COLLABORATIVE CYBERSECURITY

Make malicious traffic accountable.

TaraSec is designed to help network owners and service providers cooperate around a simple idea: identify the originating unit more reliably than by IP address alone, share trusted security signals, and act before abuse becomes profitable at scale.

THE PROBLEM

IP addresses tell only part of the story.

Security systems often see suspicious traffic but cannot reliably identify the actual device or local network responsible for it. Addresses change, users sit behind gateways, and different organisations each hold only part of the information needed to respond.

TaraSec aims to connect those pieces without requiring every participant to surrender control of its own network.

HOW IT WORKS

Turn isolated security incidents into shared, accountable context.

TaraSec flow from incident detection and reporting through persistent unit identification, AI assessment, traffic signalling, local action, Request for Assistance and anonymous recovery
01

An incident is observed

A firewall, honeypot, IDS/IPS or another security system detects suspicious or malicious traffic from a unit on another participating network.

02

The incident is reported

The receiving network reports the observation back through TaraSec with provenance and the technical information needed to associate it with the originating network.

03

The originating unit is identified

The responsible ISP or network can associate the traffic with its persistent technical unit ID. TaraSec does not need the subscriber's personal identity.

04

Threat information follows the unit

Later traffic can carry or be associated with security information based on previous incidents, instead of every destination starting again from an IP address and port.

05

AI correlates wider evidence

Reports from multiple sensors and networks can contribute to an AI-assisted assessment of the same persistent unit, including history, severity, recency, corroboration and confidence.

06

Each participant chooses its response

TaraSec supplies additional security context, not a mandatory policy. A participant may monitor, investigate, rate-limit, use the signal in Zero Trust, quarantine, block or do nothing.

07

The unit can recover

A user-facing recovery service is planned so people can voluntarily sign out their unit and receive anonymous help investigating and cleaning it. Successful remediation and subsequent behaviour can feed reassessment rather than creating a permanent blacklist.

CORE ELEMENTS

Move defence closer to the source.

Traffic tagging from incidents

Security observations from firewalls and other sensors can become accountable threat information associated with subsequent traffic from the same unit.

Request for Assistance

A service under attack — or simply under unusually high load — can ask participating routers and networks for help, for example by requesting that they temporarily forward only traffic from units they assess as sufficiently clean. This allows mitigation to begin before unwanted traffic reaches the overloaded destination.

Persistent unit identity

Threat history can follow a technical unit identity rather than an ever-changing IP address and port. The responsible ISP or network keeps any mapping between that identifier and a subscriber.

Global AI threat assessment

AI can correlate reports concerning the same unit across time and participating networks, producing evidence, reasoning, confidence and recommendations from a much richer history than IP reputation alone.

Local security freedom

TaraSec is a framework, not the participant's firewall policy. Zero Trust, SIEM/SOC, IDS/IPS, access control, AI security and conventional network controls can all use TaraSec information as an additional input.

Accountable reporting

Reports need provenance and history so false reports, compromised participants and conflicting evidence can be challenged and assessed. TaraSec should not become an anonymous global blacklist.

Recovery instead of permanent stigma

Users should have a practical path to investigate and clean compromised units anonymously. Reassessment after remediation makes the system about reducing infection and abuse, not permanently labelling devices or people.

IDENTITY MODEL

From guessing by IP and port to an owner-declared unit.

ownerIdNetwork or service owner
owner_generated_unit_idOwner-defined technical unit identity
IP + portObserved network attributes, not the long-term identity

TRUST, PRIVACY & ACCOUNTABILITY

Identify units, not people.

We don't need to know who you are to know that a device may be infected.

01

Personal data stays protected

IP addresses and other identifiers that can be linked to a person are personal data and must be handled accordingly. TaraSec applies the same strict privacy principle to persistent unit identifiers.

02

No customer identity required

TaraSec does not need or seek a subscriber's name, address, email or other private information. Security information is associated with a network owner and a technical unit identifier.

03

The owner keeps the mapping

The ISP or network owner retains the relationship between its unit identifier and its subscriber, employee or internal user. If legitimate identification is required, the responsible network owner must be involved.

04

Accountable reporting

Security assertions need provenance: who reported them, when they were reported and what observations support them. Participants must not be able to turn TaraSec into an anonymous global blacklist.

AI IN TARASEC

AI assists decisions. It does not become the authority.

TaraSec can use AI to correlate observations, recognise patterns and produce assessments with signals, reasoning, confidence and recommended actions. An AI assessment is evidence for a decision, not an unquestionable verdict.

Important enforcement remains controlled by defined network policy and, where appropriate, human review. Uncertainty should favour investigation and reassessment rather than irreversible action.

TaraSec does not ask networks to trust an AI. It aims to give networks better evidence, persistent context and accountable signals while leaving enforcement decisions under defined human and organisational policy.

ABUSE & FAILURE SAFEGUARDS

The trust system itself must be protected.

False positives

Assessments should carry context and confidence, be open to reassessment and avoid treating a temporary observation as permanent identity or guilt.

Malicious reporting

Signals should be attributable to their reporting participant so false or abusive reports can be detected, challenged and acted upon.

Local authority

A receiving network remains responsible for its own enforcement policy. Shared information does not require every participant to take the same action.

Minimum disclosure

Cooperation should exchange the security information needed to address an incident without creating a central directory of people's identities or unnecessarily sharing private customer information.

THE POTENTIAL

At sufficient scale, collaborative source-side security could change the economics of cybercrime.

Today's defenders repeatedly absorb and filter attacks after malicious traffic has crossed the Internet. TaraSec explores whether networks can instead cooperate to identify compromised units, share accountable security context and intervene closer to where abuse originates.

If participation becomes widespread, compromised devices could become harder to reuse, distributed attacks harder to sustain, and defenders less dependent on independently solving the same source problem at every destination. TaraSec is testing that possibility — not claiming it has already been achieved.

PARTICIPATE

For network owners, ISPs, researchers and security partners.

TaraSec is being developed as an open collaboration model for organisations that operate networks, protect systems or can contribute trustworthy attribution and security signals.

Students and researchers across technology, AI, business, e-health, governance, law, economics and other fields can explore projects at tarasec.org/student.

TaraSec is an initiative of Taransvar, a Norwegian registered non-profit organisation (organisation no. 992 132 027).