From Detection to Prediction: How MARE Responds to 6G Security Threats

Understanding a 6G network is only the first step. Once visibility is established, the next challenge is deciding how to react, and to do so in a rapid, intelligent and safe manner.

In this blog entry, we will explore how the MARE Security Plane:

  • Detects threats as they occur,
  • Predicts potential risks before they take place,
  • Tests security responses before they are deployed in real environments.


Together, these capabilities enable a proactive and adaptive approach to 6G security.

Threat detection: Spotting problems as they happen

A threat detection workflow focuses on identifying what is happening right now in the network.

As data flows across devices, cloud resources, edge nodes and AI-driven systems, the Security Plane continuously analyses signals, logs and various behavioural patterns. This can be compared to a highly trained observer watching for anything unusual.

The detection process:

  • Gathers monitored data from various devices from across the network,
  • Analyses it using modular security tools,
  • Checks whether behaviour resembles known attacks or anomalies,
  • Activates appropriate Security Functions when a threat is confirmed.

This allows MARE to react immediately, without waiting for manual intervention. This is a very important capability in 6G environments where attack windows can be extremely short.

Threat prediction: Anticipating what comes next

While detection is essential, MARE goes a step further by predicting what might go wrong in the near future.

A threat prediction workflow uses AI-based analysis to:

  • Study historical data and long-term trends,
  • Examine how systems have behaved over time,
  • Identify early warning signs,
  • Estimate the likelihood of future attacks or malfunctions.

 

This approach is similar to weather forecasting – instead of predicting rain, MARE predicts potential cyber threats. By anticipating risk, the system can prepare countermeasures in advance and in some cases prevent incidents entirely.

PASTE: Testing security responses safely

Before deploying security actions in a real 6G environment, MARE validates them in a dedicated pre-assessment and testing environment, known as PASTE.

PASTE combines:

  • Simulation tools,
  • Emulation platforms,
  • Realistic testbeds – including digital twins.

This environment allows the project to safely explore scenarios that would be too risky to test in live networks. For example:

  • How a misbehaving AI model might affect network decisions,
  • How quickly a Security Function can respond to a denial-of-service attempt,
  • How vulnerabilities emerge under specific configurations.

 

By testing detection, prediction and response mechanisms in advance, MARE ensures that its security solutions are robust and reliable before real-world deployment.

From insight to action

Together, detection, prediction and pre-assessment transform network insight into effective protection. These capabilities enable MARE to move beyond reactive security and towards a proactive, intelligent and trustworthy security approach for future 6G networks.

In the next blog, we will introduce the MARE Proof-of-Concept scenarios, which will show how these capabilities can be validated in practice against concrete 6G threats.