Understanding a 6G network is only the first step. Once visibility is established, the next challenge is deciding how to react, and to do so in a rapid, intelligent and safe manner.
In this blog entry, we will explore how the MARE Security Plane:
- Detects threats as they occur,
- Predicts potential risks before they take place,
- Tests security responses before they are deployed in real environments.
Together, these capabilities enable a proactive and adaptive approach to 6G security.
Threat detection: Spotting problems as they happen
A threat detection workflow focuses on identifying what is happening right now in the network.
As data flows across devices, cloud resources, edge nodes and AI-driven systems, the Security Plane continuously analyses signals, logs and various behavioural patterns. This can be compared to a highly trained observer watching for anything unusual.
The detection process:
- Gathers monitored data from various devices from across the network,
- Analyses it using modular security tools,
- Checks whether behaviour resembles known attacks or anomalies,
- Activates appropriate Security Functions when a threat is confirmed.
This allows MARE to react immediately, without waiting for manual intervention. This is a very important capability in 6G environments where attack windows can be extremely short.
Threat prediction: Anticipating what comes next
While detection is essential, MARE goes a step further by predicting what might go wrong in the near future.
A threat prediction workflow uses AI-based analysis to:
- Study historical data and long-term trends,
- Examine how systems have behaved over time,
- Identify early warning signs,
- Estimate the likelihood of future attacks or malfunctions.
This approach is similar to weather forecasting – instead of predicting rain, MARE predicts potential cyber threats. By anticipating risk, the system can prepare countermeasures in advance and in some cases prevent incidents entirely.
PASTE: Testing security responses safely
Before deploying security actions in a real 6G environment, MARE validates them in a dedicated pre-assessment and testing environment, known as PASTE.
PASTE combines:
- Simulation tools,
- Emulation platforms,
- Realistic testbeds – including digital twins.
This environment allows the project to safely explore scenarios that would be too risky to test in live networks. For example:
- How a misbehaving AI model might affect network decisions,
- How quickly a Security Function can respond to a denial-of-service attempt,
- How vulnerabilities emerge under specific configurations.
By testing detection, prediction and response mechanisms in advance, MARE ensures that its security solutions are robust and reliable before real-world deployment.
From insight to action
Together, detection, prediction and pre-assessment transform network insight into effective protection. These capabilities enable MARE to move beyond reactive security and towards a proactive, intelligent and trustworthy security approach for future 6G networks.
In the next blog, we will introduce the MARE Proof-of-Concept scenarios, which will show how these capabilities can be validated in practice against concrete 6G threats.

