FACT SHEET

Assistance Request

Ask the network that controls harmful traffic to help stop it closer to its source.

A firewall should not only be able to say “I blocked an attack.” TaraSec lets it also ask the source network: “Can you stop sending it?”

Not just DDoS

Assistance Request is intended for harmful or abusive traffic generally: distributed denial of service, SSH/RDP/web-login brute force, credential stuffing, systematic probing, exploitation attempts, botnet activity and application-layer attacks that may use little bandwidth but consume significant server resources.

How it works

  1. A receiving network detects harmful traffic and identifies the responsible originating network.
  2. It sends an authenticated Assistance Request with supporting information.
  3. The originating network verifies that the traffic belongs to a unit or connection it controls.
  4. That network independently chooses its response: rate-limit, restrict, isolate, notify the owner, request more evidence, or decline.
  5. The outcome can be reported back and reassessed after remediation.

Similar approaches — but a different direction

ApproachDifference from TaraSec Assistance Request
DDoS scrubbingAbsorbs or filters traffic for the victim; TaraSec asks the originating network to participate in suppressing the source.
BGP FlowSpecDistributes filtering rules through routing infrastructure; TaraSec sends evidence and a request to the autonomous network responsible for the source.
RTBHProvides relatively coarse upstream dropping; TaraSec aims for targeted, accountable action tied to the source unit.
ISP abuse deskUsually relies on human tickets and investigation; TaraSec aims for authenticated machine-to-machine cooperation in near real time.
Firewall / IPSProtects its own network; TaraSec additionally asks the sender’s network to help stop the traffic.

Security cooperation should not be a premium feature

Large-scale scrubbing and advanced mitigation can require specialist infrastructure, expensive services and operational expertise. A small ISP may lack those resources but still possess something a remote mitigation provider does not: direct control of the connection from which the harmful traffic originates.

Move part of Internet defence from “Who can afford the biggest mitigation infrastructure?” toward “Who is best positioned to stop the harmful traffic?”

From isolated incidents to shared threat mapping

Most defensive systems primarily solve the incident in front of them: detect the unwanted traffic, block it and move on. TaraSec can allow one Assistance Request to contribute evidence to a wider community view of recurring scanners, botnets, coordinated campaigns and supporting infrastructure.

Controlled decoys and honeypots can be tailored to resemble commonly targeted environments so defensive researchers can observe tactics safely, correlate infrastructure and improve detection. The purpose is defensive observation and remediation — not retaliation.

That intelligence can help participating ISPs and owners find involuntarily compromised hosts, clean them, impose proportionate restrictions where necessary, and make continued abuse of compromised access progressively harder.

One server asking for assistance can contribute evidence that helps the entire TaraSec community recognize and contain the same campaign elsewhere.

A different objective

Conventional cybersecurity is primarily designed to protect individual customers against an ongoing threat environment. TaraSec’s long-term objective is different: reduce the threat itself. A detected incident should not end when one firewall blocks it; it can help identify compromised units, warn their operators, request assistance, map coordinated campaigns and support remediation.

PDF fact sheet

A print-ready version is available for sharing and presentations.

Download Assistance Request PDF

Key idea

From protecting against cybercrime to reducing its ability to operate.