| 2005 | Have the cake and eat it too - Infusing usability into text-password based authentication systems. | Sundararaman Jeyaraman, Umut Topkara |
| 2005 | Dynamic Taint Propagation for Java. | Vivek Haldar, Deepak Chandra, Michael Franz |
| 2005 | Automated and Safe Vulnerability Assessment. | Fanglu Guo, Yang Yu, Tzi-cker Chiueh |
| 2005 | Strengthening Software Self-Checksumming via Self-Modifying Code. | Jonathon T. Giffin, Mihai Christodorescu, Louis Kruger |
| 2005 | Highlights from the 2005 New Security Paradigms Workshop. | Simon N. Foley, Abe Singer, Michael E. Locasto, Stelios Sidiroglou, Angelos D. Keromytis, John P. McDermott, Julie Thorpe, Paul C. van Oorschot, Anil Somayaji, Richard Ford, Mark Bush, Alex Boulatov |
| 2005 | A Nitpicker's guide to a minimal-complexity secure GUI. | Norman Feske, Christian Helmuth |
| 2005 | Improved Port Knocking with Strong Authentication. | Rennie deGraaf, John Aycock, Michael J. Jacobson Jr. |
| 2005 | Java for Mobile Devices: A Security Study. | Mourad Debbabi, Mohamed Mostafa Saleh, Chamseddine Talhi, Sami Zhioua |
| 2005 | Design and Implementation of an Extrusion-based Break-In Detector for Personal Computers. | Weidong Cui, Randy H. Katz, Wai-tian Tan |
| 2005 | How to Develop a Career in Information Assurance and How to Advance in this Field. | Marla Collier |
| 2005 | Survivability Architecture of a Mission Critical System: The DPASA Example. | Jennifer Chong, Partha P. Pal, Michael Atighetchi, Paul Rubel, Franklin Webber |
| 2005 | An Integrity Verification Scheme for DNS Zone file based on Security Impact Analysis. | Ramaswamy Chandramouli, Scott Rose |
| 2005 | Replay Attack in TCG Specification and Solution. | Danilo Bruschi, Lorenzo Cavallaro, Andrea Lanzi, Mattia Monga |
| 2005 | Lessons Learned: A Security Analysis of the Internet Chess Club. | John Black, Martin Cochran, Ryan W. Gardner |
| 2005 | Intrusion Detection in RBAC-administered Databases. | Elisa Bertino, Ashish Kamra, Evimaria Terzi, Athena Vakali |
| 2005 | Looking Back at the Bell-La Padula Model. | David Elliott Bell |
| 2005 | A Framework for Detecting Network-based Code Injection Attacks Targeting Windows and UNIX. | Stig Andersson, Andrew J. Clark, George M. Mohay, Bradley L. Schatz, Jacob Zimmermann |
| 2005 | A Host-Based Approach to Network Attack Chaining Analysis. | Paul Ammann, Joseph Pamula, Julie A. Street, Ronald W. Ritchey |
| 2004 | Detecting Attacks That Exploit Application-Logic Errors Through Application-Level Auditing. | Jingyu Zhou, Giovanni Vigna |
| 2004 | Reasoning About Complementary Intrusion Evidence. | Yan Zhai, Peng Ning, Purush Iyer, Douglas S. Reeves |
| 2004 | Alert Correlation through Triggering Events and Common Resources. | Dingbang Xu, Peng Ning |
| 2004 | Detecting Exploit Code Execution in Loadable Kernel Modules. | Haizhi Xu, Wenliang Du, Steve J. Chapin |
| 2004 | An Intrusion Detection Tool for AODV-Based Ad hoc Wireless Networks. | Giovanni Vigna, Sumit Gwalani, Kavitha Srinivasan, Elizabeth M. Belding-Royer, Richard A. Kemmerer |
| 2004 | A Serial Combination of Anomaly and Misuse IDSes Applied to HTTP Traffic. | Elvis Tombini, Herv Debar, Ludovic M, Mireille Ducass |
| 2004 | Towards Secure Design Choices for Implementing Graphical Passwords. | Julie Thorpe, Paul C. van Oorschot |