Product Lineup

Two ANMAS Product Lines

For the two most common device attack surfaces, ANMAS provides dedicated editions — deployable independently or together.

IoT
ANMAS-IoT

IoT Edition

Network security analysis for industrial control, smart buildings, manufacturing IoT, and edge devices. Detects abnormal traffic, unknown protocol abuse, and firmware-layer risks.

M
ANMAS-MASA

Mobile Edition (MASA)

Network packet analysis for iOS, Android, and HarmonyOS smartphones. No app, no USB — find the threats hidden in your phone.

Use Cases

5 Use Cases

Mobile and IoT devices are the most overlooked security gaps today. ANMAS provides tailored detection scenarios for five high-risk roles.

Executives

Confidential conversation & decision data

Government Officials

National-security-grade defense

Business Travel

Overseas connection risk detection

R&D Staff

IP and patent data protection

Routine Check

Periodic device health checks

Core Strengths

Three Core Strengths

100% Non-Intrusive

No app installed on the device, no USB, no settings change. Complete the check with the device in original state — total user privacy protection.

AI Dual-Engine

Cloud LLM matches global threat intelligence in depth; local SLM identifies abnormal packets in real time. Sensitive data never leaves your domain.

ISO-27001 Compliance Reports

Auto-generated reports follow international ISMS format — usable for internal/external audits and compliance filings.

Detection Capabilities

12 Threat Detections・3 Categories

The 12 most common and hardest-to-detect abnormal network activities on mobile and IoT devices, organized into three threat categories: data exfiltration, privacy surveillance, and system intrusion.

① Covert Communication & Data Exfiltration

How malware quietly moves sensitive data out of your network

Intermittent comms (Beeping)
C2 relay
Mass data upload
Encrypted channel disguise
DNS tunneling abuse
Unknown overseas connections

② Surveillance & Privacy Theft

How attackers eavesdrop, track and hijack identity via mobile

Voice forwarding (mic eavesdrop)
Location leak alerts
SIM hijack indicators

③ Advanced Threats & Malware Fingerprinting

System-level attack detection and known-malware sample matching

APT slow attack
System API anomalies
Known malware fingerprints
Architecture

AI Dual-Engine・Hybrid Cloud-Local AI Architecture

Combining the breadth of large cloud models with the privacy advantages of local models — the biggest differentiator from competing products.

Cloud Engine

LLM + RAG

Retrieval-augmented large language models match against global threat intelligence to identify novel APT patterns in depth.

FUSION
Local Engine

SLM Local Engine

Lightweight models running locally — sensitive packets never go to the cloud, complying with data sovereignty and privacy regulations.

★ Detailed web SVG architecture diagram (redrawn from ANMAS PDF p.11, including IoT and MASA editions) will be updated at the next release.

Technical Specs

ANMAS Core Technical Specs

SLM fine-tuning + RAG-enhanced retrieval enables deep packet analysis on local hardware.

SLM Fine-Tune + RAG Retrieval

ANMAS uses SLM models with fine-tuning and RAG-enhanced retrieval, performing AI packet analysis on local CPU or GPU.

2,400+ PCAP Training Samples

Training dataset includes exemplary malware samples from 2020–2026, over 2,400 PCAP files (malware + normal traffic) and 80 GB of AI tag data.

Nvidia DGX Spark 128 GB

Local hardware: Nvidia DGX Spark 128 GB VRAM. Enhanced edition supports enterprise cascading across multiple DGX Spark devices.

MITRE ATT&CK Aligned

Detects T0843, T1048, T1071, T1078, T1102, T1132, T1571, T1572, T1595 and produces packet forensics reports with the corresponding MITRE IDs.

4 Language Reports

ANMAS supports English, Traditional Chinese, Japanese and Vietnamese natively, matching multi-region enterprise security team needs.

Local / Cloud Switchable

Local AI: Phi-4, Gemma, GPT-OSS. Cloud AI: ChatGPT, Gemini, Claude-compatible APIs. Switch freely based on data-sovereignty requirements.

MASA Module

MASA・Mobile & IoT Extension Module

ANMAS-MASA uses Virtual WIFI to inspect multiple smartphones, tablets and IoT devices in parallel (up to 30 devices, 24+ hours).

Virtual WIFI

MASA provides Virtual WIFI. The mobile device only needs Airplane Mode + WIFI on — no app installation, no USB connection. Sensitive data stays fully protected.

Multi-Device Parallel Inspection

Supports iPhone, Android, Arduino, Raspberry Pi, ESP. Inspect multiple devices simultaneously across 24+ hour windows.

Communication Chip Detection

Records the chip manufacturer information and confirms whether its network activity complies with supply chain regulations.

Voice Eavesdropping Detection

By comparing the phone's muted state with packet traffic, malware-driven background mic relays can be discovered.

Intermittent Beeping Detection

LLM behavior analysis catches malware that sends short signals to its monitor every few seconds to minutes.

C&C Relay Detection

To evade allow/deny lists, many malware route through C2 relay hosts. MASA's LLM analysis surfaces these relays early.

Large Upload Detection

For malware continuously sending screens and files back to attackers, AI flags abnormal bandwidth spikes.

Traffic Micro-Variation Alerts

First/second-order differences on packet time-length polynomials detect slow APT attacks and low-volume file exfiltration that humans cannot see.

Drone / UAV Supply Chain

Drone / UAV & IoT Supply Chain Communication Inspection

Traditional supply chains rely only on producer-provided documents — leaving information gaps and hidden risks. UAV communication modules require a more comprehensive inspection framework.

Flight Control Module

Signal reception, computation and flight control — the most critical communication node on any UAV.

Power Drive Module

Motor, electronic speed controller (ESC) and propeller control-signal communication.

Smart Imaging Module

AI imaging chips, infrared (IR) cameras and camera-module data transmission.

Comm & Positioning Module

Long-range wireless link, GNSS positioning and obstacle-avoidance radar comms security.

Power Management Module

High-efficiency PRM regulators and DC-DC converters telemetry.

5 Supply-Chain Safety Mechanisms

1

Origin

Origin documents & import/export records verification

2

Communication

UAV/USV comm-module runtime data

3

Site

Office & production-line network monitoring

4

Mobile

MDM-paired detection of hidden mobile comms

5

Personnel

Office sensitive-file control mechanisms

IoT Device Risk Case: iLife A11 Robot Vacuum

In 2025, engineer Harishankar Narayanan discovered that the iLife A11 robot vacuum had been uploading users' 3D indoor maps, furniture positions and movement tracks to servers in mainland China — with no notification in the companion app. Reverse engineering revealed Android (Linux) with ADB wide open and a "remote shutdown" command in internal logs. This is precisely the kind of invisible communication risk that ANMAS / MASA is designed to detect.

Workflow

4-Step Workflow・AI-Generated Report

From packet capture to auditable report output, AI completes the entire workflow without manual intervention.

1

Choose Mode

One-off / Continuous / Travel mode

2

Scan Device

Non-intrusive packet capture

3

AI Analysis

Dual-engine matching and behavior modeling

4

AI Report

Auto-generates ISO compliance report, compared with prior records

★ Hi-res workflow screenshots (from ANMAS PDF p.10–13) will be updated at the next release.

Report Preview

ISO-27001 Compliance Report

Complete, auditable, downloadable — AI-generated outputs become direct evidence of compliance.

Executive Summary

Overall risk score, threat-level distribution, and trend chart compared with previous reports.

Detail Table

Item-by-item anomaly details: source IP, destination, timeline, AI confidence.

Recommended Actions

Specific remediation suggestions for detected risks, mapped to ISO-27001 controls.

Patents & Certifications

Patents and Certifications

ANMAS's core technology is built on multiple granted invention patents and is fully aligned with the ISO-27001 international ISMS standard.

★ TBDPatent number

Method & system for non-intrusive network packet analysis

External packet capture with AI behavior analysis identifies abnormal communications without any app installation (covers IoT and mobile).

★ TBDPatent number

Hybrid cloud-local AI dual-engine security analysis architecture

Hybrid LLM + SLM architecture balances depth of analysis with data sovereignty.

★ TBDPatent number

RAG-based threat intelligence matching method

Application of retrieval-augmented generation to security, improving identification of novel threats.

ISO-27001 Aligned

Compliant with international ISMS standard

AI Algorithm Validation

Third-party AI dual-engine validation

ISO-27017 Cloud Security

Cloud service information security

APPI Compliant

Japan personal information protection

★ Hi-res scans of AI and ISO certificates will be updated before official launch.

FAQ

Frequently Asked Questions

Does ANMAS truly require no app installed on the device?
Yes. ANMAS uses "external packet capture" — sampling device communications via trusted network nodes, then analyzing with AI. No software on the device, no USB, no settings change.
What's the difference between ANMAS-IoT and ANMAS-MASA?
Both share the same AI dual-engine and report standard. The difference is target devices and protocol handling: ANMAS-IoT covers industrial control / IoT (including unknown protocols); ANMAS-MASA covers smartphones (iOS/Android/HarmonyOS).
Will the check see my message contents?
No. ANMAS analyzes "network behavior patterns" (destinations, frequency, packet size, timing), not content. All data is de-identified, complying with APPI and PIPA.
How long does one health check take?
Standard one-off capture takes about 15–30 minutes; AI analysis and report generation about 1–2 hours. Travel mode supports continuous monitoring.
Which devices and systems are supported?
As ANMAS is non-intrusive, it supports any device communicating via IP networks: smartphones (iOS, Android, HarmonyOS), IoT and ICS (including major industrial protocols), and edge computing nodes.
What can I do when an anomaly is detected?
The report provides specific recommendations (isolate, wipe, deep inspect, etc.) for each anomaly. We also offer incident response consulting for high-risk events.
How is ANMAS different from MDM?
MDM focuses on "management" (policy, apps, remote control) and requires an agent on the device. ANMAS focuses on "detection" (identifying abnormal communications) and requires no installation. The two complement each other.

Ready to Give Your Devices a Full Health Check?

Get in touch — our consultant will arrange the ANMAS assessment and answer any compliance questions you have.

Contact Us