The Workshop on Attack Provenance, Reasoning, and Investigation for Security in the Monitored Environment (PRISM) invites researchers and practitioners to submit original research papers. PRISM emphasizes holistic reasoning and human-centered after-the-fact investigation. Its mission is to catalyze a shift in the security community: from fragmented, alert-centric detection toward causal, explainable, and analyst-friendly approaches that capture the complexity of modern cyber attacks. By integrating provenance research with advances in AI, systems design, and human factors, the workshop aims to establish a new foundation for how defenders understand and respond to sophisticated threats, leading to a safer and trustworthy cyberspace ultimately.
by Internet Society (NDSS Symposium)
The first Workshop on Attack Provenance, Reasoning, and Investigation for Security in the Monitored Environment (PRISM), co-located with NDSS 2026. The workshop solicits regular and work-in-progress papers on topics including provenance graphs, causal inference, learning models for detection and investigation, systems for provenance analytics, cross-domain correlation, human factors, modern deployments, case studies, log capture and integrity, adversarial attacks on provenance-aware systems, real-time pipelines, explainability, datasets and benchmarks, standards and interoperability, and privacy/governance for provenance data. The workshop also includes tutorials emphasizing live demonstrations of real systems for attack provenance, investigation, and reasoning.