| 2001 | Information Security: Science, Pseudoscience, and Flying Pigs. | Roger R. Schell |
| 2001 | Detecting Conflicts in a Role-Based Delegation Model. | Andreas Schaad |
| 2001 | Practical Automated Filter Generation to Explicitly Enforce Implicit Input Assumptions. | Valentin Razmov, Daniel R. Simon |
| 2001 | Architecture and Applications for a Distributed Embedded Firewall. | Charles Payne, Tom Markham |
| 2001 | Watcher: The Missing Piece of the Security Puzzle. | John C. Munson, Scott Wimer |
| 2001 | Secure Blue: An Architecture for a Scalable, Reliable, High Volume SSL Internet Server. | Ronald Mraz |
| 2001 | Genoa TIE, Advanced Boundary Controller Experiment. | Eric Monteith |
| 2001 | An Information Flow Tool for Gypsy. | John McHugh |
| 2001 | Abuse-Case-Based Assurance Arguments. | John P. McDermott |
| 2001 | Mitigating Distributed Denial of Service Attacks with Dynamic Resource Pricing. | David Mankins, Rajesh Krishnan, Ceilyn Boyd, John Zao, Michael Frentz |
| 2001 | DAIS: A Real-Time Data Attack Isolation System for Commercial Database Applications. | Peng Liu |
| 2001 | eXpert-BSM: A Host-Based Intrusion Detection Solution for Sun Solaris. | Ulf Lindqvist, Phillip A. Porras |
| 2001 | CONSEPP: CONvenient and Secure Electronic Payment Protocol Based on X9.59. | Albert Levi, etin Kaya Ko |
| 2001 | Verifiable Identifiers in Middleware Security. | Ulrich Lang, Dieter Gollmann, Rudolf Schreiner |
| 2001 | A Security Model for Military Message Systems: Retrospective. | Carl E. Landwehr, Constance L. Heitmeyer, John D. McLean |
| 2001 | The Authorization Service of Tivoli Policy Director. | Gnter Karjoth |
| 2001 | Mining Alarm Clusters to Improve Alarm Handling Efficiency. | Klaus Julisch |
| 2001 | Application Intrusion Detection using Language Library Calls. | Anita K. Jones, Yu Lin |
| 2001 | Temporal Signatures for Intrusion Detection. | Anita Jones, Song Li |
| 2001 | Securing Web Servers against Insider Attack . | Shan Jiang, Sean W. Smith, Kazuhiro Minami |
| 2001 | Determining Privileges of Mobile Agents. | Wayne A. Jansen |
| 2001 | A JCA-Based Implementation Framework for Threshold Cryptography. | Yih Huang, David Rine, Xunhua Wang |
| 2001 | Information Flow Analysis of Component-Structured Applications. | Peter Herrmann |
| 2001 | Restricting Access with Certificate Attributes in Multiple Root Environments-A Recipe for Certificate Masquerading. | James M. Hayes |
| 2001 | Security Vendor CTOs: Perspectives, Opinions, and Lessons Learned. | Ron Gula, Gene Kim, Chris Klaus, Paul Proctor |