| 2017 | Ex-Ray: Detection of History-Leaking Browser Extensions. | Michael Weissbacher, Enrico Mariconti, Guillermo Suarez-Tangil, Gianluca Stringhini, William K. Robertson, Engin Kirda |
| 2017 | I Like It, but I Hate It: Employee Perceptions Towards an Institutional Transition to BYOD Second-Factor Authentication. | Jake Weidman, Jens Grossklags |
| 2017 | Droid-AntiRM: Taming Control Flow Anti-analysis to Support Automated Dynamic Analysis of Android Malware. | Xiaolei Wang, Sencun Zhu, Dehua Zhou, Yuexiang Yang |
| 2017 | TRAKS: A Universal Key Management Scheme for ERTMS. | Richard James Thomas, Mihai Ordean, Tom Chothia, Joeri de Ruiter |
| 2017 | Marmite: Spreading Malicious File Reputation Through Download Graphs. | Gianluca Stringhini, Yun Shen, Yufei Han, Xiangliang Zhang |
| 2017 | Spinner: Semi-Automatic Detection of Pinning without Hostname Verification. | Chris McMahon Stone, Tom Chothia, Flavio D. Garcia |
| 2017 | HoloPair: Securing Shared Augmented Reality Using Microsoft HoloLens. | Ivo Sluganovic, Matej Serbec, Ante Derek, Ivan Martinovic |
| 2017 | QUASAR: Quantitative Attack Space Analysis and Reasoning. | Richard Skowyra, Steven R. Gomez, David Bigelow, James Landry, Hamed Okhravi |
| 2017 | On the Pitfalls of End-to-End Encrypted Communications: A Study of Remote Key-Fingerprint Verification. | Maliheh Shirvanian, Nitesh Saxena, Jesvin James George |
| 2017 | Piston: Uncooperative Remote Runtime Patching. | Christopher Salls, Yan Shoshitaishvili, Nick Stephens, Christopher Kruegel, Giovanni Vigna |
| 2017 | Smoke Detector: Cross-Product Intrusion Detection With Weak Indicators. | Kevin A. Roundy, Acar Tamersoy, Michael Spertus, Michael Hart, Daniel Kats, Matteo Dell'Amico, Robert Scott |
| 2017 | Supplementing Modern Software Defenses with Stack-Pointer Sanity. | Anh Quach, Matthew Cole, Aravind Prakash |
| 2017 | Breaking and Fixing Destructive Code Read Defenses. | Jannik Pewny, Philipp Koppe, Lucas Davi, Thorsten Holz |
| 2017 | n-Auth: Mobile Authentication Done Right. | Roel Peeters, Jens Hermans, Pieter Maene, Katri Grenman, Kimmo Halunen, Juha Hiki |
| 2017 | Nioh: Hardening The Hypervisor by Filtering Illegal I/O Requests to Virtual Devices. | Junya Ogasawara, Kenji Kono |
| 2017 | Measuring Popularity of Cryptographic Libraries in Internet-Wide Scans. | Mats Nemec, Dusan Klinec, Petr Svenda, Peter Sekan, Vashek Matyas |
| 2017 | RESECT: Self-Learning Traffic Filters for IP Spoofing Defense. | Jelena Mirkovic, Erik Kline, Peter L. Reiher |
| 2017 | Here Is Your Fingerprint!: Actual Risk versus User Perception of Latent Fingerprints and Smudges Remaining on Smartphones. | Hoyeon Lee, Seungyeon Kim, Taekyoung Kwon |
| 2017 | RevARM: A Platform-Agnostic ARM Binary Rewriter for Security Applications. | Taegyu Kim, Chung Hwan Kim, Hongjun Choi, Yonghwi Kwon, Brendan Saltaformaggio, Xiangyu Zhang, Dongyan Xu |
| 2017 | Automated Analysis of Secure Internet of Things Protocols. | Jun Young Kim, Ralph Holz, Wen Hu, Sanjay Jha |
| 2017 | Protecting Against Malicious Bits On the Wire: Automatically Generating a USB Protocol Parser for a Production Kernel. | Peter C. Johnson, Sergey Bratus, Sean W. Smith |
| 2017 | Kakute: A Precise, Unified Information Flow Analysis System for Big-data Security. | Jianyu Jiang, Shixiong Zhao, Danish Alsayed, Yuexuan Wang, Heming Cui, Feng Liang, Zhaoquan Gu |
| 2017 | Objective Metrics and Gradient Descent Algorithms for Adversarial Examples in Machine Learning. | Uyeong Jang, Xi Wu, Somesh Jha |
| 2017 | TTPDrill: Automatic and Accurate Extraction of Threat Actions from Unstructured Text of CTI Sources. | Ghaith Husari, Ehab Al-Shaer, Mohiuddin Ahmed, Bill Chu, Xi Niu |
| 2017 | Supporting Transparent Snapshot for Bare-metal Malware Analysis on Mobile Devices. | Le Guan, Shijie Jia, Bo Chen, Fengwei Zhang, Bo Luo, Jingqiang Lin, Peng Liu, Xinyu Xing, Luning Xia |