| 2009 | What is the shape of your security policy?: security as a classification problem. | Sven Trpe |
| 2009 | Fluid information systems. | Christian W. Probst, Ren Rydhof Hansen |
| 2009 | Quis Custodiet ipsos Custodes?: a new paradigm for analyzing security paradigms with appreciation to the Roman poet Juvenal. | Sean Peisert, Matt Bishop, Laura Corriss, Steven J. Greenwald |
| 2009 | A reinforcement model for collaborative security and Its formal analysis. | Janardan Misra, Indranil Saha |
| 2009 | Securing data through avoidance routing. | Erik Kline, Peter L. Reiher |
| 2009 | Laissez-faire file sharing: access control designed for individuals at the endpoints. | Maritza L. Johnson, Steven M. Bellovin, Robert W. Reeder, Stuart E. Schechter |
| 2009 | Server-side detection of malware infection. | Markus Jakobsson, Ari Juels |
| 2009 | So long, and no thanks for the externalities: the rational rejection of security advice by users. | Cormac Herley |
| 2009 | Musipass: authenticating me softly with "my" song. | Marcia Gibson, Karen Renaud, Marc Conrad, Carsten Maple |
| 2009 | Generative usability: security and user centered design beyond the appliance. | Luke Church, Alma Whitten |
| 2009 | The sisterhood of the traveling packets. | Matt Bishop, Carrie Gates, Jeffrey Hunker |
| 2008 | ROFL: routing as the firewall layer. | Hang Zhao, Chi-Kin Chau, Steven M. Bellovin |
| 2008 | The developer is the enemy. | Glenn Wurster, Paul C. van Oorschot |
| 2008 | The user is not the enemy: fighting malware by tracking user intentions. | Jeff Shirley, David Evans |
| 2008 | Trading in risk: using markets to improve access control. | Ian M. Molloy, Pau-Chen Cheng, Pankaj Rohatgi |
| 2008 | Localization of credential information to address increasingly inevitable data breaches. | Mohammad Mannan, Paul C. van Oorschot |
| 2008 | Choose the red pill | Ben Laurie, Abe Singer |
| 2008 | Security compliance: the next frontier in security research. | Klaus Julisch |
| 2008 | A profitless endeavor: phishing as tragedy of the commons. | Cormac Herley, Dinei A. F. Florncio |
| 2008 | Towards an ethical code for information security? | Steven J. Greenwald, Brian D. Snow, Richard Ford, Richard Thieme |
| 2008 | The ecology of Malware. | Jedidiah R. Crandall, Roya Ensafi, Stephanie Forrest, Joshua Ladau, Bilal Shebaro |
| 2008 | We have met the enemy and he is us. | Matt Bishop, Sophie Engle, Sean Peisert, Sean Whalen, Carrie Gates |
| 2008 | The compliance budget: managing security behaviour in organisations. | Adam Beautement, Martina Angela Sasse, Mike Wonham |
| 2007 | The future of biologically-inspired security: is there anything left to learn? | Anil Somayaji, Michael E. Locasto, Jan Feyereisl |
| 2007 | Robustly secure computer systems: a new security paradigm of system discontinuity. | Jon A. Solworth |