| 1999 | Network Security: Then and Now, or, 20 Years in 10 Minutes. | Stephen T. Kent |
| 1999 | Verification of Control Flow based Security Properties. | Thomas P. Jensen, Daniel Le Mtayer, Tommy Thorn |
| 1999 | A Multi-Threading Architecture for Multilevel Secure Transaction Processing. | Haruna R. Isa, William R. Shockley, Cynthia E. Irvine |
| 1999 | Software Smart Cards via Cryptographic Camouflage. | Douglas N. Hoover, B. N. Kausik |
| 1999 | 20 Years of Operating Systems Security. | Virgil D. Gligor |
| 1999 | Hardening COTS Software with Generic Software Wrappers. | Timothy Fraser, Lee Badger, Mark Feldman |
| 1999 | Flexible Policy-Directed Code Safety. | David E. Evans, Andrew Twyman |
| 1999 | Specification and Enforcement of Classification and Inference Constraints. | Steven Dawson, Sabrina De Capitani di Vimercati, Pierangela Samarati |
| 1999 | Twenty Years of Cryptography in the Open Literature. | G. R. Blakley |
| 1999 | Firmato: A Novel Firewall Management Toolkit. | Yair Bartal, Alain J. Mayer, Kobbi Nissim, Avishai Wool |
| 1999 | Secure Communications Processing for Distributed Languages. | Martn Abadi, Cdric Fournet, Georges Gonthier |
| 1998 | Understanding Java Stack Inspection. | Dan S. Wallach, Edward W. Felten |
| 1998 | Timing Attacks Against Trusted Path. | Jonathan T. Trostle |
| 1998 | Strand Spaces: Why is a Security Protocol Correct? | F. Javier Thayer, Jonathan C. Herzog, Joshua D. Guttman |
| 1998 | Partial Security Policies to Support Timeliness in Secure Real-Time Databases. | Sang Hyuk Son, Craig Chaney, Norris P. Thomlinson |
| 1998 | Towards Mobile Cryptography. | Tomas Sander, Christian F. Tschudin |
| 1998 | Complete, Safe Information Flow with Decentralized Labels. | Andrew C. Myers, Barbara Liskov |
| 1998 | Necessity and Realization of Universally Verifiable Secret Sharing. | Wenbo Mao |
| 1998 | Secure Execution of Java Applets using a Remote Playground. | Dahlia Malkhi, Michael K. Reiter, Aviel D. Rubin |
| 1998 | Composing Partially-Specified Systems. | Heather M. Hinton |
| 1998 | Access Control in an Open Distributed Environment. | Richard Hayton, Jean Bacon, Ken Moody |
| 1998 | On the Formal Definition of Separation-of-Duty Policies and their Composition. | Virgil D. Gligor, Serban I. Gavrila, David F. Ferraiolo |
| 1998 | An Automated Approach for Identifying Potential Vulnerabilities in Software. | Anup K. Ghosh, Tom O'Connor, Gary McGraw |
| 1998 | Ensuring Continuity During Dynamic Security Policy Reconfiguration in DTE. | Timothy Fraser, Lee Badger |
| 1998 | Stack and Queue Integrity on Hostile Platforms. | Premkumar T. Devanbu, Stuart G. Stubblebine |