| 2016 | ICST | Pseudo-Exhaustive Testing of Attribute Based Access Control Rules. | D. Richard Kuhn, Vincent C. Hu, David F. Ferraiolo, Raghu N. Kacker, Yu Lei |
| 2015 | IRI | Implementing and Managing Policy Rules in Attribute Based Access Control. | Vincent C. Hu, David F. Ferraiolo, D. Richard Kuhn, Raghu N. Kacker, Yu Lei |
| 2014 | IRI | On the unification of access control and data services. | David F. Ferraiolo, Serban I. Gavrila, Wayne A. Jansen |
| 2008 | SACMAT | A meta model for access control: why is it needed and is it even possible to achieve? | David F. Ferraiolo, Vijay Atluri |
| 2007 | CCGRID | Access Control Policy Combinations for the Grid Using the Policy Machine. | Vincent C. Hu, David F. Ferraiolo, Karen Scarfone |
| 2005 | SACMAT | Composing and combining policies under the policy machine. | David F. Ferraiolo, Serban I. Gavrila, Vincent C. Hu, D. Richard Kuhn |
| 2003 | SACMAT | The role control center: features and case studies. | David F. Ferraiolo, Ramaswamy Chandramouli, Gail-Joon Ahn, Serban I. Gavrila |
| 2001 | ICCS | The Policy Machine for Security Policy Management. | Vincent C. Hu, Deborah A. Frincke, David F. Ferraiolo |
| 2001 | SACMAT | An argument for the role-based access control model. | David F. Ferraiolo |
| 2001 | SACMAT | Panel: which access control technique will provide the greatest overall benefit-Abstract. | Timothy Fraser, David F. Ferraiolo, Mikel L. Matthews, Casey Schaufler, Stephen Smalley, Robert Watson |
| 2000 | ACSAC | Policy Mediation for Multi-Enterprise Environments. | Pablo Galiasso, Oliver Bremer, John Hale, Sujeet Shenoi, David F. Ferraiolo, Vincent C. Hu |
| 1998 | SP | On the Formal Definition of Separation-of-Duty Policies and their Composition. | Virgil D. Gligor, Serban I. Gavrila, David F. Ferraiolo |