| 2013 | Extraction of statistically significant malware behaviors. | Sirinda Palahan, Domagoj Babic, Swarat Chaudhuri, Daniel Kifer |
| 2013 | Do I know you?: efficient and privacy-preserving common friend-finder protocols and applications. | Marcin Nagy, Emiliano De Cristofaro, Alexandra Dmitrienko, N. Asokan, Ahmad-Reza Sadeghi |
| 2013 | SilverLine: preventing data leaks from compromised web applications. | Yogesh Mundada, Anirudh Ramachandran, Nick Feamster |
| 2013 | PatchDroid: scalable third-party security patches for Android devices. | Collin Mulliner, Jon Oberheide, William K. Robertson, Engin Kirda |
| 2013 | CPS: stateful policy enforcement for control system device usage. | Stephen E. McLaughlin |
| 2013 | MyCloud: supporting user-configured privacy protection in cloud computing. | Min Li, Wanyu Zang, Kun Bai, Meng Yu, Peng Liu |
| 2013 | Crossover: secure and usable user interface for mobile devices with multiple isolated OS personalities. | Matthias Lange, Steffen Liebergeld |
| 2013 | A building code for building code: putting what we know works to work. | Carl E. Landwehr |
| 2013 | SigMal: a static signal processing based malware triage. | Dhilung Kirat, Lakshmanan Nataraj, Giovanni Vigna, B. S. Manjunath |
| 2013 | Message in a bottle: sailing past censorship. | Luca Invernizzi, Christopher Kruegel, Giovanni Vigna |
| 2013 | GPU and CPU parallelization of honest-but-curious secure two-party computation. | Nathaniel Husted, Steven A. Myers, Abhi Shelat, Paul Grubbs |
| 2013 | DUET: integration of dynamic and static analyses for malware clustering with cluster ensembles. | Xin Hu, Kang G. Shin |
| 2013 | Socket overloading for fun and cache-poisoning. | Amir Herzberg, Haya Schulmann |
| 2013 | CPS: an efficiency-motivated attack against autonomous vehicular transportation. | Ryan M. Gerdes, Chris Winstead, Kevin P. Heaslip |
| 2013 | Uncovering access control weaknesses and flaws with security-discordant software clones. | Franois Gauthier, Thierry Lavoie, Ettore Merlo |
| 2013 | PRIME: private RSA infrastructure for memory-less encryption. | Behrad Garmany, Tilo Mller |
| 2013 | Subverting system authentication with context-aware, reactive virtual machine introspection. | Yangchun Fu, Zhiqiang Lin, Kevin W. Hamlen |
| 2013 | SPIDER: stealthy binary program instrumentation and debugging via hardware virtualization. | Zhui Deng, Xiangyu Zhang, Dongyan Xu |
| 2013 | A comprehensive black-box methodology for testing the forensic characteristics of solid-state drives. | Gabriele Bonetti, Marco Viglione, Alessandro Frossi, Federico Maggi, Stefano Zanero |
| 2013 | Discovery of emergent malicious campaigns in cellular networks. | Nathaniel Boggs, Wei Wang, Suhas Mathur, Baris Coskun, Carol Pincock |
| 2013 | No attack necessary: the surprising dynamics of SSL trust relationships. | B. Amann, Robin Sommer, Matthias Vallentin, Seth Hall |
| 2013 | Revisiting graphical passwords for augmenting, not replacing, text passwords. | Murat Akpulat, Kemal Bicakci, Ugur Cil |
| 2012 | Cloud-based push-styled mobile botnets: a case study of exploiting the cloud to device messaging service. | Shuang Zhao, Patrick P. C. Lee, John C. S. Lui, Xiaohong Guan, Xiaobo Ma, Jing Tao |
| 2012 | Self-healing multitier architectures using cascading rescue points. | Angeliki Zavou, Georgios Portokalidis, Angelos D. Keromytis |
| 2012 | Generalized vulnerability extrapolation using abstract syntax trees. | Fabian Yamaguchi, Markus Lottmann, Konrad Rieck |