| 2008 | Permission Set Mining: Discovering Practical and Useful Roles. | Dana Zhang, Kotagiri Ramamohanarao, Tim Ebringer, Trevor Yann |
| 2008 | Attack Grammar: A New Approach to Modeling and Analyzing Network Attack Sequences. | Yinqian Zhang, Xun Fan, Yijun Wang, Zhi Xue |
| 2008 | OMOS: A Framework for Secure Communication in Mashup Applications. | Saman Zarandioon, Danfeng Yao, Vinod Ganapathy |
| 2008 | Anti-Phishing in Offense and Defense. | Chuan Yue, Haining Wang |
| 2008 | Soft-Timer Driven Transient Kernel Control Flow Attacks and Defense. | Jinpeng Wei, Bryan D. Payne, Jonathon Giffin, Calton Pu |
| 2008 | STILL: Exploit Code Detection via Static Taint and Initialization Analyses. | Xinran Wang, Yoon-chan Jhi, Sencun Zhu, Peng Liu |
| 2008 | Improving the Efficiency of Capture-Resistant Biometric Authentication Based on Set Intersection. | Xunhua Wang, Philip D. Huff, Brett C. Tjaden |
| 2008 | MalTRAK: Tracking and Eliminating Unknown Malware. | Amit Vasudevan |
| 2008 | New Side Channels Targeted at Passwords. | Albert Tannous, Jonathan T. Trostle, Mohamed Hassan, Stephen E. McLaughlin, Trent Jaeger |
| 2008 | A Survey to Guide Group Key Protocol Development. | Ahren Studer, Christina Johns, Jaanus Kase, Kyle O'Meara, Lorrie Faith Cranor |
| 2008 | Enforcing Role-Based Access Control Policies in Web Services with UML and OCL. | Karsten Sohr, Tanveer Mustafa, Xinyu Bao, Gail-Joon Ahn |
| 2008 | Systematic Signature Engineering by Re-use of Snort Signatures. | Sebastian Schmerl, Hartmut Knig, Ulrich Flegel, Michael Meier, Ren Rietz |
| 2008 | Structuring for Strategic Cyber Defense: A Cyber Manhattan Project Blueprint. | O. Sami Saydjari |
| 2008 | On Purely Automated Attacks and Click-Based Graphical Passwords. | Amirali Salehi-Abari, Julie Thorpe, Paul C. van Oorschot |
| 2008 | McBoost: Boosting Scalability in Malware Collection and Analysis Using Statistical Classification of Executables. | Roberto Perdisci, Andrea Lanzi, Wenke Lee |
| 2008 | Instruction Set Extensions for Enhancing the Performance of Symmetric-Key Cryptography. | Sean O'Melia, Adam J. Elbirt |
| 2008 | Bluetooth Network-Based Misuse Detection. | Terrence O'Connor, Douglas S. Reeves |
| 2008 | Execution Trace-Driven Automated Attack Signature Generation. | Susanta Nanda, Tzi-cker Chiueh |
| 2008 | Toward Automatic Generation of Intrusion Detection Verification Rules. | Frdric Massicotte, Yvan Labiche, Lionel C. Briand |
| 2008 | Assessing Quality of Policy Properties in Verification of Access Control Policies. | Evan Martin, JeeHyun Hwang, Tao Xie, Vincent C. Hu |
| 2008 | Bridging the Gap between Data-Flow and Control-Flow Analysis for Anomaly Detection. | Peng Li, Hyundo Park, Debin Gao, Jianming Fu |
| 2008 | ProActive Access Control for Business Process-Driven Environments. | Mathias Kohler, Andreas Schaad |
| 2008 | Implementing ACL-Based Policies in XACML. | Gnter Karjoth, Andreas Schade, Els Van Herreweghen |
| 2008 | XSSDS: Server-Side Detection of Cross-Site Scripting Attacks. | Martin Johns, Bjrn Engelmann, Joachim Posegga |
| 2008 | pwdArmor: Protecting Conventional Password-Based Authentications. | Timothy W. van der Horst, Kent E. Seamons |