| 2010 | Paranoid Android: versatile protection for smartphones. | Georgios Portokalidis, Philip Homburg, Kostas Anagnostakis, Herbert Bos |
| 2010 | Keeping data secret under full compromise using porter devices. | Christina Ppper, David A. Basin, Srdjan Capkun, Cas Cremers |
| 2010 | Comprehensive shellcode detection using runtime heuristics. | Michalis Polychronakis, Kostas G. Anagnostakis, Evangelos P. Markatos |
| 2010 | Porscha: policy oriented secure content handling in Android. | Machigar Ongtang, Kevin R. B. Butler, Patrick D. McDaniel |
| 2010 | G-Free: defeating return-oriented programming through gadget-less binaries. | Kaan Onarlioglu, Leyla Bilge, Andrea Lanzi, Davide Balzarotti, Engin Kirda |
| 2010 | Multi-vendor penetration testing in the advanced metering infrastructure. | Stephen E. McLaughlin, Dmitry Podkuiko, Sergei Miadzvezhanka, Adam Delozier, Patrick D. McDaniel |
| 2010 | Barriers to science in security. | Tom Longstaff, David M. Balenson, Mark Matties |
| 2010 | FIRM: capability-based inline mediation of Flash behaviors. | Zhou Li, XiaoFeng Wang |
| 2010 | Defending DSSS-based broadcast communication against insider jammers via delayed seed-disclosure. | An Liu, Peng Ning, Huaiyu Dai, Yao Liu, Cliff Wang |
| 2010 | Breaking e-banking CAPTCHAs. | Shujun Li, S. Amier Haider Shah, M. Asad Usman Khan, Syed Ali Khayam, Ahmad-Reza Sadeghi, Roland Schmitz |
| 2010 | Analyzing and improving Linux kernel memory protection: a model checking approach. | Siarhei Liakh, Michael C. Grace, Xuxian Jiang |
| 2010 | Quantifying information leaks in software. | Jonathan Heusser, Pasquale Malacaria |
| 2010 | A multi-user steganographic file system on untrusted shared storage. | Jin Han, Meng Pan, Debin Gao, HweeHwa Pang |
| 2010 | SCOBA: source code based attestation on custom software. | Liang Gu, Yao Guo, Anbang Ruan, Qingni Shen, Hong Mei |
| 2010 | T-DRE: a hardware trusted computing base for direct recording electronic vote machines. | Roberto Gallo, Henrique Kawakami, Ricardo Dahab, Rafael Azevedo, Saulo Lima, Guido Araujo |
| 2010 | Securing interactive sessions using mobile device through visual channel and visual inspection. | Chengfang Fang, Ee-Chien Chang |
| 2010 | A framework for testing hardware-software security architectures. | Jeffrey S. Dwoskin, Mahadevan Gomathisankaran, Yu-Yuan Chen, Ruby B. Lee |
| 2010 | Heap Taichi: exploiting memory allocation granularity in heap-spraying attacks. | Yu Ding, Tao Wei, Tielei Wang, Zhenkai Liang, Wei Zou |
| 2010 | Two methodologies for physical penetration testing using social engineering. | Trajce Dimkov, Wolter Pieters, Pieter H. Hartel |
| 2010 | A quantitative analysis of the insecurity of embedded network devices: results of a wide-area scan. | Ang Cui, Salvatore J. Stolfo |
| 2010 | Friends of an enemy: identifying local members of peer-to-peer botnets using mutual contacts. | Baris Coskun, Sven Dietrich, Nasir D. Memon |
| 2010 | Familiarity breeds contempt: the honeymoon effect and the role of legacy code in zero-day vulnerabilities. | Sandy Clark, Stefan Frei, Matt Blaze, Jonathan M. Smith |
| 2010 | Who is tweeting on Twitter: human, bot, or cyborg? | Zi Chu, Steven Gianvecchio, Haining Wang, Sushil Jajodia |
| 2010 | Back to Berferd. | William R. Cheswick |
| 2010 | Forenscope: a framework for live forensics. | Ellick Chan, Shivaram Venkataraman, Francis M. David, Amey Chaugule, Roy H. Campbell |