TCSE logo 
 Sigsoft logo
Sustainability badge
Sat 3 May 2025 11:20 - 11:40 at 204 - Paper Session 1 Chair(s): Jinyang Li

Open-source software is widely used by developers and businesses, but assessing its security posture is challenging due to the lack of time and specialized expertise. Existing visual security analysis tools for open-source projects primarily focus on vulnerabilities within the source code, lacking a comprehensive assessment of the project’s overall security posture. To address these issues, we propose a multi-dimensional visual analytics tool for evaluating the security posture of open-source projects. Our tool integrates data from code commits, contributor activity, and historical vulnerability duration, providing a comprehensive view of project security.

Our tool integrates data from multiple sources, including the National Vulnerability Database (NVD) and GitHub commit histories, and applies the SZZ algorithm to identify both vulnerability-fixing and inducing commits. We tested the dashboard on two popular GitHub projects, each containing thousands of commits and hundreds of vulnerabilities, allowing users to easily track development and vulnerability management within each project. An evaluation study with experienced developers confirmed the dashboard’s effectiveness in helping users quickly understand developer interactions and the project’s overall approach to security management. Our contributions include a comprehensive vulnerability dataset and a visual dashboard that offers a multi-dimensional perspective on open-source project security, meeting the needs of various stakeholders.

Sat 3 May

Displayed time zone: Eastern Time (US & Canada) change

11:00 - 12:30
Paper Session 1SVM at 204
Chair(s): Jinyang Li The University of Adelaide
11:00
20m
Talk
A Landscape Study of Open-Source Tools for Software Bill of Materials (SBOM) for Supply Chain Security
SVM
Derek Garcia University of Hawaii at Manoa, Mehdi Mirakhorli University of Hawaii at Manoa, Schuyler Dillon Rochester Institute of Technology, Kevin Laporte Rochester Institute of Technology, Matthew Morrison Rochester Institute of Technology, Henry Lu Rochester Institute of Technology, Viktoria Koscinski Rochester Institute of Technology, Christopher Enoch Rochester Institute of Technology, Mohamad Fazelnia University of Hawaii at Manoa, Roger Chen University of Hawaii at Manoa
11:20
20m
Talk
A Multi-Dimensional Visual Analytics Tool for the Security Posture of Open-Source Software
SVM
Tianyu Li DistriNet Group-T, KU Leuven, Chaomeng Lu DistriNet Group-T, KU Leuven, Bert Lagaisse DistriNet Group-T, KU Leuven
11:40
50m
Meeting
Round-table discussion on “SVM in the era of (Gen)AI”
SVM

:
:
:
: