跳到主要内容
知仓学习社ZHICANG

ccs-topic-selection

Use when deciding whether a security project fits ACM CCS versus IEEE S&P, USENIX Security, NDSS, PETS, or a crypto/theory venue, identifying the se…

不碰外部(只输出文字)无严重或高危命中brycewang-stanford/Awesome-Journal-Skills

它会碰到什么

扫了多少1 个文本文件,4 KB
它会碰到什么不碰外部(只输出文字)
命中总数0 处
命中统计严重 0 · 高 0 · 中 0 · 低 0

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

CCS Topic Selection

Use this before writing. ACM CCS is the SIGSAC flagship: it rewards work with a concrete

attacker, a defensible threat model, and evidence that survives an adversarial program

committee. Decide venue by community and contribution type, never by prestige ranking.

Fit test

  • Prefer CCS when the contribution is a broad computer-security result — a new attack class,

a defense with measured cost, an applied-cryptography protocol, a systems or web-security

mechanism, or a measurement study — aimed at the cross-area SIGSAC community.

  • Route to IEEE S&P (Oakland) when the work suits that PC's taste for foundational or

systematization framing and the November cycle fits your calendar better.

  • Route to USENIX Security when the contribution is artifact-heavy systems security whose

evidence lives in a runnable tool and open benchmark.

  • Route to NDSS when the core is network- and distributed-system security (protocols, DNS,

routing, malware infrastructure).

  • Route to PETS/PoPETs when privacy is the primary lens rather than one property among many.
  • Route to CRYPTO/EUROCRYPT when the contribution is cryptographic theory whose proof, not

its deployment, is the result.

Fit signal table

| Signal in the project | CCS reading |

|---|---|

| New attack with a clearly bounded adversary and demonstrated impact | Core fit — the house genre |

| Defense evaluated against adaptive attacks with deployment cost | Core fit |

| Applied crypto protocol with implementation and measured overhead | Core fit |

| Internet-scale or ecosystem measurement with validated sampling | Core fit |

| Pure cryptographic hardness proof, no system | CRYPTO/EUROCRYPT or a theory venue |

| Privacy-first metrics with no other security property | PETS/PoPETs |

Vignette: where a side-channel result goes

A project extracts keys from a deployed TLS library via a microarchitectural side channel,

with a proof-of-concept exploit and a constant-time patch. CCS reading: strong fit — a

concrete attacker, measured leakage, and a defense with overhead numbers is exactly the CCS

arc. Strip the exploit and keep only an abstract leakage bound, and it drifts toward a crypto

theory venue; expand the network-measurement of vulnerable hosts into the whole story, and

NDSS becomes plausible; foreground only the privacy harm to users, and PETS fits better.

Sharpening moves before committing

  • Name the attacker: capabilities, knowledge, position, and what success means. If you cannot

write the threat model in three sentences, the contribution is not yet CCS-shaped.

  • Decide the contribution type — attack, defense, protocol, measurement, tool, or study —

because reviewers grade each against a different evidence bar.

  • Confirm the result fits the 12-page ACM sigconf body; CCS bodies are dense, and a paper

needing 30 pages of proofs may belong at a journal or a theory venue.

  • Scope drifts across cycles; scan the current CFP topic list and recent proceedings before

final routing.

Output format

[Fit] strong CCS / possible CCS / better elsewhere
[Best venue] CCS / IEEE S&P / USENIX Security / NDSS / PETS / crypto venue / other
[Contribution type] attack / defense / protocol / measurement / tool / study
[Threat model in one line] <adversary capability and goal>
[Top rejection risk] <threat-model / novelty / evidence / ethics / scope>
[Next action] <sharpen threat model, add evidence, reframe, or switch venue>

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。