From Blueprint to Reality: MEDIATE Begins System Integration Testing
After defining the architecture and building mock components, the MEDIATE project is now connecting them together, testing the full chain from threat detection to countermeasure deployment across real infrastructure.
MEDIATE is an EU-funded research and innovation project building a zero-trust cybersecurity framework for the computing continuum, from IoT edge devices to cloud systems. Its approach combines hardware and software security sensors, federated learning-based orchestration, AI-driven threat intelligence, and privacy-preserving data management.
Over the past months, MEDIATE's Work Package 6 has been designing and building a prototype, the MVP (Minimum Viable Product), that demonstrates how the project's core components interact. The MVP does not aim to deploy the full system; instead, it validates that components can communicate correctly, events are propagated properly, and decisions flow from detection to response.
In early June 2025, the consortium began its first real integration tests, connecting the three architectural layers of the system: the Sentinel (edge monitoring), the Overwatch (threat analysis and decision support), and the Orchestrator (system-wide management and human interface).
The MEDIATE MVP Skeleton Architecture: three interconnected layers communicating over MQTT and ComDeX
When a cyber threat is detected, the MEDIATE framework responds through a structured, automated, and optionally human-supervised, workflow:
- 1Detection: A Sentinel monitoring an asset detects anomalous behaviour and publishes a threat alert.
- 2Intelligence: The Decision Support System (DSS) queries the Cyber Threat Intelligence module for known vulnerabilities linked to the affected asset.
- 3Analysis: The DSS generates a ranked list of countermeasures, drawing on threat data, vulnerability intelligence, and predefined configuration libraries.
- 4Policy check: The Policy Manager evaluates which countermeasures comply with security policies, either approving autonomous action or flagging the need for human review.
- 5Decision: In automated mode the system applies the countermeasure directly. In Human-in-the-Loop mode, an administrator reviews and selects the mitigation via the dashboard.
- 6Deployment: The Sentinel Reconfiguration and Deployment Unit (SRDU) delivers the configuration command to the targeted Sentinel, which applies it and reports back.
Progressive Integration & Transition to Full Components
The current MVP uses mock components that faithfully replicate the interfaces and message patterns of the final system. This design means that as real implementations mature, they can be slotted in one by one, without redesigning the architecture. Hardware sentinels will progressively replace simulated ones, and full Overwatch and Orchestrator implementations will replace their mockups as the project advances.
Stay up to date with project progress
🌐 mediate-horizon.eu 💼 LinkedIn: MEDIATE Horizon 🐦 X / Twitter: @mediate_h2020 ▶️ YouTube: @MEDIATE_EU_H2020MEDIATE · Multi facEteD ImplementAtion of a mixed sofTwarE/hardware-based zerotrust framework for the computing continuum
This project has received funding from the European Union's Horizon Europe innovation programme under Grant Agreement No 101168465. This document does not reflect the opinion of the European Union, and the European Union is not responsible for any use that might be made of the information contained therein.