As mobile networks evolve towards 6G, they are becoming more distributed, more open and more connected to the world around us. Edge devices – such as smartphones, IoT sensors, connected vehicles and local computing nodes, will play a crucial role in delivering low-latency services for smart cities, industry, healthcare, entertainment and other fields. However, this growing “edge” of the network also introduces new security challenges.
PoC#9 focuses on one of the most serious and well-known cyber threats – that of Distributed Denial of Service (DDoS) attacks, specifically those launched from compromised edge devices – also referred to as X-Edge devices.
Why DDoS Attacks are Changing in 6G Networks
A DDoS attack works by overwhelming parts of a network with excessive traffic, making services slow, unreliable, or completely unavailable for legitimate users. In earlier network generations, these attacks often originated outside the network. In 5G and beyond, the situation is far more complex.
In modern mobile networks, devices at the edge of the network are already authenticated and trusted by the network. If such devices are compromised or misused, they can generate malicious traffic from inside the system. This makes attacks harder to detect and block – especially when many devices act together while appearing to behave normally.
PoC#9 addresses this challenge by studying how DDoS attacks can originate from large numbers of edge devices and how future networks can detect and respond to them effectively.
What will PoC#9 Demonstrate?
The PoC will explore a realistic scenario where compromised edge devices generate large volumes of traffic aimed at critical network components. These devices may:
- Send sudden traffic bursts,
- Repeatedly reconnect to the network,
- Generate abnormal service requests.
Such behaviour can overload essential network functions responsible for handling user data and mobility. This can result in slow internet access, dropped connections, or complete service outages for everyday users.
PoC#9 will demonstrate how these attacks impact both:
- The user plane, which carries data such as video streams or web traffic,
- The control plane, which manages network access, mobility and session setup.
Detecting Abnormal Behaviour Early
A key aspect of PoC#9 is showing how abnormal behaviour can be detected early, before a DDoS attack causes major disruption. The PoC uses advanced network analytics that continuously monitor how devices behave. In addition to looking for known attack signatures, the system also observes for patterns such as:
- Unusual traffic volumes,
- Unexpected mobility behaviour (such as frequent cell switching),
- Sudden spikes in signalling activity.
By analysing these indicators across many devices at once, the network can identify suspicious groups of devices rather than treating each one in isolation.
From Detection to Response
Detection alone is not enough. PoC#9 will also demonstrate how the network can dynamically respond to an attack – once it is identified.
Depending on the nature and severity of the threat, mitigation actions include:
- Limiting traffic rates from suspicious devices,
- Isolating compromised edge nodes,
- Protecting key network interfaces from overload,
- Continuously monitoring whether countermeasures are effective.
It is important to take into account that these actions are designed to minimise disruption for legitimate users while containing the attack.
Why this Matters
As 6G networks move towards highly distributed architectures with massive numbers of connected devices, DDoS attacks from the edge are likely to become more frequent and more complex. PoC#9 will show how combining continuous monitoring, intelligent analytics and automated response mechanisms can help future networks remain resilient.
By addressing DDoS threats at the edge, MARE contributes to building more reliable, trustworthy and secure mobile networks, capable of supporting the critical digital services that society will increasingly depend on.

