| 2007 | Tracking Darkports for Network Defense. | David Whyte, Paul C. van Oorschot, Evangelos Kranakis |
| 2007 | Personal Privacy without Computational Obscurity: Rethinking Privacy Protection Strategies for Open Information Networks. | Daniel J. Weitzner |
| 2007 | Retrofitting the IBM POWER Hypervisor to Support Mandatory Access Control. | Enriquillo Valdez, Reiner Sailer, Ronald Perez |
| 2007 | Centralized Security Labels in Decentralized P2P Networks. | Nathalie Tsybulnik, Kevin W. Hamlen, Bhavani Thuraisingham |
| 2007 | Secure Input for Web Applications. | Martin Szydlowski, Christopher Kruegel, Engin Kirda |
| 2007 | Countering False Accusations and Collusion in the Detection of In-Band Wormholes. | Daniel Sterne, Geoffrey Lawler, Richard Gopaul, Brian Rivera, Kelvin Marcus, Peter Kruus |
| 2007 | Automated Vulnerability Analysis: Leveraging Control Flow for Evolutionary Input Crafting. | Sherri Sparks, Shawn Embleton, Ryan Cunningham, Cliff Changchun Zou |
| 2007 | The Age of Data: Pinpointing Guilty Bytes in Polymorphic Buffer Overflows on Heap or Stack. | Asia Slowinska, Herbert Bos |
| 2007 | Distributed Secure Systems: Then and Now. | Brian Randell, John M. Rushby |
| 2007 | Quarantining Untrusted Entities: Dynamic Sandboxing Using LEAP. | Manigandan Radhakrishnan, Jon A. Solworth |
| 2007 | Secure and Flexible Monitoring of Virtual Machines. | Bryan D. Payne, Wenke Lee |
| 2007 | Limits of Static Analysis for Malware Detection. | Andreas Moser, Christopher Kruegel, Engin Kirda |
| 2007 | Closed-Circuit Unobservable Voice over IP. | Carlos Aguilar Melchor, Yves Deswarte, Julien Iguchi-Cartigny |
| 2007 | Efficiency Issues of Rete-Based Expert Systems for Misuse Detection. | Michael Meier, Ulrich Flegel, Sebastian Schmerl |
| 2007 | OmniUnpack: Fast, Generic, and Safe Unpacking of Malware. | Lorenzo Martignoni, Mihai Christodorescu, Somesh Jha |
| 2007 | Automated Format String Attack Prevention for Win32/X86 Binaries. | Wei Li, Tzi-cker Chiueh |
| 2007 | Improving Signature Testing through Dynamic Data Flow Analysis. | Christopher Kruegel, Davide Balzarotti, William K. Robertson, Giovanni Vigna |
| 2007 | Sania: Syntactic and Semantic Analysis for Automated Testing against SQL Injection. | Yuji Kosuga, Kenji Kono, Miyuki Hanaoka, Miho Hishiyama, Yu Takahama |
| 2007 | Automated Security Debugging Using Program Structural Constraints. | Chongkyung Kil, Emre Can Sezer, Peng Ning, Xiaolan Zhang |
| 2007 | Toward Realistic and Artifact-Free Insider-Threat Data. | Kevin S. Killourhy, Roy A. Maxion |
| 2007 | Tampering with Special Purpose Trusted Computing Devices: A Case Study in Optical Scan E-Voting. | Aggelos Kiayias, Laurent Michel, Alexander Russell, Narasimha K. Shashidhar, Andrew See, Alexander A. Shvartsman, Seda Davtyan |
| 2007 | So You Think You Can Dance? | Richard A. Kemmerer |
| 2007 | Security Usability Principles for Vulnerability Analysis and Risk Assessment. | Audun Jsang, Bander AlFayyadh, Tyrone Grandison, Mohammed Al Zomai, Judith McNamara |
| 2007 | Extending the Java Virtual Machine to Enforce Fine-Grained Security Policies in Mobile Devices. | Iulia Ion, Boris Dragovic, Bruno Crispo |
| 2007 | Channels: Runtime System Infrastructure for Security-Typed Languages. | Boniface Hicks, Tim Misiak, Patrick D. McDaniel |