The FORESIGHT project aims to develop a federated cyber-range solution to enhance the preparedness of cybersecurity professionals at all levels and advance their skills towards preventing, detecting, reacting and mitigating sophisticated cyber-attacks. This is achieved by delivering an ecosystem of networked realistic training and simulation platforms that collaboratively bring unique cyber-security aspects from the aviation, smart grid and naval domains. The proposed platform will extend the capabilities of existing cyber-ranges and will allow the creation of complex cross-domain/hybrid scenarios to be built jointly with the IoT domain.
Emphasis is given on the design and implementation of realistic and dynamic scenarios, that are based on identified and forecasted trends of cyberattacks and vulnerabilities extracted from cyber-threat intelligence gathered from the dark web. This will enable cybersecurity professionals to rapidly adapt to an evolving threat landscape. ED has undertaken the system architecture design and to provide the integrated Federated User Interface.
CitySCAPE project explores all different cybersecurity dimensions in the ICT multimodal transport, extended to the close-by power and financial sector. It will realize a modular software toolkit enabled to be seamlessly integrated into any multimodal transport system to:
- detect suspicious traffic-data values and identify persistent threats
- evaluate an attack’s impact in technical and notably in financial terms
- combine external knowledge and internally-observed activities to enhance the predictability of zeroday attacks
- instantiate a networked overlay to circulate informative notifications to CERT authorities and support their interplay
The CitySCAPE solution will be tested over a timely set of use-cases involving ticketing applications, cyber-fraud and location data in the regional transport system of two European cities, where extensive experiments will showcase its effectiveness. The findings will steer training sessions of expert/non-expert audience and shape a strong standardization contribution to security (labelling) protocols. ED is responsible to design the system architecture and provide the Risk analysis and impact assessment engine to estimate the threats propagation in the system.
NG-SOC (Next Generation Security Operations Centres) is developing a network of AI-enabled SOCs across EU member states to enhance cybersecurity. It aims to improve communication, cooperation, and information sharing to effectively respond to cyber threats, aligning with regulatory standards.
Key Features:
- Interoperable CTI Toolbox: Exchanges cyber threat intelligence from diverse sources like ENISA and CSIRTs Network.
- Incident Response: Aligns with best practices to facilitate interaction among SOCs, EU entities, and third parties.
- Training Programs: Provides tailored digital infrastructure security training.
- AI-Enhanced Technologies: Boosts threat prediction, detection, and response capabilities.
Technologies and Techniques:
- AI Monitoring: Detects anomalies using advanced AI for identifying novel attacks.
- Attack Classification: Utilizes MITRE ATT&CK framework for threat detection.
- CTI Sharing: Organizes intelligence sharing to manage dynamic trust relationships.
- Data Analysis: Analyzes data to support threat detection and response.
- Security Orchestration: Automates incident response processes with minimal disruption.
- Penetration Testing: Improves testing to reduce time and cost.
- Dynamic Risk Management: Evaluates threats and risks in real-time for mitigation.
- Continuous Training: Enhances cybersecurity skills with a hands-on educational platform.
- Maturity Indicators: Measures SOC/CSIRT readiness for the EU Cyber Shield.
The project aims to establish a robust security framework for 6G ecosystems, underpinned by the zero-trust principle and emphasizing core tenets like resilience, privacy, and dependability. Dynamic access control via a context-aware risk-based policy engine, leveraging rich cyber-threat intelligence and behavioral insights gathered from the 6G infrastructure, is at the core of the proposed approach. Micro-segmentation of vulnerable virtualized functions from critical O-RAN assets is a primary goal to prevent attackers’ lateral movement capabilities and minimize damage.
Proactive security measures will be deployed alongside sophisticated AI tools to optimize attack surface reduction and enhance intrusion detection capabilities. An intelligent extended detection and response solution will be developed, covering all layers of a 6G network; this entails the integration of collaborative intrusion detection networks and graph-based threat models, facilitating real-time and optimal responses to sophisticated multi-stage attacks targeting the 6G ecosystem.
Automation will be pivotal in various aspects, including threat modelling, and response orchestration, aided by blockchain to secure integration and lifecycle management of 6G applications. Moreover, the project will prioritize supply chain security by implementing automated vulnerability scanning and introducing O RAN application certification.
Quantum-safe technologies (QKD and PQC) and AI-driven solutions will be employed to safeguard against physical layer attacks, ensuring uninterrupted and secure data transmission in 6G networks. Additionally, privacy-preserving and trusted AI/ML schemes will be developed upholding principles like fairness, explainability, and sustainability to ensure high energy efficiency and minimal environmental footprint of the proposed solutions. These efforts aim to ensure that critical 6G communications infrastructure achieves high security and resilience against evolving cyber threats.
The use of cryptocurrencies unlocks opportunities for innovation but also facilitates criminal and terrorist activities, through perceived anonymity and freedom from centralised control and oversight.
The response to cryptocurrency-facilitated criminal/ terrorist (CFCT) activities must evolve continuously both in terms of technology and in terms of operational guidelines and training; moreover it must foster collaboration across international borders and across the different stakeholders on the side of the law (LEAs, regulators, law makers, legitimate cryptocurrency ecosystem and financial sector actors, telecommunication and technology market actors, etc.) and possibly lead to strategic regulatory steps.
The CryptoACTION project (a) builds upon existing closed-source and open-source R&D efforts to offer enhanced technical tools in service of Law Enforcement Agencies (LEAs), (b) improves the operational capacity of involved Agencies through collaboration and information sharing with the technological enablers for data management and access control, (c) develops new tools and capabilities for LEAs via a novel safe environment for experimentation and training and (d) provides recommendations for better regulation of the cryptocurrency market and improved cooperation of LEAs at the EU and international level.









