| 2001 | Requirements for a General Framework for Response to Distributed Denial-of-Service. | D. W. Gresty, Qi Shi, Madjid Merabti |
| 2001 | Experiences Implementing a Common Format for IDS Alerts. | Benjamin S. Feinstein, Gregory A. Matthews, Stuart Staniford, Andy Walther |
| 2001 | Engineering of Role/Permission Assignments. | Pete Epstein, Ravi S. Sandhu |
| 2001 | Computing Without Wires (Or Even a Net): The Pitfalls, Potentials, and Practicality of Wireless Networking. | Anna Entrichel, James Bergman, Jason Willis, Herb Little |
| 2001 | Privacy-Preserving Cooperative Statistical Analysis. | Wenliang Du, Mikhail J. Atallah |
| 2001 | Building Reliable Secure Computing Systems out of Unreliable Insecure Components. | John E. Dobson, Brian Randell |
| 2001 | Managing Alerts in a Multi-Intrusion Detection Environmen. | Frdric Cuppens |
| 2001 | A Framework for Multiple Authorization Types in a Healthcare Application System. | Ramaswamy Chandramouli |
| 2001 | Enabling Hierarchical and Bulk-Distribution for Watermarked Content. | Germano Caronni, Christoph L. Schuba |
| 2001 | Implementing the Intrusion Detection Exchange Protocol. | Tim Buchheim, Michael Erlinger, Benjamin S. Feinstein, Gregory A. Matthews, Roy Pollock, Joseph Betser, Andy Walther |
| 2001 | A Component-Based Architecture for Secure Data Publication. | Piero A. Bonatti, Ernesto Damiani, Sabrina De Capitani di Vimercati, Pierangela Samarati |
| 2001 | Trustworthiness in Distributed Electronic Healthcare Records-Basis for Shared Care. | Bernd Blobel |
| 2001 | How Useful is Software Fault Injection for Evaluating the Security of COTS Products? | Matt Bishop, Anup K. Ghosh, James A. Whittaker |
| 2001 | Wired versus Wireless Security: The Internet, WAP and iMode for E-Commerce. | Paul Ashley, Heather M. Hinton, Mark Vandenwauver |
| 2001 | Why Information Security is Hard-An Economic Perspective. | Ross J. Anderson |
| 2000 | Fair On-line Gambling. | Weiliang Zhao, Vijay Varadharajan, Yi Mu |
| 2000 | Applications in Health Care using Public-Key Certificates and Attribute Certificates. | Petra Wohlmacher, Peter Pharow |
| 2000 | On Computer Viral Infection and the Effect of Immunization. | Chenxi Wang, John C. Knight, Matthew C. Elder |
| 2000 | ITS4: A Static Vulnerability Scanner for C and C++ Code. | John Viega, J. T. Bloch, Y. Kohno, Gary McGraw |
| 2000 | A Policy-based Access Control Mechanism for the Corporate Web. | Victoria Ungureanu, F. Vesuna, Naftaly H. Minsky |
| 2000 | Denial of Service Protection - The Nozzle. | E. Strother |
| 2000 | Calculating Costs for Quality of Security Service. | E. Spyropoulou, Timothy E. Levin, Cynthia E. Irvine |
| 2000 | Efficient Commerce Protocols based on One-Time Pads. | Michael A. Schneider, Edward W. Felten |
| 2000 | Implementing Security Policies using the Safe Areas of Computation Approach. | Andr L. M. dos Santos, Richard A. Kemmerer |
| 2000 | History-based Distributed Filtering - A Tagging Approach to Network-Level Access Control. | Reiner Sailer, Matthias Kabatnik |