| 1999 | SASI enforcement of security policies: a retrospective. | lfar Erlingsson, Fred B. Schneider |
| 1998 | Toward a Secure System Engineering Methodolgy. | Chris Slater, O. Sami Saydjari, Bruce Schneier, Jim Wallner |
| 1998 | Meta Objects for Access Control: a Formal Model for Role-Based Principals. | Thomas Riechmann, Franz J. Hauck |
| 1998 | A Graph-based System for Network-vulnerability Analysis. | Cynthia A. Phillips, Laura Painton Swiler |
| 1998 | Position Paper: Prolepsis on the Problem of Trojan-horse Based Integrity Attacks. | John P. McDermott |
| 1998 | A New Model for Availability in the Face of Self-Propagating Attacks. | Meng-Jang Lin, Aleta Ricciardi, Keith Marzullo |
| 1998 | Tolerating Penetrations and Insider Attacks by Requiring Independent Corroboration. | Clifford E. Kahn |
| 1998 | An Integrated Framework for Security and Dependability. | Erland Jonsson |
| 1998 | Discussion Topic: What is the Old Security Paradigm? | Steven J. Greenwald |
| 1998 | Evaluating System Integrity. | Simon N. Foley |
| 1998 | Death, Taxes, and Imperfact Software: Surviving the Inevitable. | Crispin Cowan, Calton Pu |
| 1998 | Parsimonious Downgrading and Decision Trees Applied to the Inference Problem. | Liwu Chang, Ira S. Moskowitz |
| 1998 | Server-Assisted Cryptography. | Donald Beaver |
| 1998 | Security Engineering in an Evolutionary Acquisition Environment. | Marshall D. Abrams |
| 1997 | A security model for dynamic adaptive traffic masking. | Brenda Timmerman |
| 1997 | Principles of a computer immune system. | Anil Somayaji, Steven Hofmeyr, Stephanie Forrest |
| 1997 | Meta objects for access control: extending capability-based security. | Thomas Riechmann, Franz J. Hauck |
| 1997 | Integrating formalism and pragmatism: architectural security. | Ruth Nelson |
| 1997 | An insecurity flow model. | Ira S. Moskowitz, Myong H. Kang |
| 1997 | Three paradigms in computer security. | Catherine Meadows |
| 1997 | A tentative approach to constructing tamper-resistant software. | Masahiro Mambo, Takanori Murayama, Eiji Okamoto |
| 1997 | A practical approach to security assessment. | Darrell M. Kienzle, William A. Wulf |
| 1997 | Under-specification, composition and emergent properties. | Heather M. Hinton |
| 1997 | Patterns of trust and policy. | Daniel J. Essin |
| 1997 | Protecting routing infrastructures from denial of service using cooperative intrusion detection. | Steven Cheung, Karl N. Levitt |