| 2007 | Position: the user is the enemy. | Vidyaraman Sankaranarayanan, Madhusudhanan Chandrasekaran, Shambhu J. Upadhyaya |
| 2007 | VideoTicket: detecting identity fraud attempts via audiovisual certificates and signatures. | Deholo Nali, Paul C. van Oorschot, Andy Adler |
| 2007 | Security and usability: the gap in real-world online banking. | Mohammad Mannan, Paul C. van Oorschot |
| 2007 | Self-healing: science, engineering, and fiction. | Michael E. Locasto |
| 2007 | Computing under occupation. | Klaus Kursawe, Stefan Katzenbeisser |
| 2007 | A privacy expectations and security assurance offer system. | Jeffrey Hunker |
| 2007 | Security automation considered harmful? | W. Keith Edwards, Erika Shehan Poole, Jennifer Stoll |
| 2007 | Authenticated names. | Stanley Chow, Christophe Gustave, Dmitri Vinokurov |
| 2007 | Information protection via environmental data tethers. | Matt Beaumont-Gay, Kevin Eustice, Peter L. Reiher |
| 2006 | Diffusion and graph spectral methods for network forensic analysis. | Wei Wang, Thomas E. Daniels |
| 2006 | Large-scale collection and sanitization of network security data: risks and challenges. | Phillip A. Porras, Vitaly Shmatikov |
| 2006 | Inconsistency in deception for defense. | Vicentiu Neagoe, Matt Bishop |
| 2006 | Dark application communities. | Michael E. Locasto, Angelos Stavrou, Angelos D. Keromytis |
| 2006 | PKI design for the real world. | Peter Gutmann |
| 2006 | E-Prime for security: a new security paradigm. | Steven J. Greenwald |
| 2006 | Challenging the anomaly detection paradigm: a provocative discussion. | Carrie Gates, Carol Taylor |
| 2006 | Cent, five cent, ten cent, dollar: hitting botnets where it | Richard Ford, Sarah Gordon |
| 2006 | Sanitization models and their limitations. | Rick Crawford, Matt Bishop, Bhume Bhumiratana, Lisa Clark, Karl N. Levitt |
| 2006 | Googling considered harmful. | Gregory J. Conti |
| 2006 | A pact with the devil. | Mike Bond, George Danezis |
| 2005 | Pass-thoughts: authenticating with our minds. | Julie Thorpe, Paul C. van Oorschot, Anil Somayaji |
| 2005 | Diversity as a computer defense mechanism. | Carol Taylor, Jim Alves-Foss |
| 2005 | Diversity: the biological perspective position statement. | Carol Taylor |
| 2005 | Position paper. | Irene Schwarting |
| 2005 | Average case vs. worst case: margins of safety in system design. | Christian W. Probst, Andreas Gal, Michael Franz |