Use this before writing. ACM CCS is the SIGSAC flagship: it rewards work with a concrete attacker, a defensible threat model, and evidence that survives an adversarial program committee. Decide venue by community and contribution type, never by prestige ranking.
| Signal in the project | CCS reading |
|---|---|
| New attack with a clearly bounded adversary and demonstrated impact | Core fit — the house genre |
| Defense evaluated against adaptive attacks with deployment cost | Core fit |
| Applied crypto protocol with implementation and measured overhead | Core fit |
| Internet-scale or ecosystem measurement with validated sampling | Core fit |
| Pure cryptographic hardness proof, no system | CRYPTO/EUROCRYPT or a theory venue |
| Privacy-first metrics with no other security property | PETS/PoPETs |
A project extracts keys from a deployed TLS library via a microarchitectural side channel, with a proof-of-concept exploit and a constant-time patch. CCS reading: strong fit — a concrete attacker, measured leakage, and a defense with overhead numbers is exactly the CCS arc. Strip the exploit and keep only an abstract leakage bound, and it drifts toward a crypto theory venue; expand the network-measurement of vulnerable hosts into the whole story, and NDSS becomes plausible; foreground only the privacy harm to users, and PETS fits better.
[Fit] strong CCS / possible CCS / better elsewhere
[Best venue] CCS / IEEE S&P / USENIX Security / NDSS / PETS / crypto venue / other
[Contribution type] attack / defense / protocol / measurement / tool / study
[Threat model in one line] <adversary capability and goal>
[Top rejection risk] <threat-model / novelty / evidence / ethics / scope>
[Next action] <sharpen threat model, add evidence, reframe, or switch venue>