As 6G networks evolve into highly flexible, intelligent and interconnected ecosystems, securing them becomes far more complex than anything seen in previous generations of communication technology. In earlier blog entries, we introduced the vision of MARE and the modular security building blocks that support it.
In this blog, we focus on the first essential capability of the MARE Security Plane, specifically how it observes, collects and understands what is happening across a complex 6G environment.
At the heart of this capability is monitoring, data management and abstraction – the foundation upon which intelligent security decisions are built.
Why observation is the first step in 6G security
Modern networks are no longer static infrastructures. Instead, they behave like living systems – constantly changing, interacting and adapting to user demands and digital services. In 6G, this complexity increases dramatically as networks become more open, distributed, cloud-based and increasingly driven by AI.
In such an environment, security cannot rely on partial visibility or isolated data sources. To protect a network, one must first understand it – continuously and comprehensively.
This is why MARE places strong emphasis on monitoring and data collection across the entire 6G ecosystem.
Monitoring across a highly distributed environment
In a 6G network, relevant information comes from many places including radio components, cloud and edge resources, virtualised network functions, AI engines and even digital twins used for planning and optimisation.
If each of these elements were monitored in isolation, the result would be an overwhelming and fragmented stream of raw data. MARE addresses this challenge by collecting monitoring information in a coordinated and structured way, ensuring that data from different sources can be analysed together rather than in isolation.
This not only includes traditional network metrics, but also data related to AI behaviour, configuration changes and system interactions – all of which are critical in future networks.
The Abstraction Layer: Turning data into understanding
Collecting data alone is not enough. This is where the Abstraction Layer plays a key role.
The Abstraction Layer acts as a translator and organiser between the underlying infrastructure and the MARE Security Plane. Some of the actions it carries out include:
- Gathering monitoring information from multiple sources,
- Organising it into a unified and coherent view,
- Identifying which components are exposed to potential threats,
- Mapping the network’s overall attack surface.
In doing so, it transforms a complex and heterogeneous 6G environment into something understandable and actionable.
Why attack surface mapping matters
By mapping the attack surface, the Security Plane gains critical awareness of:
- What assets are present in the network,
- Which components are more exposed or vulnerable,
- How issues in one part of the system could affect others.
This visibility is essential for intelligent security. It allows MARE to reason about risk, understand context, and support informed decision-making. Without this foundation, higher-level security functions such as detection or prediction would lack the necessary situational awareness.
Laying the groundwork for intelligent security
Monitoring, data management and abstraction form the foundation of the MARE Security Plane. They ensure that the system has a clear and continuous understanding of the network it is protecting – including traditional infrastructure and AI-driven components.
In the next blog entry, we will build on this foundation and explore how MARE uses this knowledge to detect threats, predict future risks and test its responses before deploying them in real 6G environments.

