In our previous blog posts, we made the case of why 6G networks require a fresh approach to security, and presented how the MARE project’s vision and design are setting the stage for these needed changes. Why modular security matters In this post we explore the key technical concepts driving the vision of MARE, that of modular and programmable security. This is needed for open, distributed and ultra-connected networks, as we cannot rely on a single one-size fits all protection shield. Instead, we need various and multiple building security blocks that can be combined, adapted and evolved. What are DOTs: Atomic protection tools When considering network security, we do not have a single software component labelled “SECURITY” which we can plug into our network and be protected. Instead, this is composed of many small security components which can be combined together in different ways based on network topologies, services and threats faced. In MARE, these components are known as DOTs (basic security primitives). Each DOT performs a simple, focused task such as: Detecting anomalies, Monitoring data flows, Enforcing access policies, logging suspicious events. Designing and developing each DOT reusable allows them to be combined and deployed in many different ways across a 6G network. If we want to monitor edge devices in a factory, we will use the anomaly-detection DOT. If we want to protect AI-driven services we combine relevant DOTs that together will provide this protection. The key is flexibility, given the readiness and availability of these building blocks, we are not starting from scratch when a new threat appears, instead we can readily combine relative DOTs to provide the required protection. Security Functions: Putting together DOTs DOTs alone are useful, but real protection requires orchestration. That’s where Security Functions (SFs) come in. A Security Function is a combination of DOTs, brought together to create a security service that addresses a specific security need. For example, a “Continuous Monitoring and Response” security function might combine DOTs for traffic monitoring, logging, anomaly detection and automated mitigation. The design of MARE envisions a repository of Security Functions, each of them being plug-and-play and ready for deployment. This means that when a new threat arises, the right Security Function can be activated, using the right mix of DOTs, to provide a the defence required. From design to Proof of Concepts These modular security tools are not just theoretical. MARE will validate them in various proof-of-concepts (PoCs). PoCs are real or simulated network setups where real threats are played out, and the MARE security plane is evaluated in the defense in can provide. In these PoCs we expect to see how DOTs and Security Function perform under pressure – how quickly they deploy, how well they adapt, how they protect systems with minimal human input. It’s through these hands-on experiments that the building blocks will demonstrate and prove their value. Why this matters Although the terms DOTs and Security Functions may sound technical, they will be able to provide everyday users and organisations, including: Faster time to deploy security when threats emerge: As systems wont have to be re-engineered each time, Context-aware protection: Different threats require different tools and modularity allows combining the appropriate security elements which will provide the required security, Future-proof defence: As 6G evolves, so will new threats but with reusable building blocks the architecture can adapt faster and more efficiently. Coming up next! As MARE progresses, you’ll see these building blocks being assembled into deployments. The Security Functions will be used in PoCs, bringing these concepts out of the lab and towards the network infrastructure of the future.

