Dear All,
we submitted the paper "VulnEx: Exploring Open-Source Software
Vulnerabilities in Large Development Organizations to Understand Risk
Exposure" to the IEEE Symposium on Visualization for Cyber Security (at
IEEE VIS 2021). We request to acknowledge SPARTA if the paper is accepted.
* Abstract: "The prevalent usage of open-source software (OSS) has led
to an increased interest in resolving potential third-party security
risks by fixing common vulnerabilities and exposures (CVEs).
However, even with automated code analysis tools in place, security
analysts often lack the means to obtain an overview of vulnerable
OSS reuse in large software organizations. In this design study, we
propose VulnEx (Vulnerability Explorer), a tool to audit entire
software development organizations. We introduce three complementary
table-based representations to identify and assess vulnerability
exposures due to OSS, which we designed in collaboration with
security analysts. The presented tool allows examining problematic
projects and applications (repositories), third-party libraries, and
vulnerabilities across a software organization. We show the
applicability of our tool through a use case and preliminary expert
feedback."
Best Regards,
Eren Cakmak
--
Research Associate
Department of Computer and Information Science
Data Analysis and Visualization Group
78457 Konstanz, Germany
Website:
http://infovis.uni.kn/~cakmak
Phone: +49 (0)7531 88 2507
Room: ZT1107