| 1997 | Security in Innovative New Operating Systems. | Cynthia E. Irvine |
| 1997 | Catalytic Inference Analysis: Detecting Inference Threats due to Knowledge Discovery. | John Hale, Sujeet Shenoi |
| 1997 | Filtering Postures: Local Enforcement for Global Policies. | Joshua D. Guttman |
| 1997 | Access Control for the SPIN Extensible Operating System. | Robert Grimm, Brian N. Bershad |
| 1997 | Providing flexibility in information flow control for object oriented systems. | Elena Ferrari, Pierangela Samarati, Elisa Bertino, Sushil Jajodia |
| 1997 | An MBone Proxy for an Application Gateway Firewall. | Kelly Djahandari, Daniel F. Sterne |
| 1997 | Analyzing Consistency of Security Policies. | Laurence Cholvy, Frdric Cuppens |
| 1997 | Some weaknesses of the TCB model. | Bob Blakley, Darrell M. Kienzle |
| 1997 | A Secure and Reliable Bootstrap Architecture. | William A. Arbaugh, David J. Farber, Jonathan M. Smith |
| 1997 | Surviving information warfare attacks on databases. | Paul Ammann, Sushil Jajodia, Catherine D. McCollum, Barbara T. Blaustein |
| 1996 | A Fair Non-repudiation Protocol. | Jianying Zhou, Dieter Gollmann |
| 1996 | Cryptovirology: Extortion-Based Security Threats and Countermeasures. | Adam L. Young, Moti Yung |
| 1996 | Conference Committee. | |
| 1996 | Message from the Program Chairs. | |
| 1996 | Limitations on Design Principles for Public Key Protocols. | Paul F. Syverson |
| 1996 | Run-Time Security Evaluation (RTSE) for Distributed Applications. | Cristina Serban, Bruce M. McMillin |
| 1996 | Security Properties and CSP. | Steve A. Schneider |
| 1996 | A Communication Agreement Framework for Access/Action Control. | Martin Rscheisen, Terry Winograd |
| 1996 | View-Based Access Control with High Assurance. | Xiaolei Qian |
| 1996 | An Analysis of the Timed Z-channel. | Ira S. Moskowitz, Steven J. Greenwald, Myong H. Kang |
| 1996 | On two Proposals for On-line Bankcard Payments using Open Networks: Problems and Solutions. | Wenbo Mao |
| 1996 | Goals for Computer Security Education. | Cynthia E. Irvine |
| 1996 | What do We Mean by Entity Authentication? | Dieter Gollmann |
| 1996 | A Sense of Self for Unix Processes. | Stephanie Forrest, Steven A. Hofmeyr, Anil Somayaji, Thomas A. Longstaff |
| 1996 | A Security Model of Dynamic Labeling Providing a Tiered Approach to Verification. | Simon N. Foley, Li Gong, Xiaolei Qian |