| 2012 | User-Driven Access Control: Rethinking Permission Granting in Modern Operating Systems. | Franziska Roesner, Tadayoshi Kohno, Alexander Moshchuk, Bryan Parno, Helen J. Wang, Crispin Cowan |
| 2012 | Off-path TCP Sequence Number Inference Attack - How Firewall Middleboxes Reduce Security. | Zhiyun Qian, Zhuoqing Morley Mao |
| 2012 | Safe Loading - A Foundation for Secure Execution of Untrusted Programs. | Mathias Payer, Tobias Hartmann, Thomas R. Gross |
| 2012 | Policy Aware Social Miner. | Sharon Paradesi, Oshani Seneviratne, Lalana Kagal |
| 2012 | Smashing the Gadgets: Hindering Return-Oriented Programming Using In-place Code Randomization. | Vasilis Pappas, Michalis Polychronakis, Angelos D. Keromytis |
| 2012 | Towards a Semantics of Phish. | Hilarie Orman |
| 2012 | A Theoretical Analysis: Physical Unclonable Functions and the Software Protection Problem. | Rishab Nithyanand, John Solis |
| 2012 | Bridging the Semantic Gap to Mitigate Kernel-Level Keyloggers. | Jess Navarro, Enrique Naudon, Daniela Oliveira |
| 2012 | On the Feasibility of Internet-Scale Author Identification. | Arvind Narayanan, Hristo S. Paskov, Neil Zhenqiang Gong, John Bethencourt, Emil Stefanov, Eui Chul Richard Shin, Dawn Song |
| 2012 | Decision Support Procedure in the Insider Threat Domain. | John P. Murphy, Vincent H. Berk, Ian D. Gregorio-De Souza |
| 2012 | A Knowledge-Based Approach to Intrusion Detection Modeling. | Sumit More, Mary Matthews, Anupam Joshi, Tim Finin |
| 2012 | Third-Party Web Tracking: Policy and Technology. | Jonathan R. Mayer, John C. Mitchell |
| 2012 | Slender PUF Protocol: A Lightweight, Robust, and Secure Authentication by Substring Matching. | Mehrdad Majzoobi, Masoud Rostami, Farinaz Koushanfar, Dan S. Wallach, Srinivas Devadas |
| 2012 | Using Consensus Clustering for Multi-view Anomaly Detection. | Alexander Y. Liu, Dung N. Lam |
| 2012 | Clash Attacks on the Verifiability of E-Voting Systems. | Ralf Ksters, Tomasz Truderung, Andreas Vogt |
| 2012 | New Results for Timing-Based Attestation. | Xeno Kovah, Corey Kallenberg, Chris Weathers, Amy L. Herzog, Matthew Albin, John Butterworth |
| 2012 | Rozzle: De-cloaking Internet Malware. | Clemens Kolbitsch, Benjamin Livshits, Benjamin G. Zorn, Christian Seifert |
| 2012 | Guess Again (and Again and Again): Measuring Password Strength by Simulating Password-Cracking Algorithms. | Patrick Gage Kelley, Saranga Komanduri, Michelle L. Mazurek, Richard Shay, Timothy Vidas, Lujo Bauer, Nicolas Christin, Lorrie Faith Cranor, Julio C. Lpez |
| 2012 | A Method for Preventing "Skipping" Attacks. | Marc Joye |
| 2012 | Semantic Comparison of Security Policies: From Access Control Policies to Flow Properties. | Mathieu Jaume |
| 2012 | ReDeBug: Finding Unpatched Code Clones in Entire OS Distributions. | Jiyong Jang, Abeer Agrawal, David Brumley |
| 2012 | Memento: Learning Secrets from Process Footprints. | Suman Jana, Vitaly Shmatikov |
| 2012 | Abusing File Processing in Malware Detectors for Fun and Profit. | Suman Jana, Vitaly Shmatikov |
| 2012 | EvilSeed: A Guided Approach to Finding Malicious Web Pages. | Luca Invernizzi, Paolo Milani Comparetti, Stefano Benvenuti, Christopher Kruegel, Marco Cova, Giovanni Vigna |
| 2012 | Quid-Pro-Quo-tocols: Strengthening Semi-honest Protocols with Dual Execution. | Yan Huang, Jonathan Katz, David Evans |