of Applied Engineering Research 12, 21 (2017), 11068\u201311076.","journal-title":"International Journal of Applied Engineering Research"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSNT.2012.104"},{"key":"e_1_3_2_1_19_1","unstructured":"Erwan Le\u00a0Rousseau. 2013. Damn Vulnerable Web Application (DVWA). https:\/\/dvwa.co.uk\/. accessed on 20-Apr-2022."},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/IDAACS.2015.7340766"},{"key":"e_1_3_2_1_21_1","volume-title":"Security evaluation of web application vulnerability scanners strengths and limitations using custom web application. Master\u2019s thesis. East Bay","author":"Martirosyan Yuliana","unstructured":"Yuliana Martirosyan. 2012. Security evaluation of web application vulnerability scanners strengths and limitations using custom web application. Master\u2019s thesis. East Bay, California State University."},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSENG.2018.8638176"},{"key":"e_1_3_2_1_23_1","unstructured":"Malik Mesellem. [n.d.]. Buggy Web App (bWAPP). https:\/\/www.mmebvba.com\/sites\/bwapp\/. accessed on 20-Apr-2022."},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.5120\/ijca2016907794"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSGEA.2019.00131"},{"key":"e_1_3_2_1_26_1","unstructured":"Andrey Petukhov and Dmitry Kozlov. 2008. Detecting security vulnerabilities in web applications using dynamic analysis with penetration testing. Computing Systems Lab(2008)."},{"key":"e_1_3_2_1_27_1","first-page":"43","article-title":"Studying open source vulnerability scanners for vulnerabilities in web applications","volume":"9","author":"Sagar Deepika","year":"2018","unstructured":"Deepika Sagar, Sahil Kukreja, Jwngfu Brahma, Shobha Tyagi, and Prateek Jain. 2018. Studying open source vulnerability scanners for vulnerabilities in web applications. IIOAB JOURNAL 9, 2 (2018), 43\u201349.","journal-title":"IIOAB JOURNAL"},{"key":"e_1_3_2_1_28_1","volume-title":"Improving the adoption of dynamic web security vulnerability scanners. Master\u2019s thesis","author":"Smeets Y","unstructured":"Y Smeets. 2015. Improving the adoption of dynamic web security vulnerability scanners. Master\u2019s thesis. Radboud University, NL."},{"key":"e_1_3_2_1_29_1","volume-title":"Proceedings of the 10th Conference for Informatics and Information Technology (CIIT).","author":"Suteva Natasa","year":"2013","unstructured":"Natasa Suteva, Dragi Zlatkovski, and Aleksandra Mileva. 2013. Evaluation and testing of several free\/open source web vulnerability scanners. In Proceedings of the 10th Conference for Informatics and Information Technology (CIIT)."},{"key":"e_1_3_2_1_30_1","unstructured":"Larry Suto. 2010. Analyzing the accuracy and time costs of web application security scanners."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"crossref","unstructured":"Emin\u00a0\u0130slam Tatli and Bedirhan Urgun. 2017. WIVET \u2014 Benchmarking Coverage Qualities of Web Crawlers. Comput. J. (2017) 555\u2013572.","DOI":"10.1093\/comjnl\/bxw072"},{"key":"e_1_3_2_1_32_1","unstructured":"The OWASP Foundation. [n.d.]. OWASP Benchmark Project. https:\/\/owasp.org\/www-project-benchmark\/. accessed on 20-Apr-2022."},{"key":"e_1_3_2_1_33_1","unstructured":"The OWASP Foundation. [n.d.]. OWASP VulnerableApp. https:\/\/owasp.org\/www-project-vulnerableapp\/. accessed on 20-Apr-2022."},{"key":"e_1_3_2_1_34_1","unstructured":"The OWASP Foundation. 2021. OWASP Top Ten Web Application Security Risks. https:\/\/owasp.org\/www-project-top-ten\/. accessed on 20-Apr-2022."},{"key":"e_1_3_2_1_35_1","unstructured":"Bedirhan Urgun. [n.d.]. Web Input Vector Extractor Teaser (WIVET). https:\/\/github.com\/bedirhan\/wivet. accessed on 20-Apr-2022."},{"key":"e_1_3_2_1_36_1","first-page":"602","article-title":"Benchmarking of pentesting tools. International Journal of Computer, Electrical","volume":"11","author":"Alejandro\u00a0Armas Vega Esteban","year":"2017","unstructured":"Esteban Alejandro\u00a0Armas Vega, Ana Lucila\u00a0Sandoval Orozco, and Luis Javier\u00a0Garc\u00eda Villalba. 2017. Benchmarking of pentesting tools. International Journal of Computer, Electrical, Automation, Control and Information Engineering 11, 5 (2017), 602\u2013605.","journal-title":"Automation, Control and Information Engineering"},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2009.5270294"}],"event":{"name":"ARES 2022: The 17th International Conference on Availability, Reliability and Security","location":"Vienna Austria","acronym":"ARES 2022"},"container-title":["Proceedings of the 17th International Conference on Availability, Reliability and Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3538969.3544416","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3538969.3544416","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T18:59:57Z","timestamp":1750186797000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3538969.3544416"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,8,23]]},"references-count":37,"alternative-id":["10.1145\/3538969.3544416","10.1145\/3538969"],"URL":"https:\/\/doi.org\/10.1145\/3538969.3544416","relation":{},"subject":[],"published":{"date-parts":[[2022,8,23]]},"assertion":[{"value":"2022-08-23","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}