ECYSAP EYE: From Cyber Situational Awareness to Mission-Centric Decision Support for Enhanced Cyberspace Operations

📅 2026-06-10
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
This work addresses the limitations of traditional cyber situational awareness approaches, which predominantly focus on technical alerts and lack mission-oriented decision support, thereby struggling to integrate into diverse operational and security workflows. To bridge this gap, the paper proposes a mission-centric System-of-Systems (SoS) architecture that establishes a closed-loop framework comprising seven types of mission-driven artifacts—including a common cyber situational picture, situational reports, What-If analyses, and action recommendations—thereby seamlessly connecting perception, decision-making, execution, and learning. The proposed approach facilitates integration with heterogeneous toolchains and supports incremental deployment, enabling seamless embedding into existing cybersecurity processes and significantly enhancing the effectiveness of situational understanding in supporting mission planning and execution.
📝 Abstract
Operational organizations increasingly require Cyber Situational Awareness (CySA) capabilities that go beyond isolated technical alerts, providing mission-relevant artefacts that can be embedded into heterogeneous toolchains and cyber security or cyber defense processes. ECYSAP EYE addresses this need through an adoption-oriented System-of-Systems (SoS) architecture centered on seven groups of mission-focused artefacts: the Recognized Cyberspace Picture (RCyP), Cyber Situational Reports (CySRs), the What-If Analysis Report (WIAR), Option Recommendations (OPRE), an operator Dashboard/HMI (DSH), Action Enforcement (AE), and After-Action Reports (AAR). The ECYSAP EYE architecture structures the transition from perception (full-spectrum RCyP views), to decision-oriented reasoning (WIAR/CySRs/OPRE), and to operational execution and learning (DSH/AE/AAR), with explicit integration surfaces that support incremental deployment and validation. This paper presents this innovative project from a technology transfer perspective, summarizing the updated architecture, the functional role of seven groups of artefacts, and the expected impact of cyber situations on the decision-making process in the context of a mission planning and execution.
Problem

Research questions and friction points this paper is trying to address.

Cyber Situational Awareness
Mission-Centric Decision Support
Cyberspace Operations
System-of-Systems
Decision-Making Process
Innovation

Methods, ideas, or system contributions that make the work stand out.

Cyber Situational Awareness
Mission-Centric Decision Support
System-of-Systems Architecture
Recognized Cyberspace Picture
What-If Analysis
🔎 Similar Papers
No similar papers found.
Pantaleone Nespoli
Pantaleone Nespoli
University of Murcia
CybersecurityCyber RangeIntrusion Detection and Response SystemSecurity Chaos Engineering
Daniel Díaz-López
Daniel Díaz-López
Assistant Professor, Universidad del Rosario
CybersecurityThreat intelligencePentestingAIBlockchain
S
Sergio Lopez Bernal
Departamento de Ingeniería de la Información y las Comunicaciones, Universidad de Murcia, 30100 Murcia, Spain
F
Francisco Oliva Bermejo
Indra Sistemas S.A., Av. de Bruselas 35, 28108, Madrid, Spain
P
Pedro González Megías
Indra Sistemas S.A., Av. de Bruselas 35, 28108, Madrid, Spain
Jorge Maestre Vidal
Jorge Maestre Vidal
Indra, Digital Labs
Artificial IntelligenceCommunication NetworksCyber DefenceInformation Security
V
Víctor Sobrino García
Universidad Politécnica de Madrid, Campus de Montegancedo, 28660 Boadilla del Monte, Madrid, Spain
G
Gregorio Martínez Pérez
Departamento de Ingeniería de la Información y las Comunicaciones, Universidad de Murcia, 30100 Murcia, Spain