| 1999 | An Effective Defense Against First Party Attacks in Public-Key Algorithms. | Stephen M. Matyas, Allen Roginsky |
| 1999 | A Prototype Secure Workflow Server. | Douglas L. Long, Julie Baker, Francis Fung |
| 1999 | Secure Communications in ATM Networks. | Maryline Laurent, Ahmed Bouabdallah, Christophe Delahaye, Herbert Leitold, Reinhard Posch, Enrique Areizaga, Jun Manuel Mateos |
| 1999 | User Authentication and Authorization in the Java(tm) Platform. | Charlie Lai, Li Gong, Larry Koved, Anthony J. Nadalin, Roland Schemers |
| 1999 | SCR: A Practical Approach to Building a High Assurance COMSEC System. | James Kirby, Myla Archer, Constance L. Heitmeyer |
| 1999 | Towards a Practical, Secure, and Very Large Scale Online Election. | Jared Karro, Jie Wang |
| 1999 | Tools to Support Secure Enterprise Computing. | Myong H. Kang, Brian J. Eppinger, Judith N. Froscher |
| 1999 | Toward a Taxonomy and Costing Method for Security Services. | Cynthia E. Irvine, Timothy E. Levin |
| 1999 | TrustedBox: A Kernel-Level Integrity Checker. | Pietro Iglio |
| 1999 | SAM: Security Adaptation Manager . | Heather M. Hinton, Crispin Cowan, Lois M. L. Delcambre, Shawn Bowers |
| 1999 | Policy-Based Management: Bridging the Gap. | Susan Hinrichs |
| 1999 | Security Policy Coordination for Heterogeneous Information Systems. | John Hale, Pablo Galiasso, Mauricio Papa, Sujeet Shenoi |
| 1999 | Application-Level Isolation Using Data Inconsistency Detection. | Amgad Fayad, Sushil Jajodia, Catherine D. McCollum |
| 1999 | Generic Support for PKIX Certificate Management in CDSA. | Shabnam Erfani, C. Sekar Chandersekaran |
| 1999 | Architecture and Concepts of the ARGuE Guard. | Jeremy Epstein |
| 1999 | Security Relevancy Analysis on the Registry of Windows NT 4.0. | Wenliang Du, Praerit Garg, Aditya P. Mathur |
| 1999 | A Model of Certificate Revocation. | David A. Cooper |
| 1999 | Legal and Technical Responses to Protecting the U. S. Critical Infrastructures (Panel). | Arthur D. Friedman, Ellie Padgett, Mark Rasch, Scott Charney, John Thomas |
| 1999 | Information Security Education for the Next Millennium: Building the Next Generation of Practitioners (Forum). | Ron Ross, Cynthia E. Irvine, Charles Reynolds, Ravi S. Sandhu, Blaine Burnham, Rayford B. Vaughn |
| 1999 | SecurSight: An Architecture for Secure Information Access. | John G. Brainard |
| 1999 | Using Checkable Types in Automatic Protocol Analysis. | Stephen H. Brackin |
| 1999 | A Resource Access Decision Service for CORBA-Based Distributed Systems. | Konstantin Beznosov, Yi Deng, Bob Blakley, Carol C. Burt, John F. Barkley |
| 1999 | A Parallel Packet Screen for High Speed Networks. | Carsten Benecke |
| 1999 | Adding Availability to Log Services of Untrusted Machines. | Arianna Arona, Danilo Bruschi, Emilia Rosti |
| 1999 | How to Cheat at the Lottery (or, Massively Parallel Requirements Engineering). | Ross J. Anderson |