| 2014 | OSPF vulnerability to persistent poisoning attacks: a systematic analysis. | Gabi Nakibly, Adi Sosnovich, Eitan Menahem, Ariel Waizel, Yuval Elovici |
| 2014 | Using automatic speech recognition for attacking acoustic CAPTCHAs: the trade-off between usability and security. | Hendrik Meutzner, Viet-Hung Nguyen, Thorsten Holz, Dorothea Kolossa |
| 2014 | Centrality metrics of importance in access behaviors and malware detections. | Weixuan Mao, Zhongmin Cai, Xiaohong Guan, Don Towsley |
| 2014 | Scalability, fidelity and stealth in the DRAKVUF dynamic malware analysis system. | Tamas K. Lengyel, Steve Maresca, Bryan D. Payne, George D. Webster, Sebastian Vogl, Aggelos Kiayias |
| 2014 | CPS: driving cyber-physical systems to unsafe operating conditions by timing DoS attacks on sensor signals. | Marina Krotofil, Alvaro A. Crdenas, Bradley Manning, Jason Larsen |
| 2014 | Exploring and mitigating privacy threats of HTML5 geolocation API. | Hyungsub Kim, Sangho Lee, Jong Kim |
| 2014 | Morpheus: automatically generating heuristics to detect Android emulators. | Yiming Jing, Ziming Zhao, Gail-Joon Ahn, Hongxin Hu |
| 2014 | Less is more: cipher-suite negotiation for DNSSEC. | Amir Herzberg, Haya Schulmann, Bruno Crispo |
| 2014 | DNS authentication as a service: preventing amplification attacks. | Amir Herzberg, Haya Schulmann |
| 2014 | TroGuard: context-aware protection against web-based socially engineered trojans. | Rui Han, Alejandro Mesa, Mihai Christodorescu, Saman A. Zonouz |
| 2014 | Through the eye of the PLC: semantic security monitoring for industrial processes. | Dina Hadziosmanovic, Robin Sommer, Emmanuele Zambon, Pieter H. Hartel |
| 2014 | NodeSentry: least-privilege library integration for server-side JavaScript. | Willem De Groef, Fabio Massacci, Frank Piessens |
| 2014 | SEER: practical memory virus scanning as a service. | Jason Gionta, Ahmed M. Azab, William Enck, Peng Ning, Xiaolan Zhang |
| 2014 | On the privacy provisions of Bloom filters in lightweight bitcoin clients. | Arthur Gervais, Srdjan Capkun, Ghassan O. Karame, Damian Gruber |
| 2014 | Towards automated integrity protection of C++ virtual function tables in binary programs. | Robert Gawlik, Thorsten Holz |
| 2014 | Spam ain't as diverse as it seems: throttling OSN spam with templates underneath. | Hongyu Gao, Yi Yang, Kai Bu, Yan Chen, Doug Downey, Kathy Lee, Alok N. Choudhary |
| 2014 | MACE: high-coverage and robust memory analysis for commodity operating systems. | Qian Feng, Aravind Prakash, Heng Yin, Zhiqiang Lin |
| 2014 | Differentially private data aggregation with optimal utility. | Fabienne Eigner, Matteo Maffei, Ivan Pryvalov, Francesca Pampaloni, Aniket Kate |
| 2014 | TrueClick: automatically distinguishing trick banners from genuine download links. | Sevtap Duman, Kaan Onarlioglu, Ali Osman Ulusoy, William K. Robertson, Engin Kirda |
| 2014 | CPS: beyond usability: applying value sensitive design based methods to investigate domain characteristics for security for implantable cardiac devices. | Tamara Denning, Daniel B. Kramer, Batya Friedman, Matthew R. Reynolds, Brian T. Gill, Tadayoshi Kohno |
| 2014 | MoRePriv: mobile OS support for application personalization and privacy. | Drew Davidson, Matt Fredrikson, Benjamin Livshits |
| 2014 | HCODE: Hardware-Enhanced Real-Time CFI. | Jean-Luc Danger, Sylvain Guilley, Thibault Porteboeuf, Florian Praden, Michal Timbert |
| 2014 | IMSI-catch me if you can: IMSI-catcher-catchers. | Adrian Dabrowski, Nicola Pianta, Thomas Klepp, Martin Mulazzani, Edgar R. Weippl |
| 2014 | Probing the Limits of Virtualized Software Protection. | Joshua Cazalas, Jeffrey Todd McDonald, Todd R. Andel, Natalia Stakhanova |
| 2014 | Whitewash: outsourcing garbled circuit generation for mobile devices. | Henry Carter, Charles Lever, Patrick Traynor |