ABOUT TARASEC

Internet security needs cooperation, not just more products.

TaraSec is an experimental collaborative cybersecurity initiative developed by Taransvar, a Norwegian non-profit organisation. The central idea is simple: the network that sees an attack and the network that knows where it came from should be able to share the information needed to act.

IS IT SAFE?

What protects an experimental deployment?

We document the controls we currently use, including separate SSH services, configuration checks and operator approval of narrowly defined repairs. We also describe the risks that still depend on deployment and testing.

WHY TARASEC EXISTS

Security information is fragmented across the Internet.

A receiving network may know that traffic is malicious but not which device or local unit is responsible. The originating network may be able to identify that unit but may never learn what happened elsewhere.

TaraSec explores whether those two pieces of knowledge can be connected through accountable, privacy-conscious cooperation, so that action can happen closer to the source instead of every destination independently defending itself against the same problem.

WHO OWNS IT

TaraSec is an initiative of Taransvar.

Taransvar is a Norwegian registered non-profit organisation. The intention is that TaraSec should serve a broader public-interest security purpose rather than become a proprietary mechanism controlled by a single security vendor, cloud provider or telecommunications company.

That matters because meaningful Internet-wide cooperation requires trust between organisations that may otherwise be competitors. Governance should therefore be designed around transparency, accountability, interoperability and the ability of participants to retain control over their own networks.

OUR PRINCIPLES

Cooperate globally. Decide locally.

Shared evidence

Participants can contribute security observations and attribution context that other networks could not obtain alone.

Local authority

TaraSec supplies context. Each participant remains responsible for its own firewall, access-control and response policy.

Privacy by design

The goal is to identify accountable technical units without requiring TaraSec to know the personal identity of the subscriber or user.

Correctable decisions

False positives and changed circumstances must be reversible. Security status should be reassessed as new evidence arrives.

THE BIGGER IDEA

The Internet may not need another security silo.

TaraSec does not claim that the Internet lacks security technology. Firewalls, IDS/IPS, Zero Trust systems, SIEM platforms and AI security tools already exist.

The research question is whether they could become more effective if trustworthy information could travel between cooperating networks: those who know that traffic is malicious sharing information with those who can identify and influence the source.

At sufficient scale, that could make compromised devices harder to reuse, attacks more expensive to sustain, and cybercrime less profitable.

OPEN TO CHALLENGE

TaraSec should be tested, criticised and improved.

Technical, privacy, governance and economic assumptions are all open research questions. Students, ISPs, researchers and security organisations are invited not only to help build TaraSec, but to try to find where the model fails.