VulnEx: Exploring Open-Source Software Vulnerabilities in Large Development Organizations to Understand Risk Exposure
Frederik L. Dennig, Eren Cakmak, Henrik Plate, Daniel A. Keim

TL;DR
VulnEx is a tool designed to help large software organizations identify and assess vulnerabilities in open-source components, providing a comprehensive overview to improve security risk management.
Contribution
The paper introduces VulnEx, a novel tool with table-based representations for auditing OSS vulnerabilities across entire organizations, developed in collaboration with security analysts.
Findings
Effective identification of OSS vulnerabilities in large organizations
Useful visualizations for security analysts to assess risk exposure
Preliminary positive feedback from expert evaluations
Abstract
The prevalent usage of open-source software (OSS) has led to an increased interest in resolving potential third-party security risks by fixing common vulnerabilities and exposures (CVEs). However, even with automated code analysis tools in place, security analysts often lack the means to obtain an overview of vulnerable OSS reuse in large software organizations. In this design study, we propose VulnEx (Vulnerability Explorer), a tool to audit entire software development organizations. We introduce three complementary table-based representations to identify and assess vulnerability exposures due to OSS, which we designed in collaboration with security analysts. The presented tool allows examining problematic projects and applications (repositories), third-party libraries, and vulnerabilities across a software organization. We show the applicability of our tool through a use case and…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsSoftware Engineering Research · Information and Cyber Security · Software Reliability and Analysis Research
