| 2003 | Characterizing the Performance of Network Intrusion Detection Sensors. | Lambert Schaelicke, Thomas Slabach, Branden J. Moore, Curt Freeland |
| 2003 | Detecting Anomalous Network Traffic with Self-organizing Maps. | Manikantan Ramadas, Shawn Ostermann, Brett C. Tjaden |
| 2003 | Statistical Causality Analysis of INFOSEC Alert Data. | Xinzhou Qin, Wenke Lee |
| 2003 | Correlation of Intrusion Symptoms: An Application of Chronicles. | Benjamin Morin, Herv Debar |
| 2003 | An Analysis of the 1999 DARPA/Lincoln Laboratory Evaluation Data for Network Anomaly Detection. | Matthew V. Mahoney, Philip K. Chan |
| 2003 | Using Decision Trees to Improve Signature-Based Intrusion Detection. | Christopher Krgel, Thomas Toth |
| 2003 | Topology-Based Detection of Anomalous BGP Messages. | Christopher Krgel, Darren Mutz, William K. Robertson, Fredrik Valeur |
| 2003 | An Approach for Detecting Self-propagating Email Using Anomaly Detection. | Ajay Gupta, R. Sekar |
| 2003 | Two Sophisticated Techniques to Improve HMM-Based Intrusion Detection Systems. | Sung-Bae Cho, Sang-Jun Han |
| 2003 | Using Specification-Based Intrusion Detection for Automated Response. | Ivan Balepin, Sergei Maltsev, Jeff Rowe, Karl N. Levitt |
| 2002 | Introducing Reference Flow Control for Detecting Intrusion Symptoms at the OS Level. | Jacob Zimmermann, Ludovic M, Christophe Bidan |
| 2002 | Detecting Long Connection Chains of Interactive Terminal Sessions. | Kwong H. Yung |
| 2002 | Accurate Buffer Overflow Detection via Abstract Payload Execution. | Thomas Toth, Christopher Krgel |
| 2002 | Undermining an Anomaly-Based Intrusion Detection System Using Common Exploits. | Kymie M. C. Tan, Kevin S. Killourhy, Roy A. Maxion |
| 2002 | A Mission-Impact-Based Approach to INFOSEC Alarm Correlation. | Phillip A. Porras, Martin W. Fong, Alfonso Valdes |
| 2002 | Analyzing Intensive Intrusion Alerts via Correlation. | Peng Ning, Yun Cui, Douglas S. Reeves |
| 2002 | M2D2: A Formal Data Model for IDS Alert Correlation. | Benjamin Morin, Ludovic M, Herv Debar, Mireille Ducass |
| 2002 | The Effect of Identifying Vulnerabilities and Patching Software on the Utility of Network Intrusion Detection. | Richard Lippmann, Seth E. Webster, Douglas Stetson |
| 2002 | Performance Adaptation in Real-Time Intrusion Detection Systems. | Wenke Lee, Joo B. D. Cabrera, Ashley Thomas, Niranjan Balwalli, Sunmeet Saluja, Yi Zhang |
| 2002 | Learning Unknown Attacks - A Start. | James E. Just, James C. Reynolds, Larry A. Clough, Melissa Danforth, Karl N. Levitt, Ryan Maglich, Jeff Rowe |
| 2002 | Development of a Legal Framework for Intrusion Detection. | Steven R. Johnston |
| 2002 | Capacity Verification for High Speed Network Intrusion Detection Systems. | Mike Hall, Kevin Wiley |
| 2002 | Attacks Against Computer Network: Formal Grammar-Based Framework and Simulation Tool. | Vladimir I. Gorodetski, Igor V. Kotenko |
| 2002 | A Stochastic Model for Intrusions. | Robert P. Goldman |
| 2002 | Multiscale Stepping-Stone Detection: Detecting Pairs of Jittered Interactive Streams by Exploiting Maximum Tolerable Delay. | David L. Donoho, Ana Georgina Flesia, Umesh Shankar, Vern Paxson, Jason Coit, Stuart Staniford |