| 2009 | TrustGraph: Trusted Graphics Subsystem for High Assurance Systems. | Hamed Okhravi, David M. Nicol |
| 2009 | Privacy through Noise: A Design Space for Private Identification. | Karsten Nohl, David Evans |
| 2009 | MAVMM: Lightweight and Purpose Built VMM for Malware Analysis. | Anh M. Nguyen, Nabil Schear, HeeDong Jung, Apeksha Godiyal, Samuel T. King, Hai D. Nguyen |
| 2009 | Computer-Related Risk Futures. | Peter G. Neumann |
| 2009 | Scalable Web Content Attestation. | Thomas Moyer, Kevin R. B. Butler, Joshua Schiffman, Patrick D. McDaniel, Trent Jaeger |
| 2009 | Online Signature Generation for Windows Systems. | Lixin Li, James E. Just, R. Sekar |
| 2009 | On the Security of PAS (Predicate-Based Authentication Service). | Shujun Li, Hassan Jameel Asghar, Josef Pieprzyk, Ahmad-Reza Sadeghi, Roland Schmitz, Huaxiong Wang |
| 2009 | RAD: Reflector Attack Defense Using Message Authentication Codes. | Erik Kline, Matt Beaumont-Gay, Jelena Mirkovic, Peter L. Reiher |
| 2009 | Evaluation of a DPA-Resistant Prototype Chip. | Mario Kirschbaum, Thomas Popp |
| 2009 | Unifying Broadcast Encryption and Traitor Tracing for Content Protection. | Hongxia Jin, Jeffrey B. Lotspiech |
| 2009 | Modeling Modern Network Attacks and Countermeasures Using Attack Graphs. | Kyle Ingols, Matthew Chu, Richard Lippmann, Seth E. Webster, Stephen W. Boyer |
| 2009 | A Study of User-Friendly Hash Comparison Schemes. | Hsu-Chun Hsiao, Yue-Hsun Lin, Ahren Studer, Cassandra Studer, King-Hang Wang, Hiroaki Kikuchi, Adrian Perrig, Hung-Min Sun, Bo-Yin Yang |
| 2009 | Active Botnet Probing to Identify Obscure Command and Control Channels. | Guofei Gu, Vinod Yegneswaran, Phillip A. Porras, Jennifer Stoll, Wenke Lee |
| 2009 | Java Security: A Ten Year Retrospective. | Li Gong |
| 2009 | A Network Access Control Mechanism Based on Behavior Profiles. | Vanessa Fras-Martnez, Joseph Sherrick, Salvatore J. Stolfo, Angelos D. Keromytis |
| 2009 | Analyzing and Detecting Malicious Flash Advertisements. | Sean Ford, Marco Cova, Christopher Kruegel, Giovanni Vigna |
| 2009 | How to Securely Break into RBAC: The BTG-RBAC Model. | Ana Ferreira, David W. Chadwick, Pedro Farinha, Ricardo Joo Cruz Correia, Gansen Zhao, Rui Chilro, Luis Filipe Coelho Antunes |
| 2009 | A Survey of Vendor Software Assurance Practices. | Jeremy Epstein |
| 2009 | Analyzing Information Flow in JavaScript-Based Browser Extensions. | Mohan Dhawan, Vinod Ganapathy |
| 2009 | The Good, the Bad, And the Ugly: Stepping on the Security Scale. | Mary Ann Davidson |
| 2009 | Online Sketching of Network Flows for Real-Time Stepping-Stone Detection. | Baris Coskun, Nasir D. Memon |
| 2009 | Protecting Commodity Operating System Kernels from Vulnerable Device Drivers. | Shakeel Butt, Vinod Ganapathy, Michael M. Swift, Chih-Cheng Chang |
| 2009 | Reflections on UNIX Vulnerabilities. | Matt Bishop |
| 2009 | HIMA: A Hypervisor-Based Integrity Measurement Agent. | Ahmed M. Azab, Peng Ning, Emre Can Sezer, Xiaolan Zhang |
| 2009 | A Guided Tour Puzzle for Denial of Service Prevention. | Mehmud Abliz, Taieb Znati |