Deception technologies (DTs) can strengthen Cyber Situation Awareness (CSA) by producing low-noise, high-fidelity telemetry from adversary interactions. Building on prior work on medical-device modelling, ransomware analysis, and phase-based detection structuring, we examine how DTs can be integrated into broader cyber defence ecosystems.
We synthesise five perspectives—technical, architectural, process, cognitive, and operational—and propose a Construction Model that treats deception telemetry as both a sensor input and an analytical catalyst within multi-layered monitoring. The model links DT deployments with fusion, reasoning, and feedback loops to improve visibility, correlation, and human–machine collaboration in SOC operations.
Our key contribution is a structured pathway from deception sensing to actionable CSA in adaptive, intelligence-driven defence practices.
Editors
Jouni Ihanus, Tero Kokkonen, Tommi Mikkonen
Cite as
Ihanus, J., Kokkonen, T., Mikkonen, T. Integrating Deception Technologies into Cyber Defence Ecosystems: Enhancing Cyber Situation Awareness through Multi-layered Monitoring. In: Rocha, A., Adeli, H., Moreira, F. (eds) Recent Trends and Challenges in Information Systems and Technologies. WorldCIST 2026. Lecture Notes in Networks and Systems, vol 2091. Springer, Cham. https://doi.org/10.1007/978-3-032-32029-2_5



