Build TaraSec
Develop AI assessment, distributed software, APIs, databases, identity mechanisms, networking, protocols, sensor integration, operator interfaces, testing and production architecture.
RESEARCH • BACHELOR'S • MASTER'S • PHD
TaraSec is a working experiment in collaborative Internet security. Firewalls, honeypots and other tools can become sensors in a wider network, while identity, AI, software, organisations and policy determine how observations become accountable action. The consequences reach far beyond cybersecurity.
THE BIGGER QUESTION
What happens if malicious Internet activity can be identified and acted upon much closer to its originating device, while preserving the separation between technical identity and personal identity?
That question matters to hospitals and connected health services, government, banking, energy, transport, telecommunications, businesses, citizens and the institutions that regulate or depend on digital infrastructure.
SECURITY-POLICY AGNOSTIC
TaraSec is intended as a framework and template for sharing accountable, unit-level security information between participating networks. It does not prescribe how a participant must protect its systems.
Each participant remains free to decide which signals it trusts and what action, if any, those signals should trigger. TaraSec information could feed a Zero Trust architecture, conventional firewall, IDS/IPS, SIEM or SOC workflow, AI security system, access-control decision, rate limiter, quarantine mechanism, monitoring system or another security design.
This makes TaraSec + Zero Trust one research direction among many: how can accountable network-origin and unit-level signals become additional inputs to continuous authentication, authorization and risk decisions without making TaraSec itself the policy engine?
THREE DIRECTIONS
Develop AI assessment, distributed software, APIs, databases, identity mechanisms, networking, protocols, sensor integration, operator interfaces, testing and production architecture.
Attack the technical and organisational assumptions. Study false reports, compromised participants, privacy, law, ethics, governance, accountability, AI failure and whether another architecture would work better.
Investigate consequences for healthcare, public administration, critical infrastructure, finance, cybercrime economics, international cooperation, regulation, business and society.
MANY DISCIPLINES
Evidence correlation, confidence, explainability, anomaly detection, model evaluation, adversarial manipulation, false-positive control and human oversight.
Distributed architecture, APIs, databases, reliability, observability, testing, deployment and migration from prototypes to production-quality systems.
Gateways, routing, IPv4/IPv6, protocols, attribution, sensors, firewalls, honeypots, authentication, cryptography and attack resistance.
Study how TaraSec signals can complement continuous verification, identity-aware access, segmentation and risk-based authorization — or compare Zero Trust with entirely different participant-defined security models.
Study how collaborative security could affect hospitals, patient services, connected medical equipment, health-sector availability, integrity and resilience.
Public digital services, institutional responsibility, distributed authority, accountability, cross-border cooperation and appropriate roles for public and private actors.
Explore consequences for energy, water, transport, telecommunications, maritime systems, industrial environments and other infrastructure where Internet disruption has physical consequences.
Fraud, payment infrastructure, service availability, digital identity, risk allocation and how better source-side intervention might change attack economics.
Participation incentives, business models, partnerships, rollout strategy, organisational design, network effects, market barriers and paths to global adoption.
Personal-data boundaries, pseudonymous identifiers, proportionality, due process, appeals, jurisdiction, responsibility and safeguards against misuse.
Cybercrime incentives, externalities, societal cost, regulation, public-sector adoption and whether collaborative attribution changes the economics of abuse.
Study trust, adoption and how attackers, users, organisations and network operators change behaviour when malicious activity becomes more accountable.
Make security evidence and AI reasoning understandable, design usable operator workflows, communicate uncertainty and build trust without overstating what the system knows.
A WORKING PLATFORM
The experimental environment already includes NetBird and WireGuard networks, Linux VMs and gateways, C/Perl/PHP/database components, firewall and honeypot telemetry, a unit-identity model, AI assessment work and operational web infrastructure.
Projects can improve it, replace parts of it, measure it, attack it, study its consequences or conclude that an assumption does not hold. Negative findings are useful results.
EXAMPLE QUESTIONS
Combine identity, history and observations into evidence, confidence and recommendations while preserving auditability and meaningful human control.
Design stable technical identifiers that do not expose customer identity and remain useful across address changes, NAT, roaming and independent networks.
Compare secure in-band and out-of-band mechanisms, interoperability, authenticity, performance and failure modes.
Test whether accountable unit-level network signals improve continuous risk and access decisions, where they should remain advisory, and how trust in the signal itself should be established.
Model or test how earlier source-side identification and intervention could affect resilience, patient-facing systems, connected devices and incident response.
Design governance for reports, disputes, malicious participants, privacy responsibility, AI oversight and authority across independent organisations and jurisdictions.
Study whether increasing accountability and shortening the path from detection to source-side action changes attacker cost, defender cost and incentives.
Investigate who gains value, who bears cost, what motivates ISPs and institutions to participate and which commercial, non-profit or public structures could reach critical mass.
Deploy realistic scenarios, introduce malicious nodes and failures, measure overhead and latency, and identify technical or organisational limits.
BRING YOUR OWN QUESTION
The examples are starting points. Students and researchers from technical, health, business, legal, social-science, public-policy and other relevant fields are welcome to propose their own questions together with their academic supervisor.
Øystein Torsås
+47 99647892
oystein@taransvar.no
TaraSec is an initiative of Taransvar, Norwegian organisation no. 992 132 027.