Skip to main content
SHARE
Publication

Visual analysis of code security...

by John R Goodall, Hassan Radwan, Lenny Halseth
Publication Type
Conference Paper
Book Title
Proceedings of the Seventh International Symposium on Visualization for Cyber Security
Publication Date
Page Numbers
46 to 51
Volume
N/A
Publisher Location
New York, New Jersey, United States of America
Conference Name
International Symposium on Visualization for Cyber Security (VizSec)
Conference Location
Ottawa, Canada
Conference Date
-

To help increase the confidence that software is secure, researchers and vendors have developed different kinds of automated software security analysis tools. These tools analyze software for weaknesses and vulnerabilities, but the individual tools catch different vulnerabilities and produce voluminous data with many false positives. This paper describes a system that brings together the results of disparate software analysis tools into a visual environment to support the triage and exploration of code vulnerabilities. Our system allows software developers to explore vulnerability results to uncover hidden trends, triage the most important code weaknesses, and show who is responsible for introducing software vulnerabilities. By correlating and normalizing multiple software analysis tools' data, the overall vulnerability detection coverage of software is increased. A visual overview and powerful interaction allows the user to focus attention on the most pressing vulnerabilities within huge volumes of data, and streamlines the secure software development workflow through integration with development tools.