PRISM

The Workshop on Attack Provenance, Reasoning, and Investigation for Security in the Monitored Environment (PRISM) invites researchers and practitioners to submit original research papers. PRISM emphasizes holistic reasoning and human-centered after-the-fact investigation. Its mission is to catalyze a shift in the security community: from fragmented, alert-centric detection toward causal, explainable, and analyst-friendly approaches that capture the complexity of modern cyber attacks. By integrating provenance research with advances in AI, systems design, and human factors, the workshop aims to establish a new foundation for how defenders understand and respond to sophisticated threats, leading to a safer and trustworthy cyberspace ultimately.

P

Events

PRISM 2026

by Internet Society (NDSS Symposium)

Cybersecurity

The first Workshop on Attack Provenance, Reasoning, and Investigation for Security in the Monitored Environment (PRISM), co-located with NDSS 2026. The workshop solicits regular and work-in-progress papers on topics including provenance graphs, causal inference, learning models for detection and investigation, systems for provenance analytics, cross-domain correlation, human factors, modern deployments, case studies, log capture and integrity, adversarial attacks on provenance-aware systems, real-time pipelines, explainability, datasets and benchmarks, standards and interoperability, and privacy/governance for provenance data. The workshop also includes tutorials emphasizing live demonstrations of real systems for attack provenance, investigation, and reasoning.

Feb 23, 2026
attack provenance
causal inference
provenance graphs
+2