| 2004 | Anomalous Payload-Based Network Intrusion Detection. Ke Wang, Salvatore J. Stolfo |
| 2004 | Anomaly Detection Using Layered Networks Based on Eigen Co-occurrence Matrix. Mizuki Oka, Yoshihiro Oyama, Hirotake Abe, Kazuhiko Kato |
| 2004 | Attack Analysis and Detection for Ad Hoc Routing Protocols. Yi-an Huang, Wenke Lee |
| 2004 | Automatic Extraction of Accurate Application-Specific Sandboxing Policy. Lap-Chung Lam, Tzi-cker Chiueh |
| 2004 | Context Sensitive Anomaly Monitoring of Process Control Flow to Detect Mimicry Attacks and Impossible Paths. Haizhi Xu, Wenliang Du, Steve J. Chapin |
| 2004 | Detecting Unknown Massive Mailing Viruses Using Proactive Methods. Ruiqi Hu, Aloysius K. Mok |
| 2004 | Detection of Interactive Stepping Stones: Algorithms and Confidence Bounds. Avrim Blum, Dawn Xiaodong Song, Shobha Venkataraman |
| 2004 | Fast Detection of Scanning Worm Infections. Stuart E. Schechter, Jaeyeon Jung, Arthur W. Berger |
| 2004 | Formal Reasoning About Intrusion Detection Systems. Tao Song, Calvin Ko, Jim Alves-Foss, Cui Zhang, Karl N. Levitt |
| 2004 | HoneyStat: Local Worm Detection Using Honeypots. David Dagon, Xinzhou Qin, Guofei Gu, Wenke Lee, Julian B. Grizzard, John G. Levine, Henry L. Owen |
| 2004 | Monitoring IDS Background Noise Using EWMA Control Charts and Alert Information. Jouni Viinikka, Hervé Debar |
| 2004 | On the Design and Use of Internet Sinks for Network Abuse Monitoring. Vinod Yegneswaran, Paul Barford, David Plonka |
| 2004 | Recent Advances in Intrusion Detection: 7th International Symposium, RAID 2004, Sophia Antipolis, France, September 15-17, 2004. Proceedings Erland Jonsson, Alfonso Valdes, Magnus Almgren |
| 2004 | RheoStat: Real-Time Risk Management. Ashish Gehani, Gershon Kedem |
| 2004 | Seurat: A Pointillist Approach to Anomaly Detection. Yinglian Xie, Hyang-Ah Kim, David R. O'Hallaron, Michael K. Reiter, Hui Zhang |
| 2004 | Symantec Deception Server Experience with a Commercial Deception System. Brian Hernacki, Jeremy Bennett, Thomas Lofgren |
| 2004 | Using Adaptive Alert Classification to Reduce False Positives in Intrusion Detection. Tadeusz Pietraszek |