RESEARCH • BACHELOR'S • MASTER'S • PHD

Study what a safer Internet could change.

TaraSec is a working experiment in collaborative Internet security. Firewalls, honeypots and other tools can become sensors in a wider network, while identity, AI, software, organisations and policy determine how observations become accountable action. The consequences reach far beyond cybersecurity.

THE BIGGER QUESTION

Internet security affects nearly every part of society.

What happens if malicious Internet activity can be identified and acted upon much closer to its originating device, while preserving the separation between technical identity and personal identity?

That question matters to hospitals and connected health services, government, banking, energy, transport, telecommunications, businesses, citizens and the institutions that regulate or depend on digital infrastructure.

SECURITY-POLICY AGNOSTIC

TaraSec provides additional context — not a mandatory security policy.

TaraSec is intended as a framework and template for sharing accountable, unit-level security information between participating networks. It does not prescribe how a participant must protect its systems.

Each participant remains free to decide which signals it trusts and what action, if any, those signals should trigger. TaraSec information could feed a Zero Trust architecture, conventional firewall, IDS/IPS, SIEM or SOC workflow, AI security system, access-control decision, rate limiter, quarantine mechanism, monitoring system or another security design.

This makes TaraSec + Zero Trust one research direction among many: how can accountable network-origin and unit-level signals become additional inputs to continuous authentication, authorization and risk decisions without making TaraSec itself the policy engine?

THREE DIRECTIONS

Build it. Challenge it. Study what it could change.

01

Build TaraSec

Develop AI assessment, distributed software, APIs, databases, identity mechanisms, networking, protocols, sensor integration, operator interfaces, testing and production architecture.

02

Challenge TaraSec

Attack the technical and organisational assumptions. Study false reports, compromised participants, privacy, law, ethics, governance, accountability, AI failure and whether another architecture would work better.

03

Study what TaraSec could change

Investigate consequences for healthcare, public administration, critical infrastructure, finance, cybercrime economics, international cooperation, regulation, business and society.

MANY DISCIPLINES

A safer Internet is not only a computer-science problem.

AI & data science

Evidence correlation, confidence, explainability, anomaly detection, model evaluation, adversarial manipulation, false-positive control and human oversight.

Software & system development

Distributed architecture, APIs, databases, reliability, observability, testing, deployment and migration from prototypes to production-quality systems.

Networking & cybersecurity

Gateways, routing, IPv4/IPv6, protocols, attribution, sensors, firewalls, honeypots, authentication, cryptography and attack resistance.

Zero Trust & security architecture

Study how TaraSec signals can complement continuous verification, identity-aware access, segmentation and risk-based authorization — or compare Zero Trust with entirely different participant-defined security models.

E-health

Study how collaborative security could affect hospitals, patient services, connected medical equipment, health-sector availability, integrity and resilience.

Government & governance

Public digital services, institutional responsibility, distributed authority, accountability, cross-border cooperation and appropriate roles for public and private actors.

Critical infrastructure

Explore consequences for energy, water, transport, telecommunications, maritime systems, industrial environments and other infrastructure where Internet disruption has physical consequences.

Banking & finance

Fraud, payment infrastructure, service availability, digital identity, risk allocation and how better source-side intervention might change attack economics.

Business & management

Participation incentives, business models, partnerships, rollout strategy, organisational design, network effects, market barriers and paths to global adoption.

Law, privacy & ethics

Personal-data boundaries, pseudonymous identifiers, proportionality, due process, appeals, jurisdiction, responsibility and safeguards against misuse.

Economics & public policy

Cybercrime incentives, externalities, societal cost, regulation, public-sector adoption and whether collaborative attribution changes the economics of abuse.

Social & behavioural research

Study trust, adoption and how attackers, users, organisations and network operators change behaviour when malicious activity becomes more accountable.

Communication & UX

Make security evidence and AI reasoning understandable, design usable operator workflows, communicate uncertainty and build trust without overstating what the system knows.

A WORKING PLATFORM

Research does not have to start from a hypothetical system.

The experimental environment already includes NetBird and WireGuard networks, Linux VMs and gateways, C/Perl/PHP/database components, firewall and honeypot telemetry, a unit-identity model, AI assessment work and operational web infrastructure.

Projects can improve it, replace parts of it, measure it, attack it, study its consequences or conclude that an assumption does not hold. Negative findings are useful results.

EXAMPLE QUESTIONS

Choose a real unresolved problem.

Can AI assess unit-level risk responsibly?

Combine identity, history and observations into evidence, confidence and recommendations while preserving auditability and meaningful human control.

How should global unit identity work?

Design stable technical identifiers that do not expose customer identity and remain useful across address changes, NAT, roaming and independent networks.

How should networks exchange security signals?

Compare secure in-band and out-of-band mechanisms, interoperability, authenticity, performance and failure modes.

How does TaraSec complement Zero Trust?

Test whether accountable unit-level network signals improve continuous risk and access decisions, where they should remain advisory, and how trust in the signal itself should be established.

What changes for hospitals?

Model or test how earlier source-side identification and intervention could affect resilience, patient-facing systems, connected devices and incident response.

Who should be allowed to act?

Design governance for reports, disputes, malicious participants, privacy responsibility, AI oversight and authority across independent organisations and jurisdictions.

Can collaboration change cybercrime economics?

Study whether increasing accountability and shortening the path from detection to source-side action changes attacker cost, defender cost and incentives.

How could global adoption happen?

Investigate who gains value, who bears cost, what motivates ISPs and institutions to participate and which commercial, non-profit or public structures could reach critical mass.

Where does the architecture break?

Deploy realistic scenarios, introduce malicious nodes and failures, measure overhead and latency, and identify technical or organisational limits.

BRING YOUR OWN QUESTION

Discuss a student project, thesis or research collaboration.

The examples are starting points. Students and researchers from technical, health, business, legal, social-science, public-policy and other relevant fields are welcome to propose their own questions together with their academic supervisor.

Øystein Torsås
+47 99647892
oystein@taransvar.no

TaraSec is an initiative of Taransvar, Norwegian organisation no. 992 132 027.