The first Workshop on Attack Provenance, Reasoning, and Investigation for Security in the Monitored Environment (PRISM), co-located with NDSS 2026. The workshop solicits regular and work-in-progress papers on topics including provenance graphs, causal inference, learning models for detection and investigation, systems for provenance analytics, cross-domain correlation, human factors, modern deployments, case studies, log capture and integrity, adversarial attacks on provenance-aware systems, real-time pipelines, explainability, datasets and benchmarks, standards and interoperability, and privacy/governance for provenance data. The workshop also includes tutorials emphasizing live demonstrations of real systems for attack provenance, investigation, and reasoning.
The first Workshop on Attack Provenance, Reasoning, and Investigation for Security in the Monitored Environment (PRISM), co-located with NDSS 2026. The workshop solicits regular and work-in-progress papers on topics including provenance graphs, causal inference, learning models for detection and investigation, systems for provenance analytics, cross-domain correlation, human factors, modern deployments, case studies, log capture and integrity, adversarial attacks on provenance-aware systems, real-time pipelines, explainability, datasets and benchmarks, standards and interoperability, and privacy/governance for provenance data. The workshop also includes tutorials emphasizing live demonstrations of real systems for attack provenance, investigation, and reasoning.