首页> 外文会议>IEEE Symposium on Visualization for Cyber Security >Cesar: Visual representation of source code vulnerabilities
【24h】

Cesar: Visual representation of source code vulnerabilities

机译:Cesar:可视化表示源代码漏洞

获取原文

摘要

Code analysis tools are not widely accepted by developers, and software vulnerabilities are detected by the thousands every year. We take a user-centered approach to that problem, starting with analyzing one of the popular open source static code analyzers, and uncover serious usability issues facing developers. We then design Cesar, a system offering developers a visual analysis environment to support their quest to rid their code of vulnerabilities. We present a prototype implementation of Cesar, and perform a usability analysis of the prototype and the visualizations it employs. Our analysis shows that the prototype is promising in promoting collaboration, exploration, and enabling developers to focus on the overall quality of their code as well as inspect individual vulnerabilities. We finally provide general recommendations to guide future designs of code review tools to enhance their usability.
机译:代码分析工具未被开发人员广泛接受,并且每年都有成千上万的软件漏洞被检测出来。我们以用户为中心的方法来解决该问题,首先分析一种流行的开源静态代码分析器,然后发现开发人员面临的严重可用性问题。然后,我们设计Cesar,该系统为开发人员提供了一个可视化分析环境,以支持他们摆脱漏洞代码的追求。我们介绍了Cesar的原型实现,并对原型及其采用的可视化进行可用性分析。我们的分析表明,该原型有望促进协作,探索,并使开发人员能够专注于其代码的整体质量以及检查单个漏洞。最后,我们提供一般建议,以指导代码审查工具的未来设计以增强其可用性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号