Visible to the public Towards Visual Analytics Dashboards for Provenance-driven Static Application Security Testing

TitleTowards Visual Analytics Dashboards for Provenance-driven Static Application Security Testing
Publication TypeConference Paper
Year of Publication2021
AuthorsSchreiber, Andreas, Sonnekalb, Tim, Kurnatowski, Lynn von
Conference Name2021 IEEE Symposium on Visualization for Cyber Security (VizSec)
Keywordsapplication security, codes, composability, Computer crime, Human Behavior, human-centered computing, Metrics, Provenance, pubcrawl, Resiliency, security, Security and Privacy, Software and Application Security, software security engineering, Testing, Tools, visual analytics, visualization, Visualization application domains
AbstractThe use of static code analysis tools for security audits can be time consuming, as the many existing tools focus on different aspects and therefore development teams often use several of these tools to keep code quality high and prevent security issues. Displaying the results of multiple tools, such as code smells and security warnings, in a unified interface can help developers get a better overview and prioritize upcoming work. We present visualizations and a dashboard that interactively display results from static code analysis for "interesting" commits during development. With this, we aim to provide an effective visual analytics tool for code security analysis results.
DOI10.1109/VizSec53666.2021.00010
Citation Keyschreiber_towards_2021