Check out these security experts and their sites/papers.

Peter G. Neumann
http://www.csl.sri.com/users/neumann/neumann.html

Gene Spafford
http://www.cerias.purdue.edu/homes/spaf/

Dave Dittrich
http://www.washington.edu/People/dad/

Dan Farmer
http://www.cerias.purdue.edu/coast/a.../author16.html