计算机科学
数据可视化
软件
可视化
人机交互
脆弱性(计算)
软件工程
操作系统
计算机安全
数据挖掘
作者
Steven Lamarr Reynolds,Tobias Mertz,Steven Arzt,Jörn Kohlhammer
标识
DOI:10.1109/vizsec53666.2021.00013
摘要
Today's software systems are created by software development processes that naturally include mistakes, some of which can be exploited by attackers and are therefore called vulnerabilities. Automatic software scanners enable developers to analyze their applications to detect vulnerabilities and alert them of their presence. But often these reports are hard to understand, include false positives or overwhelm users due to the sheer number of alerts, since a report may contain hundreds to thousands of vulnerabilities. Developers must undergo a process called vulnerability triage to find the relevant vulnerabilities to fix. This paper presents two interactive visualizations for developers and security experts to gain an overview of the security state of their application. Users can see the distribution of vulnerabilities, find the most relevant ones, and compare differences between application versions. Our visualization design is inspired by an initial preliminary study and has been evaluated by domain experts to investigate the usability and appropriateness.
科研通智能强力驱动
Strongly Powered by AbleSci AI