{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,17]],"date-time":"2026-07-17T14:58:39Z","timestamp":1784300319322,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":48,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,5,13]],"date-time":"2024-05-13T00:00:00Z","timestamp":1715558400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"The Shanghai Pilot Program for Basic Research-Fudan University","award":["21TQ1400100 (21TQ012)"],"award-info":[{"award-number":["21TQ1400100 (21TQ012)"]}]},{"name":"The Funding of Ministry of Industry and Information Technology of the People's Republic of China","award":["TC220H079"],"award-info":[{"award-number":["TC220H079"]}]},{"name":"The National Key Research and Development Program","award":["2021YFB3101200"],"award-info":[{"award-number":["2021YFB3101200"]}]},{"DOI":"10.13039\/501100006374","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62172105,62172104,62102091,62102093"],"award-info":[{"award-number":["62172105,62172104,62102091,62102093"]}],"id":[{"id":"10.13039\/501100006374","id-type":"DOI","asserted-by":"publisher"}]},{"name":"The Shanghai Rising-Star Program","award":["210A1400700"],"award-info":[{"award-number":["210A1400700"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,5,13]]},"DOI":"10.1145\/3589334.3645530","type":"proceedings-article","created":{"date-parts":[[2024,5,8]],"date-time":"2024-05-08T07:08:13Z","timestamp":1715152093000},"page":"1746-1755","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":8,"title":["RecurScan: Detecting Recurring Vulnerabilities in PHP Web Applications"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0004-0763-4732","authenticated-orcid":false,"given":"Youkun","family":"Shi","sequence":"first","affiliation":[{"name":"Fudan University, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0726-9996","authenticated-orcid":false,"given":"Yuan","family":"Zhang","sequence":"additional","affiliation":[{"name":"Fudan University, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-3761-784X","authenticated-orcid":false,"given":"Tianhao","family":"Bai","sequence":"additional","affiliation":[{"name":"Fudan University, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-3295-1991","authenticated-orcid":false,"given":"Lei","family":"Zhang","sequence":"additional","affiliation":[{"name":"Fudan University, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-9018-0386","authenticated-orcid":false,"given":"Xin","family":"Tan","sequence":"additional","affiliation":[{"name":"Fudan University, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9714-5545","authenticated-orcid":false,"given":"Min","family":"Yang","sequence":"additional","affiliation":[{"name":"Fudan University, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,5,13]]},"reference":[{"key":"e_1_3_2_2_1_1","unstructured":"2014. The Practical-guide-to-code-clones. https:\/\/www.cqse.eu\/en\/news\/blog\/practical-guide-to-code-clones-part1\/."},{"key":"e_1_3_2_2_2_1","volume-title":"Cybercrime To Cost The World $10.5 Trillion Annually By","year":"2025","unstructured":"2021. Cybercrime To Cost The World $10.5 Trillion Annually By 2025. https:\/\/cybersecurityventures.com\/cybercrime-damages-6-trillion-by-2021."},{"key":"e_1_3_2_2_3_1","unstructured":"2021. Cybersecurity: A Global Priority and Career Opportunity. https:\/\/ung.edu\/continuing-education\/news-and-media\/cybersecurity.php."},{"key":"e_1_3_2_2_4_1","unstructured":"2023. Companies Using PHP by Domain. https:\/\/www.softkraft.co\/companiesusing-php."},{"key":"e_1_3_2_2_5_1","unstructured":"2023. Facebook. https:\/\/www.facebook.com."},{"key":"e_1_3_2_2_6_1","unstructured":"2023. HiddenCPG Source Code. https:\/\/github.com\/WSP-LAB\/HiddenCPG."},{"key":"e_1_3_2_2_7_1","unstructured":"2023. Spotify. https:\/\/open.spotify.com."},{"key":"e_1_3_2_2_8_1","unstructured":"2023. The Introduction of Jaro Distance Algorithm. https:\/\/www.rosettacode.org\/wiki\/Jaro_similarity."},{"key":"e_1_3_2_2_9_1","unstructured":"2023. The National Vulnerability Database. https:\/\/nvd.nist.gov\/."},{"key":"e_1_3_2_2_10_1","unstructured":"2023. The Official Website of Github. https:\/\/github.com\/."},{"key":"e_1_3_2_2_11_1","unstructured":"2023. The Official Website of Ne04j. https:\/\/neo4j.com\/."},{"key":"e_1_3_2_2_12_1","volume-title":"Efficient and Flexible Discovery of PHP Application Vulnerabilities. In 2017 IEEE european symposium on security and privacy (EuroS&P)","author":"Backes Michael","unstructured":"Michael Backes, Konrad Rieck, Malte Skoruppa, Ben Stock, and Fabian Yamaguchi. 2017. Efficient and Flexible Discovery of PHP Application Vulnerabilities. In 2017 IEEE european symposium on security and privacy (EuroS&P). IEEE, 334--349."},{"key":"e_1_3_2_2_13_1","volume-title":"Infer: An Automatic Program Verifier for Memory Safety of C Programs. In NASA Formal Methods Symposium. Springer, 459--465","author":"Calcagno Cristiano","year":"2011","unstructured":"Cristiano Calcagno and Dino Distefano. 2011. Infer: An Automatic Program Verifier for Memory Safety of C Programs. In NASA Formal Methods Symposium. Springer, 459--465."},{"key":"e_1_3_2_2_14_1","first-page":"23","article-title":"Simulation of Built-in PHP Features for Precise Static Code Analysis","volume":"14","author":"Dahse Johannes","year":"2014","unstructured":"Johannes Dahse and Thorsten Holz. 2014. Simulation of Built-in PHP Features for Precise Static Code Analysis.. In NDSS, Vol. 14. 23--26.","journal-title":"NDSS"},{"key":"e_1_3_2_2_15_1","volume-title":"Proceedings of the 23rd USENIX Security Symposium (USENIX Security). 989--1003","author":"Dahse Johannes","year":"2014","unstructured":"Johannes Dahse and Thorsten Holz. 2014. Static Detection of Second-order Vulnerabilities in Web Applications. In Proceedings of the 23rd USENIX Security Symposium (USENIX Security). 989--1003."},{"key":"e_1_3_2_2_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660363"},{"key":"e_1_3_2_2_17_1","volume-title":"Proceeding of the 21st USENIX Security Symposium (USENIX Security). 523--538","author":"Doup\u00e9 Adam","year":"2012","unstructured":"Adam Doup\u00e9, Ludovico Cavedon, Christopher Kruegel, and Giovanni Vigna. 2012. Enemy of the State: A State-Aware Black-Box Web Vulnerability Scanner. In Proceeding of the 21st USENIX Security Symposium (USENIX Security). 523--538."},{"key":"e_1_3_2_2_18_1","doi-asserted-by":"crossref","unstructured":"Kostas Drakonakis Sotiris Ioannidis and Jason Polakis. 2023. ReScan: A Middleware Framework for Realistic and Robust Black-box Web Application Scanning.. In NDSS.","DOI":"10.14722\/ndss.2023.24169"},{"key":"e_1_3_2_2_19_1","volume-title":"Black Widow: Blackbox Data-driven Web Scanning. In 2021 IEEE Symposium on Security and Privacy (SP). IEEE, 1125--1142","author":"Eriksson Benjamin","year":"2021","unstructured":"Benjamin Eriksson, Giancarlo Pellegrino, and Andrei Sabelfeld. 2021. Black Widow: Blackbox Data-driven Web Scanning. In 2021 IEEE Symposium on Security and Privacy (SP). IEEE, 1125--1142."},{"key":"e_1_3_2_2_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2012.13"},{"key":"e_1_3_2_2_21_1","volume-title":"Pixy: A Static Analysis Tool for Detecting Web Application Vulnerabilities. In 2006 IEEE Symposium on Security and Privacy (S&P'06)","author":"Jovanovic Nenad","year":"2006","unstructured":"Nenad Jovanovic, Christopher Kruegel, and Engin Kirda. 2006. Pixy: A Static Analysis Tool for Detecting Web Application Vulnerabilities. In 2006 IEEE Symposium on Security and Privacy (S&P'06). IEEE, 6--pp."},{"key":"e_1_3_2_2_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560664"},{"key":"e_1_3_2_2_23_1","volume-title":"Proceedings of the Genetic and Evolutionary Computation Conference","author":"Kim Jinhyun","year":"2016","unstructured":"Jinhyun Kim, HyukGeun Choi, Hansang Yun, and Byung-Ro Moon. 2016. Measuring Source Code Similarity by Finding Similar Subgraph with An Incremental Genetic Algorithm. In Proceedings of the Genetic and Evolutionary Computation Conference 2016. 925--932."},{"key":"e_1_3_2_2_24_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2018.02.007"},{"key":"e_1_3_2_2_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.62"},{"key":"e_1_3_2_2_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/3485447.3512234"},{"key":"e_1_3_2_2_27_1","volume-title":"CBCD: Cloned Buggy Code Detector. In 2012 34th International Conference on Software Engineering (ICSE). IEEE, 310--320","author":"Li Jingyue","year":"2012","unstructured":"Jingyue Li and Michael D Ernst. 2012. CBCD: Cloned Buggy Code Detector. In 2012 34th International Conference on Software Engineering (ICSE). IEEE, 310--320."},{"key":"e_1_3_2_2_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/3442381.3449826"},{"key":"e_1_3_2_2_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2006.28"},{"key":"e_1_3_2_2_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3559391"},{"key":"e_1_3_2_2_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660337"},{"key":"e_1_3_2_2_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/3338906.3338933"},{"key":"e_1_3_2_2_33_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3133959"},{"key":"e_1_3_2_2_34_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-26362-5_14"},{"key":"e_1_3_2_2_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/1858996.1859089"},{"key":"e_1_3_2_2_36_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2017.2676161"},{"key":"e_1_3_2_2_37_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-88418-5_8"},{"key":"e_1_3_2_2_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/2046707.2046776"},{"key":"e_1_3_2_2_39_1","unstructured":"Sooel Son Kathryn S McKinley and Vitaly Shmatikov. 2013. Fix Me Up: Repairing Access-Control Bugs in Web Applications. In NDSS. Citeseer."},{"key":"e_1_3_2_2_40_1","volume-title":"Proceedings of the 18th ISOC Network and Distributed System Security Symposium (NDSS).","author":"Sun Fangqi","year":"2011","unstructured":"Fangqi Sun, Liang Xu, and Zhendong Su. 2011. Static Detection of Access Control Vulnerabilities in Web Applications. In Proceedings of the 18th ISOC Network and Distributed System Security Symposium (NDSS)."},{"key":"e_1_3_2_2_41_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179317"},{"key":"e_1_3_2_2_42_1","volume-title":"Proceedings of the Conference of the Centre for Advanced Studies on Collaborative Research (CASCON). 13","author":"Vall\u00e9e-Rai Raja","year":"1999","unstructured":"Raja Vall\u00e9e-Rai, Phong Co, Etienne Gagnon, Laurie Hendren, Patrick Lam, and Vijay Sundaresan. 1999. Soot: A Java Bytecode Optimization Framework. In Proceedings of the Conference of the Centre for Advanced Studies on Collaborative Research (CASCON). 13."},{"key":"e_1_3_2_2_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/1250734.1250739"},{"key":"e_1_3_2_2_44_1","volume-title":"An Empirical Analysis of XSS Sanitization in Web Application Frameworks. In European Conference on Research in Computer Security (ESORICS).","author":"Weinberger Joel","year":"2011","unstructured":"Joel Weinberger, Prateek Saxena, Devdatta Akhawe, Matthew Finifter, Richard Shin, and Dawn Song. 2011. An Empirical Analysis of XSS Sanitization in Web Application Frameworks. In European Conference on Research in Computer Security (ESORICS)."},{"key":"e_1_3_2_2_45_1","doi-asserted-by":"publisher","DOI":"10.1145\/3485447.3512235"},{"key":"e_1_3_2_2_46_1","volume-title":"29th USENIX Security Symposium.","author":"Xiao Yang","year":"2020","unstructured":"Yang Xiao, Bihuan Chen, Chendong Yu, Zhengzi Xu, Zimu Yuan, Feng Li, Binghong Liu, Yang Liu, Wei Huo, Wei Zou, et al. 2020. MVP: Detecting Vulnerabilities using Patch-Enhanced Vulnerability Signatures. In 29th USENIX Security Symposium."},{"key":"e_1_3_2_2_47_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10703-013-0189-1"},{"key":"e_1_3_2_2_48_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2022.110139"}],"event":{"name":"WWW '24: The ACM Web Conference 2024","location":"Singapore Singapore","acronym":"WWW '24","sponsor":["SIGWEB ACM Special Interest Group on Hypertext, Hypermedia, and Web"]},"container-title":["Proceedings of the ACM Web Conference 2024"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3589334.3645530","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3589334.3645530","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T00:25:03Z","timestamp":1755822303000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3589334.3645530"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,5,13]]},"references-count":48,"alternative-id":["10.1145\/3589334.3645530","10.1145\/3589334"],"URL":"https:\/\/doi.org\/10.1145\/3589334.3645530","relation":{},"subject":[],"published":{"date-parts":[[2024,5,13]]},"assertion":[{"value":"2024-05-13","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}