Build TaraSec
Develop protocols, software, AI, identity, networking, integrations, testing and production architecture.
RESEARCH • BACHELOR'S • MASTER'S • PHD
TaraSec is a working experiment in collaborative Internet security. Firewalls, honeypots and other tools can become sensors in a wider network, while identity, AI, software, organisations and policy determine how observations become accountable action.
THE BIGGER QUESTION
What happens if malicious Internet activity can be identified and acted upon much closer to its originating device, while preserving the separation between technical identity and personal identity?
That question matters to hospitals, government, banking, energy, transport, telecommunications, businesses, citizens and the institutions that regulate or depend on digital infrastructure.
THREE DIRECTIONS
Develop protocols, software, AI, identity, networking, integrations, testing and production architecture.
Attack the technical and organisational assumptions. Study false reports, compromised participants, privacy, governance, AI failure and alternative designs.
Investigate healthcare, critical infrastructure, cybercrime economics, international cooperation, regulation, business, behaviour and society.
FEATURED STUDENT PROJECTS
Try to break the concept. Test realistic traffic, malicious participants, failures, overhead, false positives and operational limits.
More info →We currently experiment with urg_ptr in the TCP header plus richer information out-of-band. Find a better interoperable design.
How should local evidence, observations from many networks, confidence, explainability and human oversight fit together?
More info →Can TaraSec itself be attacked through false reports, compromised partners or manipulation of trust and reputation?
More info →Study IPv6, Layer-2 deployment, NAT, routers and how TaraSec can coexist with infrastructure it does not control.
More info →Turn existing products into TaraSec sensors and consumers of TaraSec information rather than replacing them.
More info →Who benefits, who pays, why would ISPs join, how should it be sold, standardized and governed — and could Grimstad become a global centre for collaborative cybersecurity?
More info →DISCUSS IT BEFORE YOU BUILD IT
Bring an idea, objection or research question. Ask ChatGPT to explain the architecture, inspect the current source, argue against an assumption and help turn the discussion into a testable student project.
The public TaraSec core source is in github.com/oyst12rsas/taransvar. Give ChatGPT that exact repository name so it knows what to inspect. If a ChatGPT session cannot open GitHub directly, link or upload the relevant files from the repository.
“I want to explore a student project about TaraSec. Inspect the current public source and documentation in github.com/oyst12rsas/taransvar. Explain where my idea fits, identify the relevant components and assumptions, and help me design an experiment that could prove the idea wrong.”
“What does the current source actually do?”
“What would break if TaraSec used this protocol instead?”
“Which files and services would this idea affect?”
“Design an experiment that could prove this assumption wrong.”
Important: ChatGPT does not automatically change TaraSec. An idea worth keeping should be submitted to the project, and any proposed source change must still be reviewed and tested.
IDEAS ARE NOT CODE CHANGES
A student should not need to know which file to edit. The useful path is:
Discuss → challenge → refine → submit idea → investigate → propose change → implement → review.
New ideas should be preserved as structured proposals even when nobody is ready to change code. Rejected ideas are useful too: documenting why an approach was tested and rejected prevents the next student from rediscovering the same dead end.
A WORKING PLATFORM
The experimental environment includes Linux gateways and VMs, VPN-connected test networks, C/Perl/PHP/database components, firewall and honeypot telemetry, persistent owner/unit identity work, AI assessment and operational web infrastructure.
Projects can improve it, replace parts of it, measure it, attack it or conclude that an assumption does not hold. Negative findings are useful results.
BRING YOUR OWN QUESTION
The examples are starting points. Students and researchers from technical, health, business, legal, social-science, public-policy and other relevant fields are welcome to propose their own questions together with their academic supervisor.
Øystein Torsås
+47 99647892
oystein@taransvar.no
TaraSec is an initiative of Taransvar, Norwegian organisation no. 992 132 027.