| 2005 | Principles-driven forensic analysis. | Sean Peisert, Sidney Karin, Matt Bishop, Keith Marzullo |
| 2005 | Message authentication by integrity with public corroboration. | Paul C. van Oorschot |
| 2005 | Software diversity: | John McHugh |
| 2005 | Visual security protocol modeling. | John P. McDermott |
| 2005 | Use of diversity as a defense mechanism. | Roy A. Maxion |
| 2005 | Empirical privilege profiling. | Carla Marceau, Robert A. Joyce |
| 2005 | Speculative virtual verification: policy-constrained speculative execution. | Michael E. Locasto, Stelios Sidiroglou, Angelos D. Keromytis |
| 2005 | "Diversity as a computer defense mechanism". | Bev Littlewood |
| 2005 | Internet instability and disturbance: goal or menace? | Richard Ford, Mark Bush, Alex Boulatov |
| 2005 | Divide and conquer: the role of trust and assurance in the design of secure socio-technical systems. | Ivan Flechais, Jens Riegelsberger, Martina Angela Sasse |
| 2005 | Position: "insider" is relative. | Matt Bishop |
| 2005 | The insider problem revisited. | Matt Bishop |
| 2005 | Flooding and recycling authorizations. | Konstantin Beznosov |
| 2004 | A collaborative approach to autonomic security protocols. | Hongbin Zhou, Simon N. Foley |
| 2004 | Property-based attestation for computing platforms: caring about properties, not mechanisms. | Ahmad-Reza Sadeghi, Christian Stble |
| 2004 | Support for multi-level security policies in DRM architectures. | Bogdan C. Popescu, Bruno Crispo, Andrew S. Tanenbaum |
| 2004 | The role of suspicion in model-based intrusion detection. | Timothy Hollebeek, Rand Waltzman |
| 2004 | Symmetric behavior-based trust: a new paradigm for internet computing. | Vivek Haldar, Michael Franz |
| 2004 | The user non-acceptance paradigm: INFOSEC's dirty little secret. | Steven J. Greenwald, Kenneth G. Olthoff, Victor Raskin, Willibald Ruch |
| 2004 | Profiling the defenders. | Carrie Gates, Tara Whalen |
| 2004 | Omnivore: risk management through bidirectional transparency. | Scott Flinn, Steve Stoyles |
| 2004 | Information exposure control through data manipulation for ubiquitous computing. | Boris Dragovic, Jon Crowcroft |
| 2004 | Towards agile security assurance. | Konstantin Beznosov, Philippe Kruchten |
| 2004 | A qualitative framework for Shannon information theories. | Gerard Allwein |
| 2003 | Security check: a formal yet practical framework for secure software architecture. | Arnab Ray |