| 2008 | Host-Centric Model Checking for Network Vulnerability Analysis. | Rattikorn Hewett, Phongphun Kijsanayothin |
| 2008 | Please Permit Me: Stateless Delegated Authorization in Mashups. | Ragib Hasan, Marianne Winslett, Richard M. Conlan, Brian Slesinsky, Nandakumar Ramani |
| 2008 | The Role Hierarchy Mining Problem: Discovery of Optimal Role Hierarchies. | Qi Guo, Jaideep Vaidya, Vijayalakshmi Atluri |
| 2008 | Transaction Oriented Text Messaging with Trusted-SMS. | Antonio Grillo, Alessandro Lentini, Gianluigi Me, Giuseppe F. Italiano |
| 2008 | YAGP: Yet Another Graphical Password Strategy. | Haichang Gao, Xuewu Guo, Xiaoping Chen, Liming Wang, Xiyang Liu |
| 2008 | Behavior-Profile Clustering for False Alert Reduction in Anomaly Detection Sensors. | Vanessa Fras-Martnez, Salvatore J. Stolfo, Angelos D. Keromytis |
| 2008 | VICI Virtual Machine Introspection for Cognitive Immunity. | Timothy Fraser, Matthew R. Evenson, William A. Arbaugh |
| 2008 | Epilogue for RFC 1281, Guidelines for the Secure Operation of the Internet. | Barbara Fraser, Stephen D. Crocker |
| 2008 | The Evolution of System-Call Monitoring. | Stephanie Forrest, Steven Hofmeyr, Anil Somayaji |
| 2008 | Practical Applications of Bloom Filters to the NIST RDS and Hard Drive Triage. | Paul F. Farrell Jr., Simson L. Garfinkel, Douglas White |
| 2008 | PinUP: Pinning User Files to Known Applications. | William Enck, Patrick D. McDaniel, Trent Jaeger |
| 2008 | Defending Against Attacks on Main Memory Persistence. | William Enck, Kevin R. B. Butler, Thomas Richardson, Patrick D. McDaniel, Adam D. Smith |
| 2008 | Addressing Low Base Rates in Intrusion Detection via Uncertainty-Bounding Multi-Step Analysis. | Robert J. Cole, Peng Liu |
| 2008 | Privacy-Aware Biometrics: Design and Implementation of a Multimodal Verification System. | Stelvio Cimato, Marco Gamassi, Vincenzo Piuri, Roberto Sassi, Fabio Scotti |
| 2008 | Preventing Information Leaks through Shadow Executions. | Roberto Capizzi, Antonio Longo, V. N. Venkatakrishnan, A. Prasad Sistla |
| 2008 | Analysing the Performance of Security Solutions to Reduce Vulnerability Exposure Window. | Yolanta Beres, Jonathan Griffin, Simon Shiu, Max Heitman, David Markle, Peter Ventura |
| 2008 | Automatic Inference and Enforcement of Kernel Data Structure Invariants. | Arati Baliga, Vinod Ganapathy, Liviu Iftode |
| 2008 | PAS: Predicate-Based Authentication Services Against Powerful Passive Adversaries. | Xiaole Bai, Wenjun Gu, Sriram Chellappan, Xun Wang, Dong Xuan, Bin Ma |
| 2008 | Improving Security Visualization with Exposure Map Filtering. | Mansour Alsaleh, David Barrera, Paul C. van Oorschot |
| 2008 | DARE: A Framework for Dynamic Authentication of Remote Executions. | Erdem Aktas, Kanad Ghose |
| 2007 | Efficient Distributed Detection of Node Replication Attacks in Sensor Networks. | Bo Zhu, Venkata Gopala Krishna Addada, Sanjeev Setia, Sushil Jajodia, Sankardas Roy |
| 2007 | MetaAware: Identifying Metamorphic Malware. | Qinghua Zhang, Douglas S. Reeves |
| 2007 | Database Isolation and Filtering against Data Corruption Attacks. | Meng Yu, Wanyu Zang, Peng Liu |
| 2007 | Breaking Visual CAPTCHAs with Naive Pattern Recognition Algorithms. | Jeff Yan, Ahmad Salah El Ahmad |
| 2007 | HoneyIM: Fast Detection and Suppression of Instant Messaging Malware in Enterprise-Like Networks. | Mengjun Xie, Zhenyu Wu, Haining Wang |