Build TaraSec
Develop protocols, software, AI, identity, networking, integrations and production architecture.
COLLABORATIVE CYBERSECURITY
TaraSec lets network owners and service providers combine the information each already has: one side can recognise malicious behaviour, while the originating network can identify the responsible technical unit. Shared, accountable signals make it possible to act closer to the source.
IS IT SAFE?
TaraSec combines shared attack reports, local protection and an operator-approved security agent. We are exploring opt-in global AI supervision as a research direction.
The agent can report specific setup problems and propose defined repairs. An operator signs in with Google and uses an authenticator code to approve each change. Core network rules can share attack evidence with the originating network and block traffic according to configured severity thresholds, including a protected SSH port.
New software also creates new weak spots. We publish the source and invite you to test the claims, study failure cases and help make the network safer.
ABOUT TARASEC
TaraSec is an experimental collaborative cybersecurity initiative developed by Taransvar, a Norwegian non-profit organisation.
The idea is simple: the network that sees an attack and the network that knows where it came from should be able to share the information needed to act. TaraSec explores how that cooperation can be accountable, privacy-conscious and governed in the public interest rather than controlled by one vendor.
Nonprofit ownership is intended to support fair competition and create a framework in which organisations that contribute to better Internet security can be recognised and rewarded for that contribution.
FIRST TO JOIN
Cybersecurity depends on cooperation. Organisations can enroll and begin testing TaraSec now, using an AI assistant together with the official GitHub source.
ISPs, universities, enterprises, public institutions and other network operators are invited to enroll, test the system, challenge its assumptions and help shape the cooperative network.
With permission, early participants can be recognised publicly here. We will publish the first-to-join list only when there are participating organisations to show, and we will distinguish organisations that are enrolled or testing from those operating TaraSec in production.
STUDENT PROJECTS & RESEARCH
TaraSec is a working experimental network with open research questions across cybersecurity, networking, AI, privacy, trust, business, law and societal impact.
Students at bachelor's, master's and PhD level can start from working code and test infrastructure — or challenge the assumptions behind the entire approach. Negative findings are welcome.
Develop protocols, software, AI, identity, networking, integrations and production architecture.
Attack the technical and organisational assumptions. Study privacy, false reports, compromised participants and AI failure.
Explore cybercrime economics, healthcare, critical infrastructure, regulation, business, behaviour and society.
THE PROBLEM
Security systems often see suspicious traffic but cannot reliably identify the actual device or local network responsible for it. Addresses change, users sit behind gateways, and different organisations each hold only part of the information needed to respond.
TaraSec aims to connect those pieces without requiring every participant to surrender control of its own network.
HOW IT WORKS
A firewall, honeypot, IDS/IPS or another security system detects suspicious or malicious traffic from a unit on another participating network.
The receiving network reports the observation back through TaraSec with provenance and the technical information needed to associate it with the originating network.
The responsible ISP or network can associate the traffic with its persistent technical unit ID. TaraSec does not need the subscriber's personal identity.
Later traffic can carry or be associated with security information based on previous incidents, instead of every destination starting again from an IP address and port.
Reports from multiple sensors and networks can contribute to an AI-assisted assessment of the same persistent unit, including history, severity, recency, corroboration and confidence.
TaraSec supplies additional security context, not a mandatory policy. A participant may monitor, investigate, rate-limit, use the signal in Zero Trust, quarantine, block or do nothing.
Recovery is not limited to cleaning a genuinely infected device. New contradictory evidence can also correct a false attribution, so a temporary mistake does not have to become a permanent blacklist entry.
SELF-HEALING ATTRIBUTION
TaraSec treats threat status as an evidence-based assessment that can be challenged by later network behaviour. Detection should not be a one-way path into a permanent blacklist.
If a receiver gets traffic carrying a TaraSec threat tag but its normal firewall policy accepts that packet, the acceptance can be reported as contradictory evidence for audit. The event can be sent to the TaraSec DB server and back toward the originating participant.
An accepted packet does not automatically prove that a unit is clean. But repeated successful, policy-compliant traffic — especially when no independent malicious evidence remains — can reduce confidence in the earlier attribution and trigger reassessment.
If a user first enters one IP address and shortly afterwards reaches the intended address, TaraSec can compare timing, session context and IP similarity. Transposed or visually similar addresses can become evidence that the original attribution was an input error.
A false positive can move through an auditable lifecycle such as suspected → attributed → contradicted → automatically cleared. The history remains available for accountability while current participants receive the corrected assessment.
The goal is self-healing threat attribution: detect, attribute, reassess, correct and rehabilitate when the evidence changes.
CORE ELEMENTS
Security observations from firewalls and other sensors can become accountable threat information associated with subsequent traffic from the same unit.
A service under attack — or simply under unusually high load — can ask participating routers and networks for help, for example by requesting that they temporarily forward only traffic from units they assess as sufficiently clean. This allows mitigation to begin before unwanted traffic reaches the overloaded destination.
Threat history can follow a technical unit identity rather than an ever-changing IP address and port. The responsible ISP or network keeps any mapping between that identifier and a subscriber.
AI can correlate reports concerning the same unit across time and participating networks, producing evidence, reasoning, confidence and recommendations from a much richer history than IP reputation alone.
TaraSec is a framework, not the participant's firewall policy. Zero Trust, SIEM/SOC, IDS/IPS, access control, AI security and conventional network controls can all use TaraSec information as an additional input.
Reports need provenance and history so false reports, compromised participants and conflicting evidence can be challenged and assessed. TaraSec should not become an anonymous global blacklist.
Rehabilitation includes both remediation of genuinely compromised units and automatic correction when later evidence contradicts an earlier attribution. Corrections should propagate while the audit history is preserved.
IDENTITY MODEL
TRUST, PRIVACY & ACCOUNTABILITY
We don't need to know who you are to know that a device may be infected.
IP addresses and other identifiers that can be linked to a person are personal data and must be handled accordingly. TaraSec applies the same strict privacy principle to persistent unit identifiers.
TaraSec does not need or seek a subscriber's name, address, email or other private information. Security information is associated with a network owner and a technical unit identifier.
The ISP or network owner retains the relationship between its unit identifier and its subscriber, employee or internal user. If legitimate identification is required, the responsible network owner must be involved.
Security assertions need provenance: who reported them, when they were reported and what observations support them. Participants must not be able to turn TaraSec into an anonymous global blacklist.
TaraSec can use AI to correlate observations, recognise patterns and produce assessments with signals, reasoning, confidence and recommended actions. An AI assessment is evidence for a decision, not an unquestionable verdict.
Important enforcement remains controlled by defined network policy and, where appropriate, human review. Uncertainty should favour investigation and reassessment rather than irreversible action.
TaraSec does not ask networks to trust an AI. It aims to give networks better evidence, persistent context and accountable signals while leaving enforcement decisions under defined human and organisational policy.
The TaraSec App connects an authorised owner or manager to the gateway for setup, infection status, assistance requests and gateway-level AI assessments. It is also the natural place to show reassessment and automatic false-positive recovery as evidence changes.
The App and the TaraSec AI architecture are designed together: local assessment stays close to the gateway, while structured findings can contribute back to the wider TaraSec network.
ENROLL, INSTALL & TEST WITH AI
An organisation can begin enrolling and testing TaraSec immediately. The official GitHub repositories are the technical source of truth and contain current, AI-readable instructions that an assistant such as ChatGPT can inspect and use to guide installation, configuration, testing and troubleshooting step by step.
For the TaraSec core, router/hotspot software, installation scripts and technical documentation, use the official taransvar repository.
Tell your AI assistant: “I want to enroll my organisation and install or test TaraSec. Read the official instructions in github.com/oyst12rsas/taransvar and guide me.”
For the Android app and the end-to-end security demo, use the official TaraSec_App repository. The repository contains AI_DEMO_GUIDE.md, which explains the tested phone → hotspot → TaraSec gateway → receiving-node flow and common troubleshooting.
Tell your AI assistant: “I want to test the TaraSec app. Read AI_DEMO_GUIDE.md in github.com/oyst12rsas/TaraSec_App and guide me.”
TaraSec is under active development. When website text, remembered instructions and source code differ, use the current official repository and its AI-readable guide as the technical reference. An AI assistant should inspect the current files before suggesting commands.
For test environments, ask the assistant to distinguish clearly which commands run on the Android host, hotspot, TaraSec gateway or receiving node.
ABUSE & FAILURE SAFEGUARDS
Assessments carry context and confidence. Later accepted traffic, corrected input, IP similarity, independent receiver observations and the absence of corroborating malicious behaviour can all contribute to reassessment. A correction is propagated while the audit history remains intact.
Signals should be attributable to their reporting participant so false or abusive reports can be detected, challenged and acted upon.
A receiving network remains responsible for its own enforcement policy. Shared information does not require every participant to take the same action.
Cooperation should exchange the security information needed to address an incident without creating a central directory of people's identities or unnecessarily sharing private customer information.
THE POTENTIAL
Today's defenders repeatedly absorb and filter attacks after malicious traffic has crossed the Internet. TaraSec explores whether networks can instead cooperate to identify compromised units, share accountable security context and intervene closer to where abuse originates.
If participation becomes widespread, compromised devices could become harder to reuse, distributed attacks harder to sustain, and defenders less dependent on independently solving the same source problem at every destination. TaraSec is testing that possibility — not claiming it has already been achieved.
PARTICIPATE
TaraSec is being developed as an open collaboration model for organisations that operate networks, protect systems or can contribute trustworthy attribution and security signals.
Students and researchers across technology, AI, business, e-health, governance, law, economics and other fields can explore projects at tarasec.org/student.
TaraSec is an initiative of Taransvar, a Norwegian registered non-profit organisation (organisation no. 992 132 027).
CONTACT TARASEC
Use this form for ISP discussions, research collaboration, demonstrations, deployment questions or other TaraSec enquiries. Your message is sent directly to Taransvar.