Publikationen

DaV3is: Data Flow-Based Vulnerability Verification Through Visualization

AutorMertz, Tobias; Reynolds-Ringer, Steven Lamarr; Kohlhammer, Jörn
Datum2026
ArtJournal Article
AbstraktVulnerability verification is an important process in ensuring the security of software systems. To support users in this process, we present the design study of DaV3is, which utilizes visual event sequence analysis techniques to enable the comparison and tracing of automatically detected data flows through the software's source code, thereby allowing users to take advantage of sequence similarities to reduce the verification workload. To that end, we characterize the domain problem based on input from domain users, describe our design rationale based on best-practices from the visual analytics literature, and evaluate individual design decisions, usability, and utility in studies with three stakeholder groups. The evaluations yielded overall positive responses, showing the suitability of our design and providing valuable insight for future research.
Urlhttps://publica.fraunhofer.de/handle/publica/512871