RESEARCH • BACHELOR'S • MASTER'S • PHD

Study what a safer Internet could change.

TaraSec is a working experiment in collaborative Internet security. Firewalls, honeypots and other tools can become sensors in a wider network, while identity, AI, software, organisations and policy determine how observations become accountable action.

THE BIGGER QUESTION

Internet security affects nearly every part of society.

What happens if malicious Internet activity can be identified and acted upon much closer to its originating device, while preserving the separation between technical identity and personal identity?

That question matters to hospitals, government, banking, energy, transport, telecommunications, businesses, citizens and the institutions that regulate or depend on digital infrastructure.

You do not have to believe TaraSec works.
A valuable student project may be finding where an assumption fails — and demonstrating it experimentally.

THREE DIRECTIONS

Build it. Challenge it. Study what it could change.

01

Build TaraSec

Develop protocols, software, AI, identity, networking, integrations, testing and production architecture.

02

Challenge TaraSec

Attack the technical and organisational assumptions. Study false reports, compromised participants, privacy, governance, AI failure and alternative designs.

03

Study the consequences

Investigate healthcare, critical infrastructure, cybercrime economics, international cooperation, regulation, business, behaviour and society.

FEATURED STUDENT PROJECTS

Seven starting points. Many more underneath.

Will TaraSec actually work?

Try to break the concept. Test realistic traffic, malicious participants, failures, overhead, false positives and operational limits.

More info →

Tagging & threat-information exchange

We currently experiment with urg_ptr in the TCP header plus richer information out-of-band. Find a better interoperable design.

More info →

AI threat assessment — local & global

How should local evidence, observations from many networks, confidence, explainability and human oversight fit together?

More info →

Trust & attack resistance

Can TaraSec itself be attacked through false reports, compromised partners or manipulation of trust and reputation?

More info →

TaraSec, IPv6 & existing infrastructure

Study IPv6, Layer-2 deployment, NAT, routers and how TaraSec can coexist with infrastructure it does not control.

More info →

Firewalls, honeypots & proprietary systems

Turn existing products into TaraSec sensors and consumers of TaraSec information rather than replacing them.

More info →

From research to global deployment

Who benefits, who pays, why would ISPs join, how should it be sold, standardized and governed — and could Grimstad become a global centre for collaborative cybersecurity?

More info →
Show all project ideas
  • Persistent unit identity without exposing personal identity
  • Recovery: when and how should a unit lose an infection tag?
  • Local decision-making by service and risk level
  • Measuring whether TaraSec actually reduces attacks
  • Cybercrime economics and attacker adaptation
  • ISP incentives, trust tiers and reputation
  • Internet standards and governance
  • Legacy Internet compatibility and staged deployment
  • Layer-2 / non-DHCP deployment
  • Standard firewall and SIEM/SOC integration
  • Honeypot networks and forbidden-interaction monitoring
  • Security APIs for high-risk services
  • Security VPN for users outside participating ISPs
  • Linux, OpenWRT and distribution packaging
  • Responsible traffic prioritization under congestion
  • Availability / “off-grid” signaling
  • Cleaning up unnecessary Internet traffic
  • Privacy, law, ethics and dispute handling
  • Human response to infection warnings
  • Assistance ecosystem for infected users
  • Consequences for healthcare and critical infrastructure
  • Government adoption and public digital services
  • Business models and commercialization
  • What new services become possible on a more accountable Internet?
  • Global cyber-security HQ in Grimstad — what would it take?

Open the project catalogue →

DISCUSS IT BEFORE YOU BUILD IT

Challenge TaraSec with ChatGPT.

Bring an idea, objection or research question. Ask ChatGPT to explain the architecture, inspect the current source, argue against an assumption and help turn the discussion into a testable student project.

The public TaraSec core source is in github.com/oyst12rsas/taransvar. Give ChatGPT that exact repository name so it knows what to inspect. If a ChatGPT session cannot open GitHub directly, link or upload the relevant files from the repository.

A useful starting prompt

“I want to explore a student project about TaraSec. Inspect the current public source and documentation in github.com/oyst12rsas/taransvar. Explain where my idea fits, identify the relevant components and assumptions, and help me design an experiment that could prove the idea wrong.”

Other questions to try

“What does the current source actually do?”
“What would break if TaraSec used this protocol instead?”
“Which files and services would this idea affect?”
“Design an experiment that could prove this assumption wrong.”

Important: ChatGPT does not automatically change TaraSec. An idea worth keeping should be submitted to the project, and any proposed source change must still be reviewed and tested.

IDEAS ARE NOT CODE CHANGES

Bring the thought first. Decide what to build later.

A student should not need to know which file to edit. The useful path is:

Discuss → challenge → refine → submit idea → investigate → propose change → implement → review.

New ideas should be preserved as structured proposals even when nobody is ready to change code. Rejected ideas are useful too: documenting why an approach was tested and rejected prevents the next student from rediscovering the same dead end.

A WORKING PLATFORM

Research does not have to start from a hypothetical system.

The experimental environment includes Linux gateways and VMs, VPN-connected test networks, C/Perl/PHP/database components, firewall and honeypot telemetry, persistent owner/unit identity work, AI assessment and operational web infrastructure.

Projects can improve it, replace parts of it, measure it, attack it or conclude that an assumption does not hold. Negative findings are useful results.

BRING YOUR OWN QUESTION

Discuss a student project, thesis or research collaboration.

The examples are starting points. Students and researchers from technical, health, business, legal, social-science, public-policy and other relevant fields are welcome to propose their own questions together with their academic supervisor.

Øystein Torsås
+47 99647892
oystein@taransvar.no

TaraSec is an initiative of Taransvar, Norwegian organisation no. 992 132 027.