| 2010 | ConScript: Specifying and Enforcing Fine-Grained Security Policies for JavaScript in the Browser. | Leo A. Meyerovich, V. Benjamin Livshits |
| 2010 | TrustVisor: Efficient TCB Reduction and Attestation. | Jonathan M. McCune, Yanlin Li, Ning Qu, Zongwei Zhou, Anupam Datta, Virgil D. Gligor, Adrian Perrig |
| 2010 | Crossing the "Valley of Death": Transitioning Research into Commercial Products - A Personal Perspective. | W. Douglas Maughan |
| 2010 | Object Capabilities and Isolation of Untrusted Web Applications. | Sergio Maffeis, John C. Mitchell, Ankur Taly |
| 2010 | Authenticating Primary Users' Signals in Cognitive Radio Networks via Integrated Cryptographic and Wireless Link Signatures. | Yao Liu, Peng Ning, Huaiyu Dai |
| 2010 | Revocation Systems with Very Small Private Keys. | Allison B. Lewko, Amit Sahai, Brent Waters |
| 2010 | History of US Government Investments in Cybersecurity Research: A Personal Perspective. | Carl E. Landwehr |
| 2010 | Experimental Security Analysis of a Modern Automobile. | Karl Koscher, Alexei Czeskis, Franziska Roesner, Shwetak N. Patel, Tadayoshi Kohno, Stephen Checkoway, Damon McCoy, Brian Kantor, Danny Anderson, Hovav Shacham, Stefan Savage |
| 2010 | Inspector Gadget: Automated Extraction of Proprietary Gadgets from Malware Binaries. | Clemens Kolbitsch, Thorsten Holz, Christopher Kruegel, Engin Kirda |
| 2010 | Overcoming an Untrusted Computing Base: Detecting and Removing Malicious Hardware Automatically. | Matthew Hicks, Murph Finnicum, Samuel T. King, Milo M. K. Martin, Jonathan M. Smith |
| 2010 | Reconciling Belief and Vulnerability in Information Flow. | Sardaouna Hamadou, Vladimiro Sassone, Catuscia Palamidessi |
| 2010 | A Proof-Carrying File System. | Deepak Garg, Frank Pfenning |
| 2010 | Synthesizing Near-Optimal Malware Specifications from Suspicious Behaviors. | Matt Fredrikson, Somesh Jha, Mihai Christodorescu, Reiner Sailer, Xifeng Yan |
| 2010 | Scalable Parametric Verification of Secure Systems: How to Verify Reference Monitors without Worrying about Data Structure Size. | Jason Franklin, Sagar Chaki, Anupam Datta, Arvind Seshadri |
| 2010 | Noninterference through Secure Multi-execution. | Dominique Devriese, Frank Piessens |
| 2010 | Identifying Dormant Functionality in Malware Programs. | Paolo Milani Comparetti, Guido Salvaneschi, Engin Kirda, Clemens Kolbitsch, Christopher Kruegel, Stefano Zanero |
| 2010 | Side-Channel Leaks in Web Applications: A Reality Today, a Challenge Tomorrow. | Shuo Chen, Rui Wang, XiaoFeng Wang, Kehuan Zhang |
| 2010 | Round-Efficient Broadcast Authentication Protocols for Fixed Topology Classes. | Haowen Chan, Adrian Perrig |
| 2010 | How Good Are Humans at Solving CAPTCHAs? A Large Scale Evaluation. | Elie Bursztein, Steven Bethard, Celine Fabry, John C. Mitchell, Daniel Jurafsky |
| 2010 | State of the Art: Automated Black-Box Web Application Vulnerability Testing. | Jason Bau, Elie Bursztein, Divij Gupta, John C. Mitchell |
| 2009 | DSybil: Optimal Sybil-Resistance for Recommendation Systems. | Haifeng Yu, Chenwei Shi, Michael Kaminsky, Phillip B. Gibbons, Feng Xiao |
| 2009 | Native Client: A Sandbox for Portable, Untrusted x86 Native Code. | Bennet Yee, David Sehr, Gregory Dardyk, J. Bradley Chen, Robert Muth, Tavis Ormandy, Shiki Okasaka, Neha Narula, Nicholas Fullagar |
| 2009 | Password Cracking Using Probabilistic Context-Free Grammars. | Matt Weir, Sudhir Aggarwal, Breno de Medeiros, Bill Glodek |
| 2009 | Privacy Weaknesses in Biometric Sketches. | Koen Simoens, Pim Tuyls, Bart Preneel |
| 2009 | Automatic Reverse Engineering of Malware Emulators. | Monirul Islam Sharif, Andrea Lanzi, Jonathon T. Giffin, Wenke Lee |