| 2000 | Is Electronic Privacy Achievable? | Cynthia E. Irvine, Timothy E. Levin |
| 2000 | Using Conservation of Flow as a Security Mechanism in Network Protocols. | John R. Hughes, Tuomas Aura, Matt Bishop |
| 2000 | Access Control Meets Public Key Infrastructure, Or: Assigning Roles to Strangers. | Amir Herzberg, Yosi Mass, Joris Mihaeli, Dalit Naor, Yiftach Ravid |
| 2000 | Authentication Tests. | Joshua D. Guttman, F. Javier Thayer |
| 2000 | LOMAC: Low Water-Mark Integrity Protection for COTS Environments. | Timothy Fraser |
| 2000 | IRM Enforcement of Java Stack Inspection. | lfar Erlingsson, Fred B. Schneider |
| 2000 | A More Efficient Use of Delta-CRLs. | David A. Cooper |
| 2000 | Searching for a Solution: Engineering Tradeoffs and the Evolution of Provably Secure Protocols. | John A. Clark, Jeremy L. Jacob |
| 2000 | A Security Infrastructure for Distributed Java Applications. | Dirk Balfanz, Drew Dean, Mike Spreitzer |
| 2000 | Privacy Technology Lessons from Healthcare. | Ross J. Anderson |
| 1999 | A User-Centered, Modular Authorization Service Built on an RBAC Foundation. | Mary Ellen Zurko, Richard T. Simon, Tom Sanfilippo |
| 1999 | How Computers Will Be Used Differently in the Next Twenty Years. | Mark D. Weiser |
| 1999 | Detecting Intrusions using System Calls: Alternative Data Models. | Christina Warrender, Stephanie Forrest, Barak A. Pearlmutter |
| 1999 | The Future Is Not Assured - But It Should Be. | Brian D. Snow |
| 1999 | Software Technology of the Future. | Howard E. Shrobe |
| 1999 | A Test for Non-Disclosure in Security Level Translations. | David Rosenthal, Francis Fung |
| 1999 | Twenty Year Time Capsule Panel: The Future of Networking. | Hilarie K. Orman |
| 1999 | The Hardware Environment. | Roger M. Needham |
| 1999 | 20 Years of Covert Channel Modeling and Analysis. | Jonathan K. Millen |
| 1999 | Local Reconfiguration Policies. | Jonathan K. Millen |
| 1999 | Analysis of the Internet Key Exchange Protocol using the NRL Protocol Analyzer. | Catherine Meadows |
| 1999 | Twenty Years of Formal Methods. | John McLean |
| 1999 | Twenty Years of Evaluation Criteria and Commercial Technology. | Steven B. Lipner |
| 1999 | Detecting Computer and Network Misuse through the Production-based Expert System Toolset (P-BEST). | Ulf Lindqvist, Phillip A. Porras |
| 1999 | A Data Mining Framework for Building Intrusion Detection Models. | Wenke Lee, Salvatore J. Stolfo, Kui W. Mok |