The MARE consortium was hosted by its partner CeADAR, University College Dublin on 16–17 June 2026 for its General Assembly, which brought together project partners to review progress, align technical priorities and prepare the next phase of activities toward secure, resilient and trustworthy 6G networks. The meeting provided an opportunity to assess achievements from the first half of the project, discuss integration progress across work packages and review upcoming milestones. During the meeting, partners presented updates on the evolution of the MARE Security Plane, including architectural refinements, workflows, attack-surface modelling, telemetry, orchestration, and pre-assessment capabilities. Discussions also covered the continued definition of Security Functions and DOTs, which form the building blocks of MARE’s programmable and modular approach to security. A major focus of the General Assembly was the project’s technical progress across its thematic areas and proof-of-concept activities. These included work on threats to consider, AI and data analytics, network exposure APIs, along with the corresponding security functions, detection approaches, and validation KPIs to address them. The consortium also reviewed progress on the implementation and integration of the MARE framework. This included updates on the joint software repository, the integration matrix for architectural components, the formalization of DOT and Security Function data models and the continued work needed to ensure interoperable APIs and compatibility with MARE’s automation and orchestration processes. Another key topic was the advancement of MARE’s validation ecosystem through PASTE, the Testing Environment Manager, and the Pre-Assessment and Validation framework. Partners discussed how simulation environments, Network Digital Twins, and infrastructure testbeds are being used to assess mitigation strategies before deployment, helping ensure that security responses are effective, policy-compliant and suitable for real operational conditions. The General Assembley meeting also highlighted the role of ASPO, MARE’s Adaptive Security and Privacy Orchestration component, which supports the selection of mitigation strategies, playbook generation and coordination with Security Function composition and validation workflows. These capabilities are central to MARE’s goal of enabling intelligent, automated and context-aware security management for future 6G systems. Looking ahead, the consortium agreed on the next technical and reporting actions for the months ahead, including contributions to deliverables, refinement of threat models and workflows, and preparation for the project review process scheduled for September 2026. The meeting in Dublin reaffirmed the consortium’s shared commitment to delivering an open, programmable and trustworthy security framework for next-generation mobile networks.
MARE Showcases its Programmable 6G Security Plane at the 2026 EuCNC & 6G Summit
Málaga – Spain, June 2-5 2026 The MARE project, a flagship European initiative under the Smart Networks and Services Joint Undertaking (SNS JU), successfully presented its latest advancements and activities in 6G security, with a project booth, workshops participation and poster presentation at the prestigious EuCNC & 6G Summit 2026 in Málaga. As the 6G landscape evolves toward a “network of networks,” the MARE project aims at demonstrating how its novel and programmable Security Plane – presented at the booth with a poster, can be used to address the expanded attack surface of future 6G ecosystems. MARE PoCs and Publications At the booth, the 11 MARE Proof of Concepts were presented, with posters describing the scope of each one, and videos detailing their technical progress. The 9 MARE publications were also presented, each one with a poster describing the research carried out. Further to these, the 1st MARE White paper – providing a good description of the project, was published during EuCNC. Details of these PoCs can be found on the MARE website: https://mare6g.eu/pocs/ Full details of the MARE publications including the 1st MARE White paper can be found here: https://mare6g.eu/publications/ MARE Proof of Concepts MARE Publications Throughout the summit, MARE experts were present at the booth to provide more details about the project and highlight how its programmable, modular and disaggregated security plane can reinforce Europe’s leadership in trustworthy next-generation connectivity. EuCNC Workshops and Poster Session The MARE Technical coordinator – Xavi Masip from Universitat Politècnica de Catalunya, also represented the project at two key workshops of the conference: Workshop: Advancing Network Digital Twins (NDTs) for AI-driven 6G systems: Insights, applications, and cross-project synergies Where he presented MARE’s key focus on “Using an NDT-based Sandbox for incidents and remediation actions analysis and pre-assessment” Wokshop: Is there anything new on Security for 6G Networks? Where he presented MARE’s innovative strategy of “Softwarizing security provisioning in 6G ecosystems” In the Second Poster session on Thursday 4 June 2026, Marla Grunewald from Technische Univeristät Braunschweig, Germany, presented the poster entitled ”Enhancing Secure Intent-Based Networking with an Agentic AI: The EU Project MARE Approach” This poster – along with its abstract, can be found with the other MARE posters published so far in the following link: https://mare6g.eu/posters/ MARE Posters MARE SNS Award! A key highlight of MARE’s participation at 2026 EuCNC & 6G Summit was its recognition by the SNS JU and the award it received as one of 10 6G SNS Most inspiring 6G Use Cases. With this award, we would like to thank the SNS JU and emphasize our commitment to developing our MARE research and innovations to the benefit of the European 6G SNS ecosystem and community. Thank you Malaga and see you all at 2027 EuCNC & 6G Summit in Dublin!
Mirroring the Future: How AI is Creating Safe Playgrounds for 6G Networks
Have you ever wondered how engineers test defenses against massive cyberattacks without accidentally taking down the real networks we rely on every day? As 5G and the emerging 6G networks evolve into the critical, AI-native backbone of our digital infrastructure, they are growing incredibly complex. Consequently, the risk and financial cost of testing new orchestration policies or security mechanisms directly on live, functioning systems have become prohibitive. To solve this, researchers are turning to “Network Digital Twins” (NDTs), which are virtual replicas that mirror the behavior of real networks, providing a risk-free sandbox for vital experiments without touching production. Moving Beyond Rough Sketches While the concept of a digital twin isn’t entirely new, earlier versions have often acted like rough sketches. Current solutions frequently focus on general, coarse performance predictions rather than accurately replicating the chaotic, high-fidelity reality of dynamic traffic patterns. A newly published breakthrough is changing that landscape entirely. Researchers have developed an advanced, AI-native Network Digital Twin engine based on a “Graph Transformer” and designed to deeply analyze and reconstruct the intricate, second-by-second spatio-temporal dynamics of 5G traffic. Instead of just estimating how a network might behave, this AI meticulously learns the underlying statistical structure and natural rhythms of benign, everyday activities -such as streaming a video, and contrasts them with the aggressive, overwhelming data floods typical of a Distributed Denial-of-Service (DDoS) cyberattack. Unprecedented Accuracy in Simulation The results of this new approach are genuinely groundbreaking. In rigorous experimental tests using comprehensive telemetry from a real 5G testbed, this AI model achieved an astounding accuracy score of over 98% (with R-squared scores up to 0.9839) in replicating network traffic. It significantly outperformed older, traditional AI baselines, like Long Short-Term Memory (LSTM) networks, proving its unique ability to perfectly mimic the heartbeat of a real network. When the digital twin simulates an attack, it accurately reproduces the exact data spikes, bottlenecks and signal drops that would occur in reality, preserving the underlying probability distributions and variance of real-world telemetry. A Risk-Free Future for Cybersecurity The true novelty of this work lies in this unprecedented level of fidelity. It creates a reusable, secure testing environment capable of generating realistic network traffic traces entirely on demand, without needing access to an actual live network’s measurements. This innovation represents a massive leap forward for European cybersecurity research, directly supporting the advanced objectives of collaborative efforts like the MARE project. By providing a genuinely risk-free, highly accurate virtual replica, this digital twin empowers researchers and engineers to safely evaluate robust mitigation strategies, performance and control policies. Ultimately, this foundational work ensures that as we move into the hyper-connected era of 6G, our critical digital ecosystems will remain remarkably resilient and secure. Publication Details Conformal Prediction and Risk-Based Optimization of Service Continuity in 6G Edge Networks Authors: Athina Vekraki, Maria Christopoulou, Ioannis Vasalos, Michail Alexandros Kourtis, Athanasia Alonisioti, George Xilouris MARE Partner: National Centre For Scientific Research Demokritos (NCSRD) Publication: Abstract: As 5G and emerging 6G networks evolve into highly complex, AI-native infrastructures, the risk and cost of testing new orchestration policies or security mechanisms on live systems become prohibitive. Network Digital Twins (NDTs) have emerged as a critical paradigm for providing risk-free virtual replicas; however, current solutions often focus on coarse performance prediction rather than the high-fidelity replication of dynamic traffic patterns. In this paper, we present an AI-native NDT engine based on Graph Transformers designed to reconstruct the intricate spatio-temporal dynamics of 5G traffic. Using a comprehensive dataset from an Amarisoft-based testbed, we model network telemetry as a k-hop temporal line graph to capture the underlying statistical structure and bitrate oscillations of individual User Equipments (UEs) across both benign streaming and Distributed Denial-of-Service (DDoS) traffic regimes. Experimental results demonstrate that our Graph Transformer architecture achieves high-fidelity reconstruction with R^2 scores up to 0.9839, significantly outperforming traditional Long Short-Term Memory (LSTM) baselines. Furthermore, strong alignment in Cumulative Distribution Function (CDF) analysis confirms the model’s ability to preserve the underlying probability distributions and variance of real-world telemetry. This work provides a foundation for high-fidelity traffic synthesis and reproducible security analysis in future 6G ecosystems.
Securing Tomorrow’s Connected World: The HORSE and MARE Vision for 6G
Imagine a world where your mobile internet is fast enough to download an entire high-definition movie in a fraction of a second, where driverless cars communicate with traffic lights flawlessly and where complex remote surgeries happen smoothly across continents. This is the incredible promise of 6G, the next generation of wireless technology. However, as our physical and digital worlds become deeply intertwined, the networks we rely on become prime targets for sophisticated cyberattacks. Traditional security measures, which were designed for older generations of technology, simply will not be able to keep pace with the massive scale and complexity of 6G. To address this urgent challenge, an international team of expert researchers from Italy, Spain and Greece has proposed a groundbreaking solution. In their newly published paper, they unveil the collaborative vision of two pioneering initiatives supported by The European Smart Networks and Services Joint Undertaking (SNS JU) – the HORSE and MARE projects. Their goal is to completely reinvent how we protect mobile networks, shifting from rigid, old-school defense methods to a dynamic system built specifically for the 6G era. The Innovation: Shifting to Programmable Security The core innovation of this research lies in a concept known as “programmable security”. Traditionally, network security operated much like a physical brick wall – static, rigid and incredibly difficult to alter once built. If an entirely new type of cyber threat emerged, modifying that wall took significant time, leaving the network temporarily exposed. The HORSE and MARE projects replace this outdated wall with a smart, software-driven shield. This digital shield can automatically reshape, reprogram and upgrade itself in real-time to neutralize emerging threats the moment they appear. A Global Digital Bodyguard to Protect our Daily Lives What makes this work uniquely novel is the introduction of a dedicated “security plane” within the 6G network architecture. Think of this as an autonomous digital bodyguard focused entirely on network safety. Instead of individual applications or devices scrambling to defend themselves, this centralized bodyguard monitors the entire system. Furthermore, because future networks will span multiple global operators and service providers, this framework is built to operate transparently across different organizational boundaries. It allows diverse stakeholders to share threat intelligence and deploy defenses seamlessly without compromising user privacy or network performance. Why this is Essential Why does this matter to the general public? In the near future, 6G will power critical infrastructure, including automated hospitals, smart energy grids and emergency response systems. A security breach in a 6G network won’t just mean a leaked password. It could disrupt vital real-world services. By making security proactive, adaptable and deeply embedded into the network’s DNA, the HORSE and MARE projects ensure that our hyper-connected future remains safe, resilient and trustworthy for everyone. Thanks to this pioneering research, the invisible infrastructure supporting our daily lives will be ready to defend itself against the threats of tomorrow. Publication Details Programmable Security for 6G Mobile Networks: The vision of HORSE and MARE projects Authors: Fabrizio Granelli, Eva Rodriguez, Xavier Masip-Bruin, Ioannis Vasalos, George Xilouris MARE Partners: Consorzio Nazionale Interuniversitario per le Telecomunicazioni (CNIT) Universitat Politècnica de Catalunya (UPC) National Centre For Scientific Research Demokritos (NCSRD) Publication: Abstract: In 6G, effective protection mechanisms must be inherently cross-layer and adaptive. In this context, the HORSE and MARE projects align with this vision by proposing an adaptable and extensible approach based on a 6G service provisioning platform. This approach introduces a novel security plane built upon a well-defined set of open and programmable security functions, delivered as enablers within the 6G architecture. It operates transparently across multi-domain and multistakeholder environments, while efficiently handling emerging threats. As such, it enables the dynamic orchestration of security strategies to efficiently address novel and evolving attacks.
Securing the Future: How Virtual Clones Are Protecting 5G and 6G Networks
As we transition into the era of ultra-fast 5G and emerging 6G technologies, our world is becoming more connected than ever. From smart factories to autonomous cars, next-generation mobile networks are the invisible backbone of modern life. However, this massive expansion comes with a major catch! It creates a much larger target for cybercriminals. Among the most dangerous threats are Distributed Denial of Service (DDoS) attacks, which overwhelm networks with massive floods of fake traffic to crash vital services. Defending against these attacks is traditionally tricky. Testing defense systems on live networks is incredibly risky because a false alarm or a heavy security test could accidentally shut down services for real users. On the other hand, training artificial intelligence (AI) to spot these threats usually relies on outdated or unrealistic data. Enter the “Network Digital Twin” To solve this dilemma, a team of researchers from the National Centre for Scientific Research “DEMOKRITOS” in Greece has developed a groundbreaking solution. They created a Network Digital Twin (NDT) – a perfect, real-time virtual clone of a physical mobile network. Think of it as an advanced digital flight simulator for cybersecurity. This virtual sandbox mirrors the exact layout, behavior and traffic patterns of the real network. Because it is completely separated from actual users, researchers can safely unleash severe cyberattacks inside the digital clone to see exactly how the network reacts, entirely risk-free. How the Breakthrough Works Using this virtual clone, the team simulated two destructive types of traffic-flooding attacks – one targeting connection backlogs and the other targeting data routing paths. They used the rich data generated by these safe simulations to train an advanced AI model. Because the digital twin is continuously synchronized with a real-world network, the AI learned from highly realistic, up-to-date information rather than old, synthetic datasets. Once the AI was fully trained in the virtual world, the researchers deployed it onto a real, physical 5G network testbed. The results were spectacular: The AI successfully detected and classified the cyberattacks with an astonishing 99% accuracy rate. Why this work Matters The novelty and importance of this research lie in its proactive, zero-risk approach to digital safety: Zero-Risk Testing: Security teams can safely emulate cutting-edge cyber threats without any risk of disrupting live, everyday communication services. Hyper-Realistic AI Training: By using a twin that dynamically updates alongside the real network, the AI is trained on incredibly accurate data, making it far more robust against evolving tactics. Bridging Virtual and Real Worlds: The study proves that an AI trained entirely in a digital sandbox can seamlessly step into the real world to protect physical infrastructure. By creating a safe, highly accurate environment to train the digital guardians of tomorrow, this research marks a massive step forward in ensuring our future 6G world remains safe, stable and uninterrupted. Publication Details Cyber defense framework for 5G/6G using a Network Digital Twin Authors: Ioannis Vasalos, Efstathios Zaragkas, Athina Vekraki, Maria Christopoulou, Michail Alexandros Kourtis, George Xilouris, Nikos Dimitriou MARE Partner: National Centre For Scientific Research Demokritos (NCSRD) Publication: Abstract: With the rapid evolution of 5G and emerging 6G networks, ensuring security against DDoS threats remains a pressing challenge, particularly due to expanded attack surfaces across the edge–cloud continuum and heterogeneous edge devices. Traditional security mechanisms struggle to provide proactive, scalable, and low-risk detection and classification solutions in such highly dynamic environments. This paper proposes a Network Digital Twin (NDT)–driven framework for DDoS detection, analysis, and classification in 5G/6G networks, leveraging a synchronized digital twin for safe attack emulation and AI/ML-based anomaly detection. We implement and validate the framework on a real 5G testbed combined with an operational NDT platform, demonstrating that the NDT accurately reproduces network behavior under both normal and attack conditions and validating its efficacy for DT-driven, adaptive security in next-generation mobile systems.
Staying One Step Ahead: How Smart Risk-Awareness Will Secure Seamless 6G Networks
Future 6G networks should not only react after connections degrade, they should anticipate risk before service is interrupted. Have you ever been on an important video call or playing an online game while traveling, only for the connection to suddenly freeze or drop? As we move toward ultra-fast 6G wireless technology, keeping mobile applications running smoothly while users move across changing network zones remains a major challenge. One reason for these interruptions is that many current network decisions rely on a single estimate of future performance. When the network decides whether to keep a user connected to the current local server or move them to another one, that decision may be based on one predicted value. If this prediction is too optimistic, or if a short burst of interference occurs, the system may react too early, too late, or trigger unnecessary server changes. This can lead to avoidable signaling, degraded performance, or temporary service disruption. Researchers from Technische Universität Braunschweig propose a new risk-aware approach to this problem. Instead of relying only on a single prediction, the framework estimates a range of possible future network speeds and calculates a calibrated probability that the connection may fall below the required service level. This allows the network to make decisions with a clearer understanding of uncertainty. A simple way to think about it is a weather forecast. A basic forecast might say, “Tomorrow will be sunny.” A more useful forecast says, “The temperature will likely be between 20 and 24 degrees, with a 30% chance of rain.” In the same way, the proposed system does not only ask, “How fast will the connection be?” It also asks, “How confident are we, and how likely is a slowdown?” Using this information, the network’s optimizer can decide whether to keep the current connection, switch to a better local server, or avoid risky choices that may soon degrade. The goal is to maintain smooth service while avoiding unnecessary server switching. A key strength of the work is that it is designed to fit within existing 3GPP and ETSI MEC standards. The controller can run as an edge application and use existing mechanisms for network information, policy control, traffic steering, and application mobility. This makes the approach more practical for future deployment. The evaluation shows that the risk-aware controller achieves higher expected throughput than a controller based only on single-value predictions. It also gives network operators a tuning knob to balance speed and reliability. As 6G networks become more dynamic, this work shows that service continuity should not depend only on reacting after problems occur. By considering uncertainty and risk before making decisions, future networks can become more stable, adaptive, and reliable for users. Publication Details Conformal Prediction and Risk-Based Optimization of Service Continuity in 6G Edge Networks Authors: Zied Ennaceur, Admela Jukan MARE Partner: Technische Universität Braunschweig (TUBS) Publication: IEEE International Conference on Communications (ICC) , Glasgow, Scotland, UK, 24–28 May 2026. Conference website. Abstract: We study the problem of service continuity in 6G networks and propose a solution aligned with current mobile network standards that integrates conformal prediction and risk-aware throughput estimation to anticipate short-term degradations and, in addition, to optimize application and session continuity during network topology changes. Our pipeline combines throughput prediction over short horizons with calibration based on split conformal prediction to produce sharp intervals with coverage guarantees, and a throughput degradations estimator that provides the probability that throughput falls below the SLA threshold on each link. A risk-aware optimizer then selects associations that balance expected throughput, reliability, and continuity. Experiments on emulated mobile network traces demonstrate that the performance improves by incorporating uncertainty and calibrated risk estimation. Experiments on emulated mobile network traces demonstrate that the degradation risk model is well calibrated with a Brier score of 0.095, an Expected Calibration Error of 0.068, and a PR–AUC of 0.810, and that incorporating uncertainty and calibrated risk improves control decisions. The risk-aware controller consistently attains higher expected throughput than the commonly used point-estimate baseline at matched reassociation rates, and it can identify network operating regimes with low SLA degradation, e.g., 7.9% violations at 999 Mb expected throughput for ε = 0.40. DOI: https://doi.org/10.5281/zenodo.19095625 Access Publication
Security Sharing in a Network of Networks: PoC#11 in the MARE Project
Future digital services will not rely on a single, isolated network. Instead, 6G ecosystems will consist of many interconnected networks operated by different stakeholders – such as mobile operators, cloud providers, edge platforms, private enterprise networks and vertical industries. Together, these form what is often referred to as a “Network of Networks”. While this interconnection enables powerful new services and seamless connectivity, it also introduces significant security challenges. A weakness in one network can quickly affect others and isolated security mechanisms are no longer sufficient. PoC#11 will addresses this challenge by exploring how security information can be safely and effectively shared across multiple interconnected networks. Why Security Sharing is Essential in 6G In today’s networks, security monitoring and incident response are often handled within a single administrative domain. In future 6G environments, this approach becomes inadequate. Services may span several networks and attacks can propagate across network boundaries. For example, a threat detected in one operator’s network may be relevant to neighbouring networks or partner infrastructures. If this information is not shared in a timely and trustworthy manner, other networks will remain vulnerable. PoC#11 addresses this issue by exploring mechanisms that allow collaboration between networks, without compromising autonomy, privacy, or commercial boundaries. What does “Security Sharing” mean? Security sharing does not mean giving full access to internal systems. Instead, PoC#11 focuses on controlled exchange of relevant security insights, such as: Indicators of malicious activity, Threat alerts, Risk assessments, High-level situational awareness. The goal is to ensure that networks can learn from each other’s observations, improving collective resilience while maintaining local control. Challenges of Sharing Security Information Sharing security data across networks is not trivial. Different networks may use different technologies, policies and security tools. There are also concerns related to: Data confidentiality, Trust between stakeholders, Liability and responsibility, Compliance with regulations. PoC#11 will explore how these challenges can be addressed by defining clear interfaces, policies and trust models that regulate what information is shared, with whom and under what conditions. What PoC#11 will Demonstrate PoC#11 will demonstrate how security-related information can be exchanged between networks in a structured and controlled way. Instead of just raw data, networks can share processed and meaningful security signals that can be acted upon without revealing sensitive internal details. By correlating shared information with local observations, each network will be able to gain a more complete picture of ongoing threats. This will enable earlier detection of coordinated or large-scale attacks that might otherwise go unnoticed when networks operate in isolation. Supporting Coordinated Responses Another key aspect of PoC#11 is showing how shared security insights can support coordinated responses. When multiple networks are affected by similar threats, aligned mitigation actions can reduce overall impact and prevent attackers from simply moving from one network to another. Importantly, PoC#11 does not assume centralised control. Each network remains responsible for its own decisions, while benefiting from shared awareness and collective intelligence. Why this Matters for Future Services Many future services enabled by 6G – such as cross-border connectivity, smart transportation systems, industrial automation and emergency communications, depend on multiple networks working together seamlessly. Security weaknesses in any part of this chain can undermine service reliability and user trust. PoC#11 shows how security sharing can become a foundational capability for such services, enabling cooperation without sacrificing independence. A key Building block for Trustworthy 6G Ecosystems Within the MARE project, PoC#11 will highlight the importance of moving beyond siloed security approaches. By enabling networks to share relevant security information responsibly, it supports the creation of resilient, trustworthy and cooperative 6G ecosystems. As networks become more interconnected, security can no longer be addressed alone. PoC#11 demonstrates how collaboration, supported by clear governance and intelligent mechanisms, will be essential for protecting the digital infrastructure of the future.
Secure Exposure of Network Capabilities in Future 6G Networks: PoC#10 in the MARE Project
Modern mobile networks are no longer closed systems used only for connectivity. In 5G and future 6G networks, operators increasingly expose selected network capabilities to external applications through standardised APIs (Application Programming Interfaces). This openness enables innovation to occur – applications can request network information, optimise performance, support smart mobility, or deliver new digital services specifically designed twardso user needs. However, opening up network capabilities also introduces new security and privacy risks. PoC#10 focuses on understanding these risks and demonstrating how future networks can expose capabilities securely, without compromising trust, reliability, or user data. Why Network Exposure Matters Network capability exposure allows third-party developers, vertical industries and service providers to interact directly with the network. For example, an application may request information about network conditions, subscribe to performance events, or trigger specific network behaviours. This creates exciting and innovative opportunities, however, it also increases the attack surface of the network. APIs become new entry points that attackers may exploit if these are not properly protected. PoC#10 investigates how these risks can be addressed in a structured and automated way. Key Threats Addressed in PoC#10 PoC#10 focuses on several realistic threat scenarios that arise when network capabilities are exposed. These include: Sensitive data leakage, where poorly protected APIs accidentally reveal confidential information such as subscriber data, network configurations, or operational logs. Unauthorised access, where attackers attempt to use exposed interfaces without proper permissions. Privilege escalation, where an application gains access to capabilities beyond what it is allowed to use. API abuse, including excessive or malicious requests that may disrupt network operations. These threats are particularly critical in future 6G environments, where networks are more dynamic, cloud-native and distributed across central and edge infrastructures. What PoC#10 will Demonstrate PoC#10 will demonstrate how exposed network capabilities can be protected through continuous monitoring, strong access control and intelligent analysis. Instead of relying on static rules alone, the PoC will show how network interactions can be observed in real time. Telemetry data, access logs and configuration changes can be continuously collected and analysed to identify suspicious behaviour early. This allows the network to detect misuse before it escalates into a serious incident. A key aspect of PoC#10 is enforcing who can access what and under which conditions. Applications and users will be authenticated and authorised using established identity and access management mechanisms. Communication with exposed APIs will be protected through encryption, ensuring that data cannot be easily intercepted or manipulated. Seeing the Network as a Whole One of the challenges in securing exposed network capabilities is understanding how different components, interfaces and services are connected. PoC#10 considers this, by correlating data from multiple sources and building a unified view of network interactions. By linking operational data, access policies and runtime behaviour, the system can identify inconsistencies, misconfigurations, or unexpected access patterns. This makes it easier to spot issues such as legacy interfaces that should no longer be exposed, or applications using capabilities in unexpected ways. Responding to Threats Automatically Detection by its own is not sufficient in highly dynamic networks. PoC#10 will also demonstrate how automated responses can be triggered when a security issue is identified. Depending on the situation, the network may: Restrict or revoke access to certain APIs, Enforce stricter policies, Generate alerts for operators, Adjust exposure rules dynamically. These actions will help protect against security incidents, containing them quickly and reducing the risk of service disruption or data leakage. Why this is Important for the Future As 6G networks become platforms for digital innovation, secure exposure of network capabilities will be essential. Without proper safeguards, openness could undermine trust in the network and limit adoption by industries and public services. PoC#10 will demonstrate how MARE contributes to building secure, transparent and controllable network exposure mechanisms. By combining monitoring, policy enforcement and intelligent analytics, future networks can remain open to innovation while staying resilient against misuse and attacks.
Defending future Networks from DDoS Attacks at the Edge: PoC#9 in the MARE Project
As mobile networks evolve towards 6G, they are becoming more distributed, more open and more connected to the world around us. Edge devices – such as smartphones, IoT sensors, connected vehicles and local computing nodes, will play a crucial role in delivering low-latency services for smart cities, industry, healthcare, entertainment and other fields. However, this growing “edge” of the network also introduces new security challenges. PoC#9 focuses on one of the most serious and well-known cyber threats – that of Distributed Denial of Service (DDoS) attacks, specifically those launched from compromised edge devices – also referred to as X-Edge devices. Why DDoS Attacks are Changing in 6G Networks A DDoS attack works by overwhelming parts of a network with excessive traffic, making services slow, unreliable, or completely unavailable for legitimate users. In earlier network generations, these attacks often originated outside the network. In 5G and beyond, the situation is far more complex. In modern mobile networks, devices at the edge of the network are already authenticated and trusted by the network. If such devices are compromised or misused, they can generate malicious traffic from inside the system. This makes attacks harder to detect and block – especially when many devices act together while appearing to behave normally. PoC#9 addresses this challenge by studying how DDoS attacks can originate from large numbers of edge devices and how future networks can detect and respond to them effectively. What will PoC#9 Demonstrate? The PoC will explore a realistic scenario where compromised edge devices generate large volumes of traffic aimed at critical network components. These devices may: Send sudden traffic bursts, Repeatedly reconnect to the network, Generate abnormal service requests. Such behaviour can overload essential network functions responsible for handling user data and mobility. This can result in slow internet access, dropped connections, or complete service outages for everyday users. PoC#9 will demonstrate how these attacks impact both: The user plane, which carries data such as video streams or web traffic, The control plane, which manages network access, mobility and session setup. Detecting Abnormal Behaviour Early A key aspect of PoC#9 is showing how abnormal behaviour can be detected early, before a DDoS attack causes major disruption. The PoC uses advanced network analytics that continuously monitor how devices behave. In addition to looking for known attack signatures, the system also observes for patterns such as: Unusual traffic volumes, Unexpected mobility behaviour (such as frequent cell switching), Sudden spikes in signalling activity. By analysing these indicators across many devices at once, the network can identify suspicious groups of devices rather than treating each one in isolation. From Detection to Response Detection alone is not enough. PoC#9 will also demonstrate how the network can dynamically respond to an attack – once it is identified. Depending on the nature and severity of the threat, mitigation actions include: Limiting traffic rates from suspicious devices, Isolating compromised edge nodes, Protecting key network interfaces from overload, Continuously monitoring whether countermeasures are effective. It is important to take into account that these actions are designed to minimise disruption for legitimate users while containing the attack. Why this Matters As 6G networks move towards highly distributed architectures with massive numbers of connected devices, DDoS attacks from the edge are likely to become more frequent and more complex. PoC#9 will show how combining continuous monitoring, intelligent analytics and automated response mechanisms can help future networks remain resilient. By addressing DDoS threats at the edge, MARE contributes to building more reliable, trustworthy and secure mobile networks, capable of supporting the critical digital services that society will increasingly depend on.
Double Identity – Defending the 6G Digital Twin from Cyber Attacks: PoC#8 in the MARE Project
The concept of a “Digital Twin” is rapidly becoming one of the most transformative technologies in the 6G era. By creating a real-time, virtual replica of a physical network, operators can test updates, predict failures and optimize performance without ever risking disruption to the actual service. It is the ultimate sandbox – a safe environment where the future can be rehearsed. But what if the sandbox itself becomes a trap? This is the important question addressed by Proof of Concept 8 (PoC#8) within the MARE project, titled “SNDT: Secure Network Digital Twin”. While Digital Twins are designed to protect the physical network from operational risks, PoC#8 investigates a new frontier of cyber threats: Attacks that target the Digital Twin itself to blind, mislead, or compromise the physical infrastructure it mirrors. The Risk: When the Mirror Lies A Network Digital Twin (NDT) relies on a constant, two-way stream of data. It ingests real-time telemetry from the physical network to stay accurate, and it sends configuration commands back to the physical network based on its simulations. This close synchronization between the two systems creates a unique vulnerability. If an attacker can compromise the Digital Twin, they don’t need to hack the physical network directly. They can launch a “man-in-the-middle” attack on the synchronization link, injecting false data to make the physical network look healthy when it is failing, or vice versa. Even more dangerously, they could manipulate the Digital Twin’s simulation logic, causing it to recommend harmful configuration changes – like turning off security protocols or overloading a server, which the physical network then executes. In this scenario, the Digital Twin evolves from a helpful tool into a “Trojan Horse” that carries out the attacker’s will. How PoC#8 Secures the Virtual Replica PoC#8 is developing a specialized security shield for this precise problem. It treats the Digital Twin as critical infrastructure that requires its own dedicated defense system. The solution will use MARE’s modular architecture to build a resilient synchronization channel between the physical and virtual worlds. Key innovations include: Synchronization Integrity Checks: The system will continuously monitor the data flowing between the physical network and its Digital Twin. Using advanced cryptographic verification, it will ensure that the telemetry feeding the Digital Twin has not been tampered with and that the commands coming back are authentic. Behavioral Anomaly Detection: By using AI-driven analysis, PoC#8 will be able to detect when the Digital Twin is behaving “out of character.” If the Digital Twin suddenly suggests a configuration change that contradicts historical safety patterns or physical reality, the system flags it as a potential compromise. Isolation Protocols: If a threat is detected, the PoC demonstrates how to instantly sever the control link. This “kill switch” will ensure that a compromised Digital Twin is cut off before it can push malicious commands to the live network, containing the damage to the virtual realm. Why this matters for 6G As we move toward Zero-Touch Service Management, where networks run themselves with minimal human oversight, the Digital Twin will be the brain behind many automated decisions. PoC#8 is vital because it ensures that this brain remains sane and secure. By validating the integrity of the Digital Twin, MARE is enabling operators to use this powerful technology with confidence. It guarantees that the Digital Twin remains what it was always meant to be – a safe simulation tool for innovation and network management, not a backdoor for destruction. Through PoC#8, MARE is proving that we can secure both the physical networks of the future, and the virtual worlds that will guide them.

