Information, not verdict
The tag says relevant security observations exist; it does not declare a person guilty.
Carry security context forward instead of making every destination rediscover the same threat.
Today, one firewall may identify malicious traffic, block it and move on. The next destination often has to detect and classify the same source again. IP addresses, NAT and changing ports also make long-term attribution difficult.
When a participating network reports harmful traffic, the originating network can associate the observation with a persistent technical identity such as ownerId + owner_generated_unit_id. Later traffic from that unit can carry or be associated with accountable threat information.
The tag says relevant security observations exist; it does not declare a person guilty.
Recipients may monitor, investigate, rate-limit, quarantine, block, use the signal in Zero Trust/SIEM/AI, or take no action.
The network owner keeps any mapping to a subscriber or internal user. TaraSec does not need that personal identity.
Reports retain provenance, history, severity and confidence so conflicting or abusive reports can be challenged.
After remediation, reassessment can reduce or remove the threat state instead of creating a permanent blacklist.
Tagging is one part of a feedback system intended to reduce the threat itself. A blocked incident can become information that helps the originating network identify a compromised unit, notify its owner, support remediation, correlate a wider campaign and prevent the same machine being reused against another target.
A print-ready version is available for sharing and presentations.
Download Traffic Tagging PDFDo not make every firewall rediscover the same malicious source. Carry accountable security knowledge forward — while leaving enforcement with the receiving network.