| 2024 | CCS | ReactAppScan: Mining React Application Vulnerabilities via Component Graph. | Zhiyong Guo, Mingqing Kang, V. N. Venkatakrishnan, Rigel Gjomemo, Yinzhi Cao |
| 2023 | SP | Scaling JavaScript Abstract Interpretation to Detect and Exploit Node.js Taint-style Vulnerability. | Mingqing Kang, Yichao Xu, Song Li, Rigel Gjomemo, Jianwei Hou, V. N. Venkatakrishnan, Yinzhi Cao |
| 2022 | ICISS | Ostinato: Cross-host Attack Correlation Through Attack Activity Similarity Detection. | Sutanu Kumar Ghosh, Kiavash Satvat, Rigel Gjomemo, V. N. Venkatakrishnan |
| 2019 | CCS | POIROT: Aligning Attack Behavior with Kernel Audit Records for Cyber Threat Hunting. | Sadegh M. Milajerdi, Birhanu Eshete, Rigel Gjomemo, V. N. Venkatakrishnan |
| 2019 | SP | HOLMES: Real-Time APT Detection through Correlation of Suspicious Information Flows. | Sadegh Momeni Milajerdi, Rigel Gjomemo, Birhanu Eshete, R. Sekar, V. N. Venkatakrishnan |
| 2017 | DSN | DynaMiner: Leveraging Offline Infection Analytics for On-the-Wire Malware Detection. | Birhanu Eshete, V. N. Venkatakrishnan |
| 2016 | CCS | Chainsaw: Chained Automated Workflow-based Exploit Generation. | Abeer Alhuzali, Birhanu Eshete, Rigel Gjomemo, V. N. Venkatakrishnan |
| 2016 | QRS | Leveraging Static Analysis Tools for Improving Usability of Memory Error Sanitization Compilers. | Rigel Gjomemo, Phu H. Phung, Edmund Ballou, Kedar S. Namjoshi, V. N. Venkatakrishnan, Lenore D. Zuck |
| 2015 | SP | Vetting SSL Usage in Applications with SSLINT. | Boyuan He, Vaibhav Rastogi, Yinzhi Cao, Yan Chen, V. N. Venkatakrishnan, Runqing Yang, Zhenrui Zhang |
| 2015 | VMCAI | From Verification to Optimizations. | Rigel Gjomemo, Kedar S. Namjoshi, Phu H. Phung, V. N. Venkatakrishnan, Lenore D. Zuck |
| 2014 | CCS | MACE: Detecting Privilege Escalation Vulnerabilities in Web Applications. | Maliheh Monshizadeh, Prasad Naldurg, V. N. Venkatakrishnan |
| 2014 | FC | Digital Check Forgery Attacks on Client Check Truncation Systems. | Rigel Gjomemo, Hafiz Malik, Nilesh Sumb, V. N. Venkatakrishnan, Rashid Ansari |
| 2013 | PLDI | WEBLOG: a declarative language for secure web development. | Timothy L. Hinrichs, Daniele Rossetti, Gabriele Petronella, V. N. Venkatakrishnan, A. Prasad Sistla, Lenore D. Zuck |
| 2011 | CCS | WAPTEC: whitebox analysis of web applications for parameter tampering exploit construction. | Prithvi Bisht, Timothy L. Hinrichs, Nazari Skrupsky, V. N. Venkatakrishnan |
| 2010 | CCS | NoTamper: automatic blackbox detection of parameter tampering opportunities in web applications. | Prithvi Bisht, Timothy L. Hinrichs, Nazari Skrupsky, Radoslaw Bobrowicz, V. N. Venkatakrishnan |
| 2010 | CCS | TAPS: automatically preparing safe SQL queries. | Prithvi Bisht, A. Prasad Sistla, V. N. Venkatakrishnan |
| 2010 | FC | Automatically Preparing Safe SQL Queries. | Prithvi Bisht, A. Prasad Sistla, V. N. Venkatakrishnan |
| 2010 | ICISS | WebAppArmor: A Framework for Robust Prevention of Attacks on Web Applications (Invited Paper). | V. N. Venkatakrishnan, Prithvi Bisht, Mike Ter Louw, Michelle Zhou, Kalpana Gondi, Karthik Thotta Ganesh |
| 2010 | ICISS | Strengthening XSRF Defenses for Legacy Web Applications Using Whitebox Analysis and Transformation. | Michelle Zhou, Prithvi Bisht, V. N. Venkatakrishnan |
| 2009 | SP | Blueprint: Robust Prevention of Cross-site Scripting Attacks for Existing Browsers. | Mike Ter Louw, V. N. Venkatakrishnan |
| 2008 | ACSAC | Preventing Information Leaks through Shadow Executions. | Roberto Capizzi, Antonio Longo, V. N. Venkatakrishnan, A. Prasad Sistla |
| 2008 | CCS | CMV: automatic verification of complete mediation for java virtual machines. | A. Prasad Sistla, V. N. Venkatakrishnan, Michelle Zhou, Hilary Branske |
| 2008 | DIMVA | XSS-GUARD: Precise Dynamic Prevention of Cross-Site Scripting Attacks. | Prithvi Bisht, V. N. Venkatakrishnan |
| 2008 | DIMVA | Expanding Malware Defense by Securing Software Installations. | Weiqing Sun, R. Sekar, Zhenkai Liang, V. N. Venkatakrishnan |
| 2007 | CCS | CANDID: preventing sql injection attacks using dynamic candidate evaluations. | Sruthi Bandhakavi, Prithvi Bisht, P. Madhusudan, V. N. Venkatakrishnan |
| 2007 | DIMVA | Extensible Web Browser Security. | Mike Ter Louw, Jin Soon Lim, V. N. Venkatakrishnan |
| 2006 | ACSAC | Data Sandboxing: A Technique for Enforcing Confidentiality Policies. | Tejas Khatiwala, Raj Swaminathan, V. N. Venkatakrishnan |
| 2006 | ICICS | Provably Correct Runtime Enforcement of Non-interference Properties. | V. N. Venkatakrishnan, Wei Xu, Daniel C. DuVarney, R. Sekar |
| 2006 | ICWS | A Framework for Building Privacy-Conscious Composite Web Services. | Wei Xu, V. N. Venkatakrishnan, R. Sekar, I. V. Ramakrishnan |
| 2005 | NDSS | One-Way Isolation: An Effective Approach for Realizing Safe Execution Environments. | Weiqing Sun, Zhenkai Liang, V. N. Venkatakrishnan, R. Sekar |
| 2005 | WWW | An approach for realizing privacy-preserving web-based services. | Wei Xu, R. Sekar, I. V. Ramakrishnan, V. N. Venkatakrishnan |
| 2003 | ACSAC | Isolated Program Execution: An Application Transparent Approach for Executing Untrusted Programs. | Zhenkai Liang, V. N. Venkatakrishnan, R. Sekar |
| 2003 | NSPW | SELF: a transparent security extension for ELF binaries. | Daniel C. DuVarney, V. N. Venkatakrishnan, Sandeep Bhatkar |
| 2003 | SOSP | Model-carrying code: a practical approach for safe execution of untrusted applications. | R. Sekar, V. N. Venkatakrishnan, Samik Basu, Sandeep Bhatkar, Daniel C. DuVarney |
| 2002 | NSPW | Empowering mobile code using expressive security policies. | V. N. Venkatakrishnan, Ram Peri, R. Sekar |
| 2000 | CAV | XMC: A Logic-Programming-Based Verification Toolset. | C. R. Ramakrishnan, I. V. Ramakrishnan, Scott A. Smolka, Yifei Dong, Xiaoqun Du, Abhik Roychoudhury, V. N. Venkatakrishnan |