| 2014 | Challenges and implications of verifiable builds for security-critical open-source software. | Xavier de Carn de Carnavalet, Mohammad Mannan |
| 2014 | JShield: towards real-time and vulnerability-based detection of polluted drive-by download attacks. | Yinzhi Cao, Xiang Pan, Yan Chen, Jianwei Zhuge |
| 2014 | Cloud radar: near real-time detection of security failures in dynamic virtualized infrastructures. | Sren Bleikertz, Carsten Vogel, Thomas Gro |
| 2014 | Hot-hardening: getting more out of your security settings. | Sebastian Biedermann, Stefan Katzenbeisser, Jakub Szefer |
| 2014 | CPS: market analysis of attacks against demand response in the smart grid. | Carlos A. Barreto, Alvaro A. Crdenas, Nicanor Quijano, Eduardo Mojica-Nava |
| 2014 | A security evaluation of AIS automated identification system. | Marco Balduzzi, Alessandro Pasta, Kyle Wilhoit |
| 2014 | Android security framework: extensible multi-layered access control on Android. | Michael Backes, Sven Bugiel, Sebastian Gerling, Philipp von Styp-Rekowsky |
| 2014 | Scippa: system-centric IPC provenance on Android. | Michael Backes, Sven Bugiel, Sebastian Gerling |
| 2014 | Understanding visual perceptions of usability and security of Android's graphical password pattern. | Adam J. Aviv, Dane Fichter |
| 2014 | Uncovering network tarpits with degreaser. | Lance Alt, Robert Beverly, Alberto Dainotti |
| 2014 | Mixed-Mode Malware and Its Analysis. | Shabnam Aboughadareh, Christoph Csallner, Mehdi Azarmi |
| 2013 | Auto-FBI: a user-friendly approach for secure access to sensitive content on the web. | Mohsen Zohrevandi, Rida A. Bazzi |
| 2013 | AFrame: isolating advertisements from mobile applications in Android. | Xiao Zhang, Amit Ahlawat, Wenliang Du |
| 2013 | Implementation and implications of a stealth hard-drive backdoor. | Jonas Zaddach, Anil Kurmus, Davide Balzarotti, Erik-Oliver Blass, Aurlien Francillon, Travis Goodspeed, Moitrayee Gupta, Ioannis Koltsidas |
| 2013 | Systems thinking for safety and security. | William Young, Nancy G. Leveson |
| 2013 | Beehive: large-scale log analysis for detecting suspicious activity in enterprise networks. | Ting-Fang Yen, Alina Oprea, Kaan Onarlioglu, Todd Leetham, William K. Robertson, Ari Juels, Engin Kirda |
| 2013 | Validating web content with senser. | Jordan Wilberding, Andrew Yates, Micah Sherr, Wenchao Zhou |
| 2013 | A portable user-level approach for system-wide integrity protection. | Wai-Kit Sze, R. Sekar |
| 2013 | Pitfalls in the automated strengthening of passwords. | David Schmidt, Trent Jaeger |
| 2013 | FireDroid: hardening security in almost-stock Android. | Giovanni Russello, Arturo Blas Jimenez, Habib Naderi, Wannes van der Mark |
| 2013 | DR BACA: dynamic role based access control for Android. | Felix Rohrer, Yuting Zhang, Lou Chitkushev, Tanya Zlateva |
| 2013 | Seeing is not believing: visual verifications through liveness analysis using mobile devices. | Mahmudur Rahman, Umut Topkara, Bogdan Carbunar |
| 2013 | The man who | Iasonas Polakis, Stamatis Volanis, Elias Athanasopoulos, Evangelos P. Markatos |
| 2013 | Control-flow restrictor: compiler-based CFI for iOS. | Jannik Pewny, Thorsten Holz |
| 2013 | k-subscription: privacy-preserving microblogging browsing through obfuscation. | Panagiotis Papadopoulos, Antonis Papadogiannakis, Michalis Polychronakis, Apostolis Zarras, Thorsten Holz, Evangelos P. Markatos |