• English
  • Deutsch
  • Log In
    or
  • Research Outputs
  • Projects
  • Researchers
  • Institutes
  • Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Konferenzschrift
  4. User-Centered Design of Visualizations for Software Vulnerability Reports
 
  • Details
  • Full
Options
2021
Konferenzbeitrag
Titel

User-Centered Design of Visualizations for Software Vulnerability Reports

Abstract
Today's software systems are created by software development processes that naturally include mistakes, some of which can be exploited by attackers and are therefore called vulnerabilities. Automatic software scanners enable developers to analyze their applications to detect vulnerabilities and alert them of their presence. But often these reports are hard to understand, include false positives or overwhelm users due to the sheer number of alerts, since a report may contain hundreds to thousands of vulnerabilities. Developers must undergo a process called vulnerability triage to find the relevant vulnerabilities to fix. This paper presents two interactive visualizations for developers and security experts to gain an overview of the security state of their application. Users can see the distribution of vulnerabilities, find the most relevant ones, and compare differences between application versions. Our visualization design is inspired by an initial preliminary study and has been evaluated by domain experts to investigate the usability and appropriateness.
Author(s)
Reynolds, Steven Lamarr
Fraunhofer-Institut für Graphische Datenverarbeitung IGD
Mertz, Tobias
Fraunhofer-Institut für Graphische Datenverarbeitung IGD
Arzt, Steven
Fraunhofer-Institut für Sichere Informationstechnologie SIT
Kohlhammer, Jörn
Fraunhofer-Institut für Graphische Datenverarbeitung IGD
Hauptwerk
IEEE Symposium on Visualization for Cyber Security, VizSec 2021. Proceedings
Project(s)
ATHENE
Funder
Bundesministerium für Bildung und Forschung BMBF (Deutschland)
Konferenz
Symposium on Visualization for Cyber Security (VizSec) 2021
Thumbnail Image
DOI
10.1109/VizSec53666.2021.00013
Language
Englisch
google-scholar
IGD
SIT
Tags
  • Lead Topic: Visual Co...

  • Research Line: Comput...

  • Research Line: Human ...

  • cyber security

  • data visualization

  • interactive visualiza...

  • usability evaluation

  • CRISP

  • ATHENE

  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Send Feedback
© 2022