COLLABORATIVE CYBERSECURITY

One network sees the attack. Another knows the source. TaraSec connects them.

TaraSec lets network owners and service providers combine the information each already has: one side can recognise malicious behaviour, while the originating network can identify the responsible technical unit. Shared, accountable signals make it possible to act closer to the source.

IS IT SAFE?

Experimental security deserves scrutiny.

TaraSec combines shared attack reports, local protection and an operator-approved security agent. We are exploring opt-in global AI supervision as a research direction.

The agent can report specific setup problems and propose defined repairs. An operator signs in with Google and uses an authenticator code to approve each change. Core network rules can share attack evidence with the originating network and block traffic according to configured severity thresholds, including a protected SSH port.

New software also creates new weak spots. We publish the source and invite you to test the claims, study failure cases and help make the network safer.

ABOUT TARASEC

Internet security needs cooperation, not just more products.

TaraSec is an experimental collaborative cybersecurity initiative developed by Taransvar, a Norwegian non-profit organisation.

The idea is simple: the network that sees an attack and the network that knows where it came from should be able to share the information needed to act. TaraSec explores how that cooperation can be accountable, privacy-conscious and governed in the public interest rather than controlled by one vendor.

Nonprofit ownership is intended to support fair competition and create a framework in which organisations that contribute to better Internet security can be recognised and rewarded for that contribution.

FIRST TO JOIN

Will your organisation be among the first to join TaraSec?

Cybersecurity depends on cooperation. Organisations can enroll and begin testing TaraSec now, using an AI assistant together with the official GitHub source.

ISPs, universities, enterprises, public institutions and other network operators are invited to enroll, test the system, challenge its assumptions and help shape the cooperative network.

With permission, early participants can be recognised publicly here. We will publish the first-to-join list only when there are participating organisations to show, and we will distinguish organisations that are enrolled or testing from those operating TaraSec in production.

STUDENT PROJECTS & RESEARCH

Build it. Challenge it. Study what it could change.

TaraSec is a working experimental network with open research questions across cybersecurity, networking, AI, privacy, trust, business, law and societal impact.

Students at bachelor's, master's and PhD level can start from working code and test infrastructure — or challenge the assumptions behind the entire approach. Negative findings are welcome.

01

Build TaraSec

Develop protocols, software, AI, identity, networking, integrations and production architecture.

02

Challenge TaraSec

Attack the technical and organisational assumptions. Study privacy, false reports, compromised participants and AI failure.

03

Study the consequences

Explore cybercrime economics, healthcare, critical infrastructure, regulation, business, behaviour and society.

THE PROBLEM

IP addresses tell only part of the story.

Security systems often see suspicious traffic but cannot reliably identify the actual device or local network responsible for it. Addresses change, users sit behind gateways, and different organisations each hold only part of the information needed to respond.

TaraSec aims to connect those pieces without requiring every participant to surrender control of its own network.

HOW IT WORKS

Turn isolated security incidents into shared, accountable context.

TaraSec flow from incident detection and reporting through persistent unit identification, AI assessment, traffic signalling, local action, Request for Assistance and anonymous recovery
01

An incident is observed

A firewall, honeypot, IDS/IPS or another security system detects suspicious or malicious traffic from a unit on another participating network.

02

The incident is reported

The receiving network reports the observation back through TaraSec with provenance and the technical information needed to associate it with the originating network.

03

The originating unit is identified

The responsible ISP or network can associate the traffic with its persistent technical unit ID. TaraSec does not need the subscriber's personal identity.

04

Threat information follows the unit

Later traffic can carry or be associated with security information based on previous incidents, instead of every destination starting again from an IP address and port.

06

Each participant chooses its response

TaraSec supplies additional security context, not a mandatory policy. A participant may monitor, investigate, rate-limit, use the signal in Zero Trust, quarantine, block or do nothing.

07

The unit can recover

Recovery is not limited to cleaning a genuinely infected device. New contradictory evidence can also correct a false attribution, so a temporary mistake does not have to become a permanent blacklist entry.

SELF-HEALING ATTRIBUTION

A security system should be able to correct itself.

TaraSec treats threat status as an evidence-based assessment that can be challenged by later network behaviour. Detection should not be a one-way path into a permanent blacklist.

01

Accepted tagged traffic becomes evidence

If a receiver gets traffic carrying a TaraSec threat tag but its normal firewall policy accepts that packet, the acceptance can be reported as contradictory evidence for audit. The event can be sent to the TaraSec DB server and back toward the originating participant.

02

The network continuously tests its own conclusions

An accepted packet does not automatically prove that a unit is clean. But repeated successful, policy-compliant traffic — especially when no independent malicious evidence remains — can reduce confidence in the earlier attribution and trigger reassessment.

03

Human input mistakes can be recognised

If a user first enters one IP address and shortly afterwards reaches the intended address, TaraSec can compare timing, session context and IP similarity. Transposed or visually similar addresses can become evidence that the original attribution was an input error.

04

Corrections are propagated, not erased

A false positive can move through an auditable lifecycle such as suspected → attributed → contradicted → automatically cleared. The history remains available for accountability while current participants receive the corrected assessment.

The goal is self-healing threat attribution: detect, attribute, reassess, correct and rehabilitate when the evidence changes.

CORE ELEMENTS

Move defence closer to the source.

Traffic tagging from incidents

Security observations from firewalls and other sensors can become accountable threat information associated with subsequent traffic from the same unit.

Request for Assistance

A service under attack — or simply under unusually high load — can ask participating routers and networks for help, for example by requesting that they temporarily forward only traffic from units they assess as sufficiently clean. This allows mitigation to begin before unwanted traffic reaches the overloaded destination.

Persistent unit identity

Threat history can follow a technical unit identity rather than an ever-changing IP address and port. The responsible ISP or network keeps any mapping between that identifier and a subscriber.

Local security freedom

TaraSec is a framework, not the participant's firewall policy. Zero Trust, SIEM/SOC, IDS/IPS, access control, AI security and conventional network controls can all use TaraSec information as an additional input.

Accountable reporting

Reports need provenance and history so false reports, compromised participants and conflicting evidence can be challenged and assessed. TaraSec should not become an anonymous global blacklist.

Self-healing recovery

Rehabilitation includes both remediation of genuinely compromised units and automatic correction when later evidence contradicts an earlier attribution. Corrections should propagate while the audit history is preserved.

IDENTITY MODEL

From guessing by IP and port to an owner-declared unit.

ownerIdNetwork or service owner
owner_generated_unit_idOwner-defined technical unit identity
IP + portObserved network attributes, not the long-term identity

TRUST, PRIVACY & ACCOUNTABILITY

Identify units, not people.

We don't need to know who you are to know that a device may be infected.

01

Personal data stays protected

IP addresses and other identifiers that can be linked to a person are personal data and must be handled accordingly. TaraSec applies the same strict privacy principle to persistent unit identifiers.

02

No customer identity required

TaraSec does not need or seek a subscriber's name, address, email or other private information. Security information is associated with a network owner and a technical unit identifier.

03

The owner keeps the mapping

The ISP or network owner retains the relationship between its unit identifier and its subscriber, employee or internal user. If legitimate identification is required, the responsible network owner must be involved.

04

Accountable reporting

Security assertions need provenance: who reported them, when they were reported and what observations support them. Participants must not be able to turn TaraSec into an anonymous global blacklist.

AI IN TARASEC

AI assists decisions. It does not become the authority.

TaraSec can use AI to correlate observations, recognise patterns and produce assessments with signals, reasoning, confidence and recommended actions. An AI assessment is evidence for a decision, not an unquestionable verdict.

Important enforcement remains controlled by defined network policy and, where appropriate, human review. Uncertainty should favour investigation and reassessment rather than irreversible action.

TaraSec does not ask networks to trust an AI. It aims to give networks better evidence, persistent context and accountable signals while leaving enforcement decisions under defined human and organisational policy.

THE TARASEC APP

Local visibility and control for owners and managers.

The TaraSec App connects an authorised owner or manager to the gateway for setup, infection status, assistance requests and gateway-level AI assessments. It is also the natural place to show reassessment and automatic false-positive recovery as evidence changes.

The App and the TaraSec AI architecture are designed together: local assessment stays close to the gateway, while structured findings can contribute back to the wider TaraSec network.

ENROLL, INSTALL & TEST WITH AI

Let an AI assistant guide your organisation from the official TaraSec source.

An organisation can begin enrolling and testing TaraSec immediately. The official GitHub repositories are the technical source of truth and contain current, AI-readable instructions that an assistant such as ChatGPT can inspect and use to guide installation, configuration, testing and troubleshooting step by step.

01

Install or inspect TaraSec Core

For the TaraSec core, router/hotspot software, installation scripts and technical documentation, use the official taransvar repository.

Tell your AI assistant: “I want to enroll my organisation and install or test TaraSec. Read the official instructions in github.com/oyst12rsas/taransvar and guide me.”

02

Test the TaraSec Android App

For the Android app and the end-to-end security demo, use the official TaraSec_App repository. The repository contains AI_DEMO_GUIDE.md, which explains the tested phone → hotspot → TaraSec gateway → receiving-node flow and common troubleshooting.

Tell your AI assistant: “I want to test the TaraSec app. Read AI_DEMO_GUIDE.md in github.com/oyst12rsas/TaraSec_App and guide me.”

03

Use the repositories as the technical source of truth

TaraSec is under active development. When website text, remembered instructions and source code differ, use the current official repository and its AI-readable guide as the technical reference. An AI assistant should inspect the current files before suggesting commands.

For test environments, ask the assistant to distinguish clearly which commands run on the Android host, hotspot, TaraSec gateway or receiving node.

ABUSE & FAILURE SAFEGUARDS

The trust system itself must be protected.

False positives must be reversible

Assessments carry context and confidence. Later accepted traffic, corrected input, IP similarity, independent receiver observations and the absence of corroborating malicious behaviour can all contribute to reassessment. A correction is propagated while the audit history remains intact.

Malicious reporting

Signals should be attributable to their reporting participant so false or abusive reports can be detected, challenged and acted upon.

Local authority

A receiving network remains responsible for its own enforcement policy. Shared information does not require every participant to take the same action.

Minimum disclosure

Cooperation should exchange the security information needed to address an incident without creating a central directory of people's identities or unnecessarily sharing private customer information.

THE POTENTIAL

At sufficient scale, collaborative source-side security could change the economics of cybercrime.

Today's defenders repeatedly absorb and filter attacks after malicious traffic has crossed the Internet. TaraSec explores whether networks can instead cooperate to identify compromised units, share accountable security context and intervene closer to where abuse originates.

If participation becomes widespread, compromised devices could become harder to reuse, distributed attacks harder to sustain, and defenders less dependent on independently solving the same source problem at every destination. TaraSec is testing that possibility — not claiming it has already been achieved.

PARTICIPATE

For network owners, ISPs, researchers and security partners.

TaraSec is being developed as an open collaboration model for organisations that operate networks, protect systems or can contribute trustworthy attribution and security signals.

Students and researchers across technology, AI, business, e-health, governance, law, economics and other fields can explore projects at tarasec.org/student.

TaraSec is an initiative of Taransvar, a Norwegian registered non-profit organisation (organisation no. 992 132 027).

CONTACT TARASEC

Talk to us without publishing an email address.

Use this form for ISP discussions, research collaboration, demonstrations, deployment questions or other TaraSec enquiries. Your message is sent directly to Taransvar.