{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,14]],"date-time":"2026-05-14T22:51:29Z","timestamp":1778799089884,"version":"3.51.4"},"publisher-location":"New York, NY, USA","reference-count":44,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,4,30]],"date-time":"2023-04-30T00:00:00Z","timestamp":1682812800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000001","name":"NSF (National Science Foundation)","doi-asserted-by":"publisher","award":["CNS-1813974, CNS-2126654, CNS-2211575"],"award-info":[{"award-number":["CNS-1813974, CNS-2126654, CNS-2211575"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000006","name":"Office of Naval Research","doi-asserted-by":"publisher","award":["N00014-20-1-2720"],"award-info":[{"award-number":["N00014-20-1-2720"]}],"id":[{"id":"10.13039\/100000006","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,4,30]]},"DOI":"10.1145\/3543507.3583394","type":"proceedings-article","created":{"date-parts":[[2023,4,26]],"date-time":"2023-04-26T23:30:25Z","timestamp":1682551825000},"page":"2284-2294","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":4,"title":["Scan Me If You Can: Understanding and Detecting Unwanted Vulnerability Scanning"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-4760-308X","authenticated-orcid":false,"given":"Xigao","family":"Li","sequence":"first","affiliation":[{"name":"Computer Science, Stony Brook University, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1370-9305","authenticated-orcid":false,"given":"Babak","family":"Amin Azad","sequence":"additional","affiliation":[{"name":"Computer Science, Stony Brook University, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7361-1898","authenticated-orcid":false,"given":"Amir","family":"Rahmati","sequence":"additional","affiliation":[{"name":"Computer Science, Stony Brook University, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9366-357X","authenticated-orcid":false,"given":"Nick","family":"Nikiforakis","sequence":"additional","affiliation":[{"name":"Computer Science, Stony Brook University, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2023,4,30]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"2022. Acunetix online scanner. https:\/\/www.acunetix.com\/online-vulnerability-scanner\/."},{"key":"e_1_3_2_1_2_1","unstructured":"2022. Tenable cloud web scanner. https:\/\/www.tenable.com\/products\/tenable-io."},{"key":"e_1_3_2_1_3_1","unstructured":"apachebench 2022. AB - Apache HTTP server benchmarking tool. https:\/\/httpd.apache.org\/docs\/2.4\/programs\/ab.html."},{"key":"e_1_3_2_1_4_1","unstructured":"arachni 2022. Arachni Web Application Security Scanner Framework. https:\/\/www.arachni-scanner.com\/."},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1109\/ESEM.2011.18"},{"key":"e_1_3_2_1_6_1","volume-title":"International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment. Springer.","author":"Azad Babak\u00a0Amin","year":"2020","unstructured":"Babak\u00a0Amin Azad, Oleksii Starov, Pierre Laperdrix, and Nick Nikiforakis. 2020. Web runner 2049: Evaluating third-party anti-bot services. In International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment. Springer."},{"key":"e_1_3_2_1_7_1","unstructured":"Lee Brotherston. 2022. TLS Fingerprinting library. https:\/\/github.com\/LeeBrotherston\/tls-fingerprinting. https:\/\/github.com\/LeeBrotherston\/tls-fingerprinting"},{"key":"e_1_3_2_1_8_1","unstructured":"BugCrowd. 2022. Trello bug bounty program. https:\/\/bugcrowd.com\/trello."},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/2994459.2994467"},{"key":"e_1_3_2_1_10_1","unstructured":"Cybersecurity and Infrastructure\u00a0Security Agency. 2021. Apache Log4j Vulnerability Guidance. https:\/\/www.cisa.gov\/uscert\/apache-log4j-vulnerability-guidance."},{"key":"e_1_3_2_1_11_1","volume-title":"21st { USENIX} Security Symposium ({ USENIX} Security","author":"Doup\u00e9 Adam","year":"2012","unstructured":"Adam Doup\u00e9, Ludovico Cavedon, Christopher Kruegel, and Giovanni Vigna. 2012. Enemy of the state: A state-aware black-box web vulnerability scanner. In 21st { USENIX} Security Symposium ({ USENIX} Security 2012)."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-14215-4_7"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.5555\/1881151.1881152"},{"key":"e_1_3_2_1_14_1","volume-title":"Black Widow: Blackbox Data-driven Web Scanning. IEEE Symposium on Security and Privacy","author":"Eriksson Benjamin","year":"2021","unstructured":"Benjamin Eriksson, Giancarlo Pellegrino, and Andrei Sabelfeld. 2021. Black Widow: Blackbox Data-driven Web Scanning. IEEE Symposium on Security and Privacy (2021)."},{"key":"e_1_3_2_1_15_1","unstructured":"Alicia Hope. 2021. Massive Cyber Attacks Target F5 BIG-IP Critical Vulnerabilities After Firm Releases Updates. https:\/\/www.cpomagazine.com\/cyber-security\/massive-cyber-attacks-target-f5-big-ip-critical-vulnerabilities-after-firm-releases-updates\/."},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00017"},{"key":"e_1_3_2_1_17_1","volume-title":"21st USENIX Security Symposium (USENIX Security 12)","author":"Jacob Gregoire","year":"2012","unstructured":"Gregoire Jacob, Engin Kirda, Christopher Kruegel, and Giovanni Vigna. 2012. PUBCRAWL: Protecting Users and Businesses from CRAWLers. In 21st USENIX Security Symposium (USENIX Security 12). USENIX Association, Bellevue, WA, 507\u2013522. https:\/\/www.usenix.org\/conference\/usenixsecurity12\/technical-sessions\/presentation\/jacob"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00079"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484765"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00079"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/1145581.1145634"},{"key":"e_1_3_2_1_22_1","unstructured":"majestic 2022. Majestic Million. https:\/\/majestic.com\/reports\/majestic-million."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/IDAACS.2015.7340766"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSENG.2018.8638176"},{"key":"e_1_3_2_1_25_1","unstructured":"mturk 2022. Amazon Mechanical Turk. https:\/\/www.mturk.com\/."},{"key":"e_1_3_2_1_26_1","unstructured":"NIST. 2021. CVSS Severity Distribution Over Time. https:\/\/nvd.nist.gov\/general\/visualizations\/vulnerability-visualizations\/cvss-severity-distribution-over-time."},{"key":"e_1_3_2_1_27_1","unstructured":"Charlie Osborne. 2021. Critical remote code execution flaw in thousands of VMWare vCenter servers remains unpatched. https:\/\/www.zdnet.com\/article\/critical-remote-code-execution-flaw-in-thousands-of-vmware-vcenter-servers-remains-unpatched\/."},{"key":"e_1_3_2_1_28_1","unstructured":"owasp 2022. Free for Open Source Application Security Tools. https:\/\/owasp.org\/www-community\/Free_for_Open_Source_Application_Security_Tools."},{"key":"e_1_3_2_1_29_1","unstructured":"owasp 2022. OWASP Zed Attack Proxy (ZAP). https:\/\/owasp.org\/www-project-zap\/."},{"key":"e_1_3_2_1_30_1","unstructured":"owasp 2022. WSTG - v4.1 Testing Tools Resource. https:\/\/owasp.org\/www-project-web-security-testing-guide\/v41\/6-Appendix\/A-Testing_Tools_Resource."},{"key":"e_1_3_2_1_31_1","volume-title":"USENIX Annual Technical Conference, General Track.","author":"Park KyoungSoo","year":"2006","unstructured":"KyoungSoo Park, Vivek\u00a0S Pai, Kang-Won Lee, and Seraphin\u00a0B Calo. 2006. Securing Web Service by Automatic Robot Detection.. In USENIX Annual Technical Conference, General Track."},{"key":"e_1_3_2_1_32_1","unstructured":"Davor Petreski. 2019. Integrating Web Vulnerability Scanners in Continuous Integration: DAST for CI\/CD. https:\/\/blog.probely.com\/integrating-web-vulnerability-scanners-in-continuous-integration-dast-for-ci-cd-7637eaff26bd."},{"key":"e_1_3_2_1_33_1","unstructured":"Piwik. 2022. Piwik Pro bug bounty program. https:\/\/piwik.pro\/security-bug-bounty-programat-piwik-pro\/."},{"key":"e_1_3_2_1_34_1","unstructured":"PortSwigger. 2019. CI\/CD security testing. https:\/\/portswigger.net\/developers\/ci-cd-security."},{"key":"e_1_3_2_1_35_1","volume-title":"An overview of vulnerability assessment and penetration testing techniques. Journal of Computer Virology and Hacking Techniques","author":"Shah Sugandh","year":"2015","unstructured":"Sugandh Shah and Babu\u00a0M Mehtre. 2015. An overview of vulnerability assessment and penetration testing techniques. Journal of Computer Virology and Hacking Techniques (2015)."},{"key":"e_1_3_2_1_36_1","volume-title":"Analyzing the accuracy and time costs of web application security scanners","author":"Suto Larry","year":"2010","unstructured":"Larry Suto. 2010. Analyzing the accuracy and time costs of web application security scanners. San Francisco, February (2010)."},{"key":"e_1_3_2_1_37_1","volume-title":"Intelligent Technologies for Information Analysis","author":"Tan Pang-Ning","unstructured":"Pang-Ning Tan and Vipin Kumar. 2004. Discovery of web robot sessions based on their navigational patterns. In Intelligent Technologies for Information Analysis. Springer."},{"key":"e_1_3_2_1_38_1","unstructured":"UnitedAirlines. 2022. United Airlines bug bounty program. https:\/\/www.united.com\/ual\/en\/us\/fly\/contact\/vdppolicy.html."},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660279"},{"key":"e_1_3_2_1_40_1","volume-title":"2014 6th International Conference On Cyber Conflict (CyCon","author":"Virvilis Nikos","year":"2021","unstructured":"Nikos Virvilis, Bart Vanautgaerden, and Oscar\u00a0Serrano Serrano. 2021. Changing the game: The art of deceiving sophisticated attackers. In 2014 6th International Conference On Cyber Conflict (CyCon 2014). IEEE."},{"key":"e_1_3_2_1_41_1","unstructured":"w3techs 2022. Usage statistics and market share of Joomla. https:\/\/w3techs.com\/technologies\/details\/cm-joomla."},{"key":"e_1_3_2_1_42_1","unstructured":"w3techs 2022. Usage statistics and market share of WordPress. https:\/\/w3techs.com\/technologies\/details\/cm-wordpress."},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/2590296.2590297"},{"key":"e_1_3_2_1_44_1","unstructured":"Ting-Fang Yen Yinglian Xie Fang Yu Roger\u00a0Peng Yu and Martin Abadi. 2012. Host Fingerprinting and Tracking on the Web: Privacy and Security Implications.. In NDSS."}],"event":{"name":"WWW '23: The ACM Web Conference 2023","location":"Austin TX USA","acronym":"WWW '23","sponsor":["SIGWEB ACM Special Interest Group on Hypertext, Hypermedia, and Web"]},"container-title":["Proceedings of the ACM Web Conference 2023"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3543507.3583394","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/abs\/10.1145\/3543507.3583394","content-type":"text\/html","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3543507.3583394","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3543507.3583394","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T16:47:51Z","timestamp":1750178871000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3543507.3583394"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,4,30]]},"references-count":44,"alternative-id":["10.1145\/3543507.3583394","10.1145\/3543507"],"URL":"https:\/\/doi.org\/10.1145\/3543507.3583394","relation":{},"subject":[],"published":{"date-parts":[[2023,4,30]]},"assertion":[{"value":"2023-04-30","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}