Dear All,
we submitted the paper "VulnEx: Exploring Open-Source Software
Vulnerabilities in Large Development Organizations to Understand
Risk Exposure" to the IEEE Symposium on Visualization for Cyber
Security (at IEEE VIS 2021). We request to acknowledge SPARTA if
the paper is accepted.
- Abstract: "The prevalent usage of open-source software (OSS)
has led to an increased interest in resolving potential
third-party security risks by fixing common vulnerabilities and
exposures (CVEs). However, even with automated code analysis
tools in place, security analysts often lack the means to obtain
an overview of vulnerable OSS reuse in large software
organizations. In this design study, we propose VulnEx
(Vulnerability Explorer), a tool to audit entire software
development organizations. We introduce three complementary
table-based representations to identify and assess vulnerability
exposures due to OSS, which we designed in collaboration with
security analysts. The presented tool allows examining
problematic projects and applications (repositories),
third-party libraries, and vulnerabilities across a software
organization. We show the applicability of our tool through a
use case and preliminary expert feedback."
Best Regards,
Eren Cakmak
--
Research Associate
Department of Computer and Information Science
Data Analysis and Visualization Group
78457 Konstanz, Germany
Website: http://infovis.uni.kn/~cakmak
Phone: +49 (0)7531 88 2507
Room: ZT1107