ECYSAP EYE: From Cyber Situational Awareness to Mission-Centric Decision Support for Enhanced Cyberspace Operations
ECYSAP EYE:从网络态势感知到以任务为中心的决策支持,增强网络空间行动
Pantaleone Nespoli, Daniel Díaz-López, Sergio Lopez Bernal, Francisco Oliva Bermejo, Pedro González Megías, Jorge Maestre Vidal, Víctor Sobrino García, Gregorio Martínez Pérez
AI总结 提出ECYSAP EYE系统之系统架构,通过七类任务相关制品(如RCyP、CySRs等)实现从感知到决策再到执行的过渡,支持增量部署与验证,提升网络空间任务规划与执行中的态势感知与决策支持能力。
详情
- Comments
- 4 pages, 1 figure, 1 table, paper in proceedings of the XI National Cybersecurity Research Conference (JNIC) in Barcelona, Spain, May, 2026
运营组织越来越需要超越孤立技术警报的网络态势感知(CySA)能力,提供可嵌入异构工具链和网络安全或网络防御流程的任务相关制品。ECYSAP EYE通过一种面向采用的系统之系统(SoS)架构满足这一需求,该架构围绕七组以任务为中心的制品:识别网络空间图(RCyP)、网络态势报告(CySRs)、假设分析报告(WIAR)、选项建议(OPRE)、操作员仪表板/人机界面(DSH)、行动执行(AE)和事后报告(AAR)。ECYSAP EYE架构构建了从感知(全频谱RCyP视图)到面向决策的推理(WIAR/CySRs/OPRE),再到操作执行和学习(DSH/AE/AAR)的过渡,具有支持增量部署和验证的明确集成面。本文从技术转移角度介绍这一创新项目,总结了更新后的架构、七组制品的功能角色,以及在任务规划与执行背景下网络态势对决策过程的预期影响。
Operational organizations increasingly require Cyber Situational Awareness (CySA) capabilities that go beyond isolated technical alerts, providing mission-relevant artefacts that can be embedded into heterogeneous toolchains and cyber security or cyber defense processes. ECYSAP EYE addresses this need through an adoption-oriented System-of-Systems (SoS) architecture centered on seven groups of mission-focused artefacts: the Recognized Cyberspace Picture (RCyP), Cyber Situational Reports (CySRs), the What-If Analysis Report (WIAR), Option Recommendations (OPRE), an operator Dashboard/HMI (DSH), Action Enforcement (AE), and After-Action Reports (AAR). The ECYSAP EYE architecture structures the transition from perception (full-spectrum RCyP views), to decision-oriented reasoning (WIAR/CySRs/OPRE), and to operational execution and learning (DSH/AE/AAR), with explicit integration surfaces that support incremental deployment and validation. This paper presents this innovative project from a technology transfer perspective, summarizing the updated architecture, the functional role of seven groups of artefacts, and the expected impact of cyber situations on the decision-making process in the context of a mission planning and execution.