| 2013 | Towards the realization of a public health system for shared secure cyber-space. | Jeff Rowe, Karl N. Levitt, Mike Hogarth |
| 2013 | Principles of authentication. | Sean Peisert, Edward B. Talbot, Tom M. Kroeger |
| 2013 | Detecting hidden enemy lines in IP address space. | Suhas Mathur, Baris Coskun, Suhrid Balakrishnan |
| 2013 | Markets for zero-day exploits: ethics and implications. | Serge Egelman, Cormac Herley, Paul C. van Oorschot |
| 2013 | Useful password hashing: how to waste computing cycles with style. | Markus Drmuth |
| 2013 | Booby trapping software. | Stephen Crane, Per Larsen, Stefan Brunthaler, Michael Franz |
| 2013 | Go with the flow: toward workflow-oriented security assessment. | Binbin Chen, Zbigniew Kalbarczyk, David M. Nicol, William H. Sanders, Rui Tan, William G. Temple, Nils Ole Tippenhauer, An Hoa Vu, David K. Y. Yau |
| 2013 | NSPHD: the polyglot computer. | Daniel Medeiros Nunes de Castro |
| 2013 | Forgive and forget: return to obscurity. | Matt Bishop, Emily Rine Butler, Kevin R. B. Butler, Carrie Gates, Steven Greenspan |
| 2013 | Can we sell security like soap?: a new approach to behaviour change. | Debi Ashenden, Darren Lawrence |
| 2013 | Information behaving badly. | Julie Boxwell Ard, Matt Bishop, Carrie Gates, Michael Xin Sun |
| 2012 | Point-and-shoot security design: can we build better tools for developers? | Sven Trpe |
| 2012 | Video-passwords: advertising while authenticating. | Julie Thorpe, Amirali Salehi-Abari, Robert Burden |
| 2012 | Argumentation logic to assist in security administration. | Jeff Rowe, Karl N. Levitt, Simon Parsons, Elizabeth Sklar, Andy Applebaum, Sharmin Jalal |
| 2012 | A move in the security measurement stalemate: elo-style ratings to quantify vulnerability. | Wolter Pieters, Sanne H. G. van der Ven, Christian W. Probst |
| 2012 | Turtles all the way down: a clean-slate, ground-up, first-principles approach to secure systems. | Sean Peisert, Edward B. Talbot, Matt Bishop |
| 2012 | Privacy is a process, not a PET: a theory for effective privacy practice. | Anthony Morton, Martina Angela Sasse |
| 2012 | Someone to watch over me. | Heather Richter Lipford, Mary Ellen Zurko |
| 2012 | The need for application-aware access control evaluation. | William C. Garrison III, Adam J. Lee, Timothy L. Hinrichs |
| 2012 | All your base are belong to US. | Richard Ford, Liam M. Mayron |
| 2012 | Beyond the blacklist: modeling malware spread and the effect of interventions. | Benjamin Edwards, Tyler Moore, George Stelle, Steven Hofmeyr, Stephanie Forrest |
| 2012 | Pools, clubs and security: designing for a party not a person. | Zheng Dong, Vaibhav Garg, L. Jean Camp, Apu Kapadia |
| 2012 | Holographic vulnerability studies: vulnerabilities as fractures in interpretation as information flows across abstraction boundaries. | Jedidiah R. Crandall, Daniela Oliveira |
| 2011 | Influencing mental models of security: a research agenda. | Rick Wash, Emilee J. Rader |
| 2011 | Reducing normative conflicts in information security. | Wolter Pieters, Lizzie Coles-Kemp |