| 2006 | Backtracking Algorithmic Complexity Attacks against a NIDS. | Randy Smith, Cristian Estan, Somesh Jha |
| 2006 | PolyUnpack: Automating the Hidden-Code Extraction of Unpack-Executing Malware. | Paul Royal, Mitch Halpin, David Dagon, Robert Edmonds, Wenke Lee |
| 2006 | A Study of Access Control Requirements for Healthcare Systems Based on Audit Trails from Access Logs. | Lillian Rstad, Ole Edsberg |
| 2006 | Anomaly Based Web Phishing Page Detection. | Ying Pan, Xuhua Ding |
| 2006 | A Framework for a Collaborative DDoS Defense. | George C. Oikonomou, Jelena Mirkovic, Peter L. Reiher, Max Robinson |
| 2006 | Risks of Untrustworthiness. | Peter G. Neumann |
| 2006 | Foreign Code Detection on the Windows/X86 Platform. | Susanta Nanda, Wei Li, Lap-Chung Lam, Tzi-cker Chiueh |
| 2006 | Vulnerability Analysis of MMS User Agents. | Collin Mulliner, Giovanni Vigna |
| 2006 | Shamon: A System for Distributed Mandatory Access Control. | Jonathan M. McCune, Trent Jaeger, Stefan Berger, Ramn Cceres, Reiner Sailer |
| 2006 | Automatic Evaluation of Intrusion Detection Systems. | Frdric Massicotte, Franois Gagnon, Yvan Labiche, Lionel C. Briand, Mathieu Couture |
| 2006 | How to Automatically and Accurately Sandbox Microsoft IIS. | Wei Li, Lap-Chung Lam, Tzi-cker Chiueh |
| 2006 | Address-Space Randomization for Windows Systems. | Lixin Li, James E. Just, R. Sekar |
| 2006 | A General Dynamic Information Flow Tracking Framework for Security Applications. | Lap-Chung Lam, Tzi-cker Chiueh |
| 2006 | Address Space Layout Permutation (ASLP): Towards Fine-Grained Randomization of Commodity Software. | Chongkyung Kil, Jinsuk Jun, Christopher Bookholt, Jun Xu, Peng Ning |
| 2006 | An Internet Voting System Supporting User Privacy. | Aggelos Kiayias, Michael Korman, David Walluck |
| 2006 | Data Sandboxing: A Technique for Enforcing Confidentiality Policies. | Tejas Khatiwala, Raj Swaminathan, V. N. Venkatakrishnan |
| 2006 | Delegate: A Proxy Based Architecture for Secure Website Access from an Untrusted Machine. | Ravi Chandra Jammalamadaka, Timothy W. van der Horst, Sharad Mehrotra, Kent E. Seamons, Nalini Venkatasubramanian |
| 2006 | Offloading IDS Computation to the GPU. | Nigel Jacob, Carla E. Brodley |
| 2006 | Practical Attack Graph Generation for Network Defense. | Kyle Ingols, Richard Lippmann, Keith Piwowarski |
| 2006 | Back to the Future: A Framework for Automatic Malware Removal and System Repair. | Francis Hsu, Hao Chen, Thomas Ristenpart, Jason Li, Zhendong Su |
| 2006 | Detecting Policy Violations through Traffic Analysis. | Jeffrey Horton, Reihaneh Safavi-Naini |
| 2006 | From Languages to Systems: Understanding Practical Application Development in Security-typed Languages. | Boniface Hicks, Kiyan Ahmadizadeh, Patrick D. McDaniel |
| 2006 | Specification-Based Intrusion Detection in WLANs. | Rupinder Gill, Jason Smith, Andrew J. Clark |
| 2006 | PAST: Probabilistic Authentication of Sensor Timestamps. | Ashish Gehani, Surendar Chandra |
| 2006 | A Module System for Isolating Untrusted Software Extensions. | Philip W. L. Fong, Simon A. Orr |