| 2002 | Evaluation of the Diagnostic Capabilities of Commercial Intrusion Detection Systems. | Herv Debar, Benjamin Morin |
| 2002 | Detecting Malicious Software by Monitoring Anomalous Windows Registry Accesses. | Frank Apap, Andrew Honig, Shlomo Hershkop, Eleazar Eskin, Salvatore J. Stolfo |
| 2001 | CDIS: Towards a Computer Immune System for Detecting Network Intrusions. | Paul D. Williams, Kevin P. Anchor, John L. Bebo, Gregg H. Gunsch, Gary B. Lamont |
| 2001 | Interfacing Trusted Applications with Intrusion Detection Systems. | Marc G. Welz, Andrew Hutchison |
| 2001 | Designing a Web of Highly-Configurable Intrusion Detection Sensors. | Giovanni Vigna, Richard A. Kemmerer, Per Blix |
| 2001 | Probabilistic Alert Correlation. | Alfonso Valdes, Keith Skinner |
| 2001 | Experiences with Specification-Based Intrusion Detection. | Prem Uppuluri, R. Sekar |
| 2001 | Autonomic Response to Distributed Denial of Service Attacks. | Daniel F. Sterne, Kelly Djahandari, Brett Wilson, Bill Babson, Dan Schnackenberg, Harley Holliday, Travis Reid |
| 2001 | From Declarative Signatures to Misuse IDS. | Jean-Philippe Pouzol, Mireille Ducass |
| 2001 | System Health and Intrusion Monitoring Using a Hierarchy of Constraints. | Calvin Ko, Paul Brutch, Jeff Rowe, Guy Tsafnat, Karl N. Levitt |
| 2001 | The Impact of Privacy and Data Protection Legislation on the Sharing of Intrusion Detection Information. | Steven R. Johnston |
| 2001 | Aggregation and Correlation of Intrusion-Detection Alerts. | Herv Debar, Andreas Wespi |
| 2001 | Accurately Detecting Source Code of Attacks That Increase Privilege. | Robert K. Cunningham, Craig S. Stevenson |
| 2001 | Application-Integrated Data Collection for Security Monitoring. | Magnus Almgren, Ulf Lindqvist |
| 2000 | Intrusion Detection Using Variable-Length Audit Trail Patterns. | Andreas Wespi, Marc Dacier, Herv Debar |
| 2000 | Adaptive, Model-Based Monitoring for Cyber Attack Detection. | Alfonso Valdes, Keith Skinner |
| 2000 | Target Naming and Service Apoptosis. | James Riordan, Dominique Alessandri |
| 2000 | Using Finite Automata to Mine Execution Data for Intrusion Detection: A Preliminary Report. | Christoph C. Michael, Anup K. Ghosh |
| 2000 | The 1998 Lincoln Laboratory IDS Evaluation. | John McHugh |
| 2000 | Flexible Intrusion Detection Using Variable-Length Behavior Modeling in Distributed Environment: Application to CORBA Objects. | Zakia Marrakchi, Ludovic M, Bernard Vivinis, Benjamin Morin |
| 2000 | Analysis and Results of the 1999 DARPA Off-Line Intrusion Detection Evaluation. | Richard Lippmann, Joshua W. Haines, David J. Fried, Jonathan Korba, Kumar Das |
| 2000 | A Data Mining and CIDF Based Approach for Detecting Novel and Distributed Intrusions. | Wenke Lee, Rahul A. Nimbalkar, Kam K. Yee, Sunil B. Patil, Pragneshkumar H. Desai, Thuan T. Tran, Salvatore J. Stolfo |
| 2000 | A Pattern Matching Based Filter for Audit Reduction and Fast Detection of Potential Intrusions. | Josu Kuri, Gonzalo Navarro, Ludovic M, Laurent Heye |
| 2000 | A Real-Time Intrusion Detection System Based on Learning Program Behavior. | Anup K. Ghosh, Christoph C. Michael, Michael Schatz |
| 2000 | Better Logging through Formality. | Chapman Flack, Mikhail J. Atallah |