| 2025 | ESORICS | Formal Security Analysis of ss2DNS. | Ali Sadeghi Jahromi, AbdelRahman Abdou, Paul C. van Oorschot |
| 2024 | FC | Owl: An Augmented Password-Authenticated Key Exchange Scheme. | Feng Hao, Samiran Bag, Liqun Chen, Paul C. van Oorschot |
| 2022 | AsiaCCS | SoK: Password-Authenticated Key Exchange - Theory, Practice, Standardization and Real-World Lessons. | Feng Hao, Paul C. van Oorschot |
| 2021 | FC | SoK: Securing Email - A Stakeholder-Based Analysis. | Jeremy Clark, Paul C. van Oorschot, Scott Ruoti, Kent E. Seamons, Daniel Zappala |
| 2020 | ACSAC | CAPS: Smoothly Transitioning to a More Resilient Web PKI. | Stephanos Matsumoto, Jay Bosamiya, Yucheng Dai, Paul C. van Oorschot, Bryan Parno |
| 2019 | PST | Analysis, Implications, and Challenges of an Evolving Consumer IoT Security Landscape. | Christopher Bellman, Paul C. van Oorschot |
| 2019 | PST | Onboarding and Software Update Architecture for IoT Devices. | Hemant Gupta, Paul C. van Oorschot |
| 2018 | CCS | A Discussion on Security Education in Academia. | Kevin R. B. Butler, Robert K. Cunningham, Paul C. van Oorschot, Reihaneh Safavi-Naini, Ashraf Matrawy, Jeremy Clark |
| 2017 | CCS | Accurate Manipulation of Delay-based Internet Geolocation. | AbdelRahman Abdou, Ashraf Matrawy, Paul C. van Oorschot |
| 2017 | CCS | Science, Security and Academic Literature: Can We Learn from History? | Paul C. van Oorschot |
| 2017 | SP | SoK: Science, Security and the Elusive Goal of Security as a Scientific Pursuit. | Cormac Herley, Paul C. van Oorschot |
| 2016 | ACSAC | Device fingerprinting for augmenting web authentication: classification and analysis of methods. | Furkan Alaca, Paul C. van Oorschot |
| 2014 | CCS | A three-way investigation of a game-CAPTCHA: automated attacks, relay attacks and usability. | Manar Mohamed, Niharika Sachdeva, Michael Georgescu, Song Gao, Nitesh Saxena, Chengcui Zhang, Ponnurangam Kumaraguru, Paul C. van Oorschot, Wei-bang Chen |
| 2013 | CCS | Deadbolt: locking down android disk encryption. | Adam Skillen, David Barrera, Paul C. van Oorschot |
| 2013 | NSPW | Markets for zero-day exploits: ethics and implications. | Serge Egelman, Cormac Herley, Paul C. van Oorschot |
| 2013 | SP | SoK: SSL and HTTPS: Revisiting Past Challenges and Evaluating Certificate Trust Model Enhancements. | Jeremy Clark, Paul C. van Oorschot |
| 2012 | ACSAC | Tapas: design, implementation, and usability evaluation of a password manager. | Daniel McCarney, David Barrera, Jeremy Clark, Sonia Chiasson, Paul C. van Oorschot |
| 2012 | CCS | Understanding and improving app installation security mechanisms through empirical analysis of android. | David Barrera, Jeremy Clark, Daniel McCarney, Paul C. van Oorschot |
| 2012 | SP | The Quest to Replace Passwords: A Framework for Comparative Evaluation of Web Authentication Schemes. | Joseph Bonneau, Cormac Herley, Paul C. van Oorschot, Frank Stajano |
| 2011 | CCS | Network scan detection with LQS: a lightweight, quick and stateful algorithm. | Mansour Alsaleh, Paul C. van Oorschot |
| 2011 | FC | Exploration and Field Study of a Password Manager Using Icon-Based Passwords. | Kemal Bicakci, Nart Bedin Atalay, Mustafa Yuceel, Paul C. van Oorschot |
| 2011 | FC | Mercury: Recovering Forgotten Passwords Using Personal Devices. | Mohammad Mannan, David Barrera, Carson D. Brown, David Lie, Paul C. van Oorschot |
| 2011 | NSPW | A multi-word password proposal (gridWord) and exploring questions about science in security research and usable security evaluation. | Kemal Bicakci, Paul C. van Oorschot |
| 2010 | ACSAC | Exploring usability effects of increasing security in click-based graphical passwords. | Elizabeth Stobert, Alain Forget, Sonia Chiasson, Paul C. van Oorschot, Robert Biddle |
| 2010 | CCS | A methodology for empirical analysis of permission-based security models and its application to android. | David Barrera, Hilmi Gnes Kayacik, Paul C. van Oorschot, Anil Somayaji |
| 2010 | CCS | System security, platform security and usability. | Paul C. van Oorschot |
| 2010 | CCS | A control point for reducing root abuse of file-system privileges. | Glenn Wurster, Paul C. van Oorschot |
| 2009 | CCS | Browser interfaces and extended validation SSL certificates: an empirical study. | Robert Biddle, Paul C. van Oorschot, Andrew S. Patrick, Jennifer Sobey, Tara Whalen |
| 2009 | CCS | Multiple password interference in text passwords and click-based graphical passwords. | Sonia Chiasson, Alain Forget, Elizabeth Stobert, Paul C. van Oorschot, Robert Biddle |
| 2009 | FC | Passwords: If We're So Smart, Why Are We Still Using Them? | Cormac Herley, Paul C. van Oorschot, Andrew S. Patrick |
| 2009 | VizSec | Security visualization tools and IPv6 addresses. | David Barrera, Paul C. van Oorschot |
| 2008 | ACSAC | Improving Security Visualization with Exposure Map Filtering. | Mansour Alsaleh, David Barrera, Paul C. van Oorschot |
| 2008 | ACSAC | On Purely Automated Attacks and Click-Based Graphical Passwords. | Amirali Salehi-Abari, Julie Thorpe, Paul C. van Oorschot |
| 2008 | CCS | SOMA: mutual approval for included content in web pages. | Terri Oda, Glenn Wurster, Paul C. van Oorschot, Anil Somayaji |
| 2008 | ESORICS | CROO: A Universal Infrastructure and Protocol to Detect Identity Fraud. | Deholo Nali, Paul C. van Oorschot |
| 2008 | ESORICS | Exploring User Reactions to New Browser Cues for Extended Validation Certificates. | Jennifer Sobey, Robert Biddle, Paul C. van Oorschot, Andrew S. Patrick |
| 2008 | FC | Weighing Down "The Unbearable Lightness of PIN Cracking". | Mohammad Mannan, Paul C. van Oorschot |
| 2008 | NSDI | Centered Discretization with Application to Graphical Passwords. | Sonia Chiasson, Jayakumar Srinivasan, Robert Biddle, Paul C. van Oorschot |
| 2008 | NSPW | Localization of credential information to address increasingly inevitable data breaches. | Mohammad Mannan, Paul C. van Oorschot |
| 2008 | NSPW | The developer is the enemy. | Glenn Wurster, Paul C. van Oorschot |
| 2008 | Persuasive | Persuasion for Stronger Passwords: Motivation and Pilot Study. | Alain Forget, Sonia Chiasson, Paul C. van Oorschot, Robert Biddle |
| 2008 | WWW | Privacy-enhanced sharing of personal content on the web. | Mohammad Mannan, Paul C. van Oorschot |
| 2008 | SOUPS | Improving text passwords through persuasion. | Alain Forget, Sonia Chiasson, Paul C. van Oorschot, Robert Biddle |
| 2007 | ACSAC | Tracking Darkports for Network Defense. | David Whyte, Paul C. van Oorschot, Evangelos Kranakis |
| 2007 | ESORICS | Graphical Password Authentication Using Cued Click Points. | Sonia Chiasson, Paul C. van Oorschot, Robert Biddle |
| 2007 | FC | Using a Personal Device to Strengthen Password Authentication from an Untrusted Computer. | Mohammad Mannan, Paul C. van Oorschot |
| 2007 | NSPW | Security and usability: the gap in real-world online banking. | Mohammad Mannan, Paul C. van Oorschot |
| 2007 | NSPW | VideoTicket: detecting identity fraud attempts via audiovisual certificates and signatures. | Deholo Nali, Paul C. van Oorschot, Andy Adler |
| 2007 | SOUPS | A second look at the usability of click-based graphical passwords. | Sonia Chiasson, Robert Biddle, Paul C. van Oorschot |
| 2007 | SOUPS | Usability of anonymous web browsing: an examination of Tor interfaces and deployability. | Jeremy Clark, Paul C. van Oorschot, Carlisle Adams |
| 2006 | ACSAC | Addressing SMTP-Based Mass-Mailing Activity within Enterprise Networks. | David Whyte, Paul C. van Oorschot, Evangelos Kranakis |
| 2006 | FC | A Protocol for Secure Public Instant Messaging. | Mohammad Mannan, Paul C. van Oorschot |
| 2005 | ACNS | Mitigating Network Denial-of-Service Through Diversity-Based Traffic Management. | Ashraf Matrawy, Paul C. van Oorschot, Anil Somayaji |
| 2005 | ACSAC | Highlights from the 2005 New Security Paradigms Workshop. | Simon N. Foley, Abe Singer, Michael E. Locasto, Stelios Sidiroglou, Angelos D. Keromytis, John P. McDermott, Julie Thorpe, Paul C. van Oorschot, Anil Somayaji, Richard Ford, Mark Bush, Alex Boulatov |
| 2005 | ACSAC | Detecting Intra-enterprise Scanning Worms based on Address Resolution. | David Whyte, Paul C. van Oorschot, Evangelos Kranakis |
| 2005 | FC | Countering Identity Theft Through Digital Uniqueness, Location Cross-Checking, and Funneling. | Paul C. van Oorschot, Stuart G. Stubblebine |
| 2005 | NDSS | Pretty Secure BGP, psBGP. | Tao Wan, Evangelos Kranakis, Paul C. van Oorschot |
| 2005 | NDSS | DNS-based Detection of Scanning Worms in an Enterprise Network. | David Whyte, Evangelos Kranakis, Paul C. van Oorschot |
| 2005 | NSPW | Message authentication by integrity with public corroboration. | Paul C. van Oorschot |
| 2005 | NSPW | Pass-thoughts: authenticating with our minds. | Julie Thorpe, Paul C. van Oorschot, Anil Somayaji |
| 2005 | SP | A Generic Attack on Checksumming-Based Software Tamper Resistance. | Glenn Wurster, Paul C. van Oorschot, Anil Somayaji |
| 2004 | ACNS | S-RIP: A Secure Distance Vector Routing Protocol. | Tao Wan, Evangelos Kranakis, Paul C. van Oorschot |
| 2004 | ACSAC | Towards Secure Design Choices for Implementing Graphical Passwords. | Julie Thorpe, Paul C. van Oorschot |
| 2004 | FC | Addressing Online Dictionary Attacks with Login Histories and Humans-in-the-Loop (Extended Abstract). | Stuart G. Stubblebine, Paul C. van Oorschot |
| 2004 | ICICS | Securing the Destination-Sequenced Distance Vector Routing Protocol (S-DSDV). | Tao Wan, Evangelos Kranakis, Paul C. van Oorschot |
| 2004 | PST | Secure Public Instant Messaging. | Mohammad Mannan, Paul C. van Oorschot |
| 2002 | CCS | A White-Box DES Implementation for DRM Applications. | Stanley Chow, Philip A. Eisen, Harold Johnson, Paul C. van Oorschot |
| 1999 | NDSS | Addressing the Problem of Undetected Signature Key Compromise. | Mike Just, Paul C. van Oorschot |
| 1996 | CRYPTO | Improving Implementable Meet-in-the-Middle Attacks by Orders of Magnitude. | Paul C. van Oorschot, Michael J. Wiener |
| 1996 | EuroCrypt | On Diffie-Hellman Key Agreement with Short Exponents. | Paul C. van Oorschot, Michael J. Wiener |
| 1996 | EuroCrypt | On the Security of Two MAC Algorithms. | Bart Preneel, Paul C. van Oorschot |
| 1995 | CRYPTO | MDx-MAC and Building Fast MACs from Hash Functions. | Bart Preneel, Paul C. van Oorschot |
| 1994 | CCS | On Key Distribution via True Broadcasting. | Mike Just, Evangelos Kranakis, Danny Krizanc, Paul C. van Oorschot |
| 1994 | CCS | Parallel Collision Search with Application to Hash Functions and Discrete Logarithms. | Paul C. van Oorschot, Michael J. Wiener |
| 1994 | SP | On unifying some cryptographic protocol logics. | Paul F. Syverson, Paul C. van Oorschot |
| 1993 | CCS | Extending Cryptographic Logics of Belief to Key Agreement Protocols. | Paul C. van Oorschot |
| 1993 | EuroCrypt | An Alternate Explanation of two BAN-logic "failures". | Paul C. van Oorschot |
| 1990 | CRYPTO | A Comparison of Practical Public Key Cryptosystems Based on Integer Factorization and Discrete Logarithms. | Paul C. van Oorschot |
| 1990 | EuroCrypt | A Known Plaintext Attack on Two-Key Triple Encryption. | Paul C. van Oorschot, Michael J. Wiener |
| 1988 | ISSAC | Some Computational Aspects of Root Finding in GF(q | Alfred Menezes, Paul C. van Oorschot, Scott A. Vanstone |