| 2016 | SP | SOK: (State of) The Art of War: Offensive Techniques in Binary Analysis. | Yan Shoshitaishvili, Ruoyu Wang, Christopher Salls, Nick Stephens, Mario Polino, Andrew Dutcher, John Grosen, Siji Feng, Christophe Hauser, Christopher Krgel, Giovanni Vigna |
| 2014 | RAID | Protecting Web-Based Single Sign-on Protocols against Relying Party Impersonation Attacks through a Dedicated Bi-directional Authenticated Secure Channel. | Yinzhi Cao, Yan Shoshitaishvili, Kevin Borgolte, Christopher Krgel, Giovanni Vigna, Yan Chen |
| 2014 | RAID | Eyes of a Human, Eyes of a Program: Leveraging Different Views of the Web for Analysis and Detection. | Jacopo Corbetta, Luca Invernizzi, Christopher Krgel, Giovanni Vigna |
| 2013 | NDSS | COMPA: Detecting Compromised Accounts on Social Networks. | Manuel Egele, Gianluca Stringhini, Christopher Krgel, Giovanni Vigna |
| 2013 | NDSS | Clickonomics: Determining the Effect of Anti-Piracy Measures for One-Click Hosting. | Tobias Lauinger, Martin Szydlowski, Kaan Onarlioglu, Gilbert Wondracek, Engin Kirda, Christopher Krgel |
| 2010 | WWW | Detection and analysis of drive-by-download attacks and malicious JavaScript code. | Marco Cova, Christopher Krgel, Giovanni Vigna |
| 2009 | NDSS | Scalable, Behavior-Based Malware Clustering. | Ulrich Bayer, Paolo Milani Comparetti, Clemens Hlauschek, Christopher Krgel, Engin Kirda |
| 2009 | RAID | Protecting a Moving Target: Addressing Web Application Concept Drift. | Federico Maggi, William K. Robertson, Christopher Krgel, Giovanni Vigna |
| 2009 | SP | Prospex: Protocol Specification Extraction. | Paolo Milani Comparetti, Gilbert Wondracek, Christopher Krgel, Engin Kirda |
| 2008 | NDSS | Automatic Network Protocol Analysis. | Gilbert Wondracek, Paolo Milani Comparetti, Christopher Krgel, Engin Kirda |
| 2007 | NDSS | Cross Site Scripting Prevention with Dynamic Data Tainting and Static Analysis. | Philipp Vogt, Florian Nentwich, Nenad Jovanovic, Engin Kirda, Christopher Krgel, Giovanni Vigna |
| 2007 | SP | Exploring Multiple Execution Paths for Malware Analysis. | Andreas Moser, Christopher Krgel, Engin Kirda |
| 2006 | DIMVA | Using Static Program Analysis to Aid Intrusion Detection. | Manuel Egele, Martin Szydlowski, Engin Kirda, Christopher Krgel |
| 2006 | NDSS | Using Generalization and Characterization Techniques in the Anomaly-based Detection of Web Attacks. | William K. Robertson, Giovanni Vigna, Christopher Krgel, Richard A. Kemmerer |
| 2006 | WWW | SecuBat: a web vulnerability scanner. | Stefan Kals, Engin Kirda, Christopher Krgel, Nenad Jovanovic |
| 2006 | SAC | Noxes: a client-side solution for mitigating cross-site scripting attacks. | Engin Kirda, Christopher Krgel, Giovanni Vigna, Nenad Jovanovic |
| 2006 | SAC | An anomaly-driven reverse proxy for web applications. | Fredrik Valeur, Giovanni Vigna, Christopher Krgel, Engin Kirda |
| 2006 | SP | Pixy: A Static Analysis Tool for Detecting Web Application Vulnerabilities (Short Paper). | Nenad Jovanovic, Christopher Krgel, Engin Kirda |
| 2005 | COMPSAC | Protecting Users Against Phishing Attacks with AntiPhish. | Engin Kirda, Christopher Krgel |
| 2005 | RAID | Polymorphic Worm Detection Using Structural Information of Executables. | Christopher Krgel, Engin Kirda, Darren Mutz, William K. Robertson, Giovanni Vigna |
| 2004 | ACSAC | Detecting Kernel-Level Rootkits Through Binary Analysis. | Christopher Krgel, William K. Robertson, Giovanni Vigna |
| 2004 | DIMVA | Alert Verification Determining the Success of Intrusion Attempts. | Christopher Krgel, William K. Robertson |
| 2003 | ACSAC | Bayesian Event Classification for Intrusion Detection. | Christopher Krgel, Darren Mutz, William K. Robertson, Fredrik Valeur |
| 2003 | CCS | Anomaly detection of web-based attacks. | Christopher Krgel, Giovanni Vigna |
| 2003 | ESORICS | On the Detection of Anomalous System Call Arguments. | Christopher Krgel, Darren Mutz, Fredrik Valeur, Giovanni Vigna |
| 2003 | RAID | Topology-Based Detection of Anomalous BGP Messages. | Christopher Krgel, Darren Mutz, William K. Robertson, Fredrik Valeur |
| 2003 | RAID | Using Decision Trees to Improve Signature-Based Intrusion Detection. | Christopher Krgel, Thomas Toth |
| 2002 | ACSAC | Evaluating the Impact of Automated Intrusion Response Mechanisms. | Thomas Toth, Christopher Krgel |
| 2002 | NDSS | Distributed Pattern Detection for Intrusion Detection. | Christopher Krgel, Thomas Toth |
| 2002 | Networking | XGuide - A Practical Guide to XML-Based Web Engineering. | Clemens Kerer, Engin Kirda, Christopher Krgel |
| 2002 | RAID | Accurate Buffer Overflow Detection via Abstract Payload Execution. | Thomas Toth, Christopher Krgel |
| 2002 | SAC | Service specific anomaly detection for network intrusion detection. | Christopher Krgel, Thomas Toth, Engin Kirda |
| 2002 | SP | Stateful Intrusion Detection for High-Speed Networks. | Christopher Krgel, Fredrik Valeur, Giovanni Vigna, Richard A. Kemmerer |
| 2001 | ICISC | Decentralized Event Correlation for Intrusion Detection. | Christopher Krgel, Thomas Toth, Clemens Kerer |
| 2001 | WETICE | Supporting Multi-Device Enabled Web Services: Challenges and Open Problems. | Engin Kirda, Clemens Kerer, Mehdi Jazayeri, Christopher Krgel |