V-Achilles: An Interactive Visualization of Transitive Security Vulnerabilities

dc.contributor.authorJarukitpipat V.
dc.contributor.authorChhun K.
dc.contributor.authorWanprasert W.
dc.contributor.authorRagkhitwetsagul C.
dc.contributor.authorChoetkiertikul M.
dc.contributor.authorSunetnanta T.
dc.contributor.authorKula R.G.
dc.contributor.authorChinthanet B.
dc.contributor.authorIshio T.
dc.contributor.authorMatsumoto K.
dc.contributor.otherMahidol University
dc.date.accessioned2023-06-18T17:01:31Z
dc.date.available2023-06-18T17:01:31Z
dc.date.issued2022-09-19
dc.description.abstractA key threat to the usage of third-party dependencies has been the threat of security vulnerabilities, which risks unwanted access to a user application. As part of an ecosystem of dependencies, users of a library are prone to both the direct and transitive dependencies adopted into their applications. Recent work involves tool supports for vulnerable dependency updates, rarely showing the complexity of the transitive updates. In this paper, we introduce our solution to support vulnerability updating in npm. V-Achilles is a prototype that shows a visualization (i.e., using dependency graphs) affected by vulnerability attacks. In addition to the tool overview, we highlight three use cases to demonstrate the usefulness and application of our prototype with real-world npm packages. The prototype is available at https://github.com/MUICT-SERU/V-Achilles, with an accompanying video demonstration at https://www.youtube.com/watch?v=tspiZfhMNcs.
dc.identifier.citationACM International Conference Proceeding Series (2022)
dc.identifier.doi10.1145/3551349.3559526
dc.identifier.scopus2-s2.0-85146954197
dc.identifier.urihttps://repository.li.mahidol.ac.th/handle/20.500.14594/84255
dc.rights.holderSCOPUS
dc.subjectComputer Science
dc.titleV-Achilles: An Interactive Visualization of Transitive Security Vulnerabilities
dc.typeConference Paper
mu.datasource.scopushttps://www.scopus.com/inward/record.uri?partnerID=HzOxMe3b&scp=85146954197&origin=inward
oaire.citation.titleACM International Conference Proceeding Series
oairecerif.author.affiliationNara Institute of Science and Technology
oairecerif.author.affiliationMahidol University

Files

Collections