| 2010 | Stealth DoS Attacks on Secure Channels. | Amir Herzberg, Haya Schulmann |
| 2010 | On the Safety of Enterprise Policy Deployment. | Yudong Gao, Ni Pan, Xu Chen, Zhuoqing Morley Mao |
| 2010 | Preventing Capability Leaks in Secure JavaScript Subsets. | Matthew Finifter, Joel Weinberger, Adam Barth |
| 2010 | Where Do You Want to Go Today? Escalating Privileges by Pathname Manipulation. | Suresh Chari, Shai Halevi, Wietse Z. Venema |
| 2010 | Binary Code Extraction and Interface Identification for Security Applications. | Juan Caballero, Noah M. Johnson, Stephen McCamant, Dawn Song |
| 2010 | Server-side Verification of Client Behavior in Online Games. | Darrell Bethea, Robert A. Cochran, Michael K. Reiter |
| 2010 | A Security Evaluation of DNSSEC with NSEC3. | Jason Bau, John C. Mitchell |
| 2010 | Protecting Browsers from Extension Vulnerabilities. | Adam Barth, Adrienne Porter Felt, Prateek Saxena, Aaron Boodman |
| 2010 | Efficient Detection of Split Personalities in Malware. | Davide Balzarotti, Marco Cova, Christoph Karlberger, Engin Kirda, Christopher Kruegel, Giovanni Vigna |
| 2009 | Traffic Morphing: An Efficient Defense Against Statistical Traffic Analysis. | Charles V. Wright, Scott E. Coull, Fabian Monrose |
| 2009 | The Blind Stone Tablet: Outsourcing Durability to Untrusted Parties. | Peter Williams, Radu Sion, Dennis E. Shasha |
| 2009 | Detecting Forged TCP Reset Packets. | Nicholas Weaver, Robin Sommer, Vern Paxson |
| 2009 | IntScope: Automatically Detecting Integer Overflow Vulnerability in X86 Binary Using Symbolic Execution. | Tielei Wang, Tao Wei, Zhiqiang Lin, Wei Zou |
| 2009 | Spectrogram: A Mixture-of-Markov-Chains Model for Anomaly Detection in Web Traffic. | Yingbo Song, Angelos D. Keromytis, Salvatore J. Stolfo |
| 2009 | An Efficient Black-box Technique for Defeating Web Application Attacks. | R. Sekar |
| 2009 | Document Structure Integrity: A Robust Basis for Cross-site Scripting Defense. | Yacin Nadji, Prateek Saxena, Dawn Song |
| 2009 | Safe Passage for Passwords and Other Sensitive Data. | Jonathan M. McCune, Adrian Perrig, Michael K. Reiter |
| 2009 | K-Tracer: A System for Extracting Kernel Malware Behavior. | Andrea Lanzi, Monirul Islam Sharif, Wenke Lee |
| 2009 | Conditioned-safe Ceremonies and a User Study of an Application to Web Authentication. | Chris Karlof, J. Doug Tygar, David A. Wagner |
| 2009 | RB-Seeker: Auto-detection of Redirection Botnets. | Xin Hu, Matthew Knysz, Kang G. Shin |
| 2009 | RAINBOW: A Robust And Invisible Non-Blind Watermark for Network Flows. | Amir Houmansadr, Negar Kiyavash, Nikita Borisov |
| 2009 | Noncespaces: Using Randomization to Enforce Information Flow Tracking and Thwart Cross-Site Scripting Attacks. | Matthew Van Gundy, Hao Chen |
| 2009 | Coordinated Scan Detection. | Carrie Gates |
| 2009 | SybilInfer: Detecting Sybil Nodes using Social Networks. | George Danezis, Prateek Mittal |
| 2009 | Recursive DNS Architectures and Vulnerability Implications. | David Dagon, Manos Antonakakis, Kevin Day, Xiapu Luo, Christopher P. Lee, Wenke Lee |