| 2005 | Building Evidence Graphs for Network Forensics Analysis. | Wei Wang, Thomas E. Daniels |
| 2005 | Fault Attacks on Dual-Rail Encoded Systems. | Jason Waddle, David A. Wagner |
| 2005 | Uniform Application-level Access Control Enforcement of Organizationwide Policies. | Tine Verhanneman, Frank Piessens, Bart De Win, Wouter Joosen |
| 2005 | Stealth Breakpoints. | Amit Vasudevan, Ramesh Yerraballi |
| 2005 | Graphical Passwords: A Survey. | Xiaoyuan Suo, Ying Zhu, G. Scott Owen |
| 2005 | Exploiting Independent State For Network Intrusion Detection. | Robin Sommer, Vern Paxson |
| 2005 | We Need Assurance! | Brian D. Snow |
| 2005 | PorKI: Making User PKI Safe on Machines of Heterogeneous Trustworthiness. | Sara Sinclair, Sean W. Smith |
| 2005 | Model Checking An Entire Linux Distribution for Security Violations. | Benjamin Schwarz, Hao Chen, David A. Wagner, Jeremy Lin, Wei Tu, Geoff Morrison, Jacob West |
| 2005 | Building a MAC-Based Security Architecture for the Xen Open-Source Hypervisor. | Reiner Sailer, Trent Jaeger, Enriquillo Valdez, Ramn Cceres, Ronald Perez, Stefan Berger, John Linwood Griffin, Leendert van Doorn |
| 2005 | Generating Policies for Defense in Depth. | Paul Rubel, Michael Ihde, Steven A. Harp, Charles N. Payne |
| 2005 | Understanding Complex Network Attack Graphs through Clustered Adjacency Matrices. | Steven Noel, Sushil Jajodia |
| 2005 | TARP: Ticket-based Address Resolution Protocol. | Wesam Lootah, William Enck, Patrick D. McDaniel |
| 2005 | Securing Email Archives through User Modeling. | Yiru Li, Anil Somayaji |
| 2005 | mSSL: Extending SSL to Support Data Sharing Among Collaborative Clients. | Jun Li, Xun Kang |
| 2005 | Automatic Generation of Buffer Overflow Attack Signatures: An Approach Based on Program Behavior Models. | Zhenkai Liang, R. Sekar |
| 2005 | ScriptGen: an automated script generation tool for honeyd. | Corrado Leita, Ken Mermoud, Marc Dacier |
| 2005 | Using Continuous Biometric Verification to Protect Interactive Login Sessions. | Sandeep Kumar, Terence Sim, Rajkumar Janakiraman, Sheng Zhang |
| 2005 | e-NeXSh: Achieving an Effectively Non-Executable Stack and Heap via System-Call Policing. | Gaurav S. Kc, Angelos D. Keromytis |
| 2005 | Evolving Successful Stack Overflow Attacks for Vulnerability Testing. | Hilmi Gnes Kayacik, Nur Zincir-Heywood, Malcolm I. Heywood |
| 2005 | Multi-Level Security Requirements for Hypervisors. | Paul A. Karger |
| 2005 | The Pump: A Decade of Covert Fun. | Myong H. Kang, Ira S. Moskowitz, Stanley Chincheck |
| 2005 | Privacy Requirements Implemented with a JavaCard. | Anas Abou El Kalam, Yves Deswarte |
| 2005 | Code Security Analysis of a Biometric Authentication System Using Automated Theorem Provers. | Jan Jrjens |
| 2005 | Layering Public Key Distribution Over Secure DNS using Authenticated Delegation. | John P. Jones, Daniel F. Berger, Chinya V. Ravishankar |