ANMAS
AI Network Monitoring & Analysis System
ANMAS is Intelligency's flagship parent brand — positioned as "the ChatGPT for PCAP files." Encompassing ANMAS-IoT and ANMAS-MASA (Mobile), SLM + RAG automatically produces MITRE ATT&CK-aligned packet forensics reports inside enterprise environments.
Two ANMAS Product Lines
For the two most common device attack surfaces, ANMAS provides dedicated editions — deployable independently or together.
IoT Edition
Network security analysis for industrial control, smart buildings, manufacturing IoT, and edge devices. Detects abnormal traffic, unknown protocol abuse, and firmware-layer risks.
Mobile Edition (MASA)
Network packet analysis for iOS, Android, and HarmonyOS smartphones. No app, no USB — find the threats hidden in your phone.
5 Use Cases
Mobile and IoT devices are the most overlooked security gaps today. ANMAS provides tailored detection scenarios for five high-risk roles.
Executives
Confidential conversation & decision data
Government Officials
National-security-grade defense
Business Travel
Overseas connection risk detection
R&D Staff
IP and patent data protection
Routine Check
Periodic device health checks
Three Core Strengths
100% Non-Intrusive
No app installed on the device, no USB, no settings change. Complete the check with the device in original state — total user privacy protection.
AI Dual-Engine
Cloud LLM matches global threat intelligence in depth; local SLM identifies abnormal packets in real time. Sensitive data never leaves your domain.
ISO-27001 Compliance Reports
Auto-generated reports follow international ISMS format — usable for internal/external audits and compliance filings.
12 Threat Detections・3 Categories
The 12 most common and hardest-to-detect abnormal network activities on mobile and IoT devices, organized into three threat categories: data exfiltration, privacy surveillance, and system intrusion.
① Covert Communication & Data Exfiltration
How malware quietly moves sensitive data out of your network
② Surveillance & Privacy Theft
How attackers eavesdrop, track and hijack identity via mobile
③ Advanced Threats & Malware Fingerprinting
System-level attack detection and known-malware sample matching
AI Dual-Engine・Hybrid Cloud-Local AI Architecture
Combining the breadth of large cloud models with the privacy advantages of local models — the biggest differentiator from competing products.
LLM + RAG
Retrieval-augmented large language models match against global threat intelligence to identify novel APT patterns in depth.
SLM Local Engine
Lightweight models running locally — sensitive packets never go to the cloud, complying with data sovereignty and privacy regulations.
★ Detailed web SVG architecture diagram (redrawn from ANMAS PDF p.11, including IoT and MASA editions) will be updated at the next release.
ANMAS Core Technical Specs
SLM fine-tuning + RAG-enhanced retrieval enables deep packet analysis on local hardware.
SLM Fine-Tune + RAG Retrieval
ANMAS uses SLM models with fine-tuning and RAG-enhanced retrieval, performing AI packet analysis on local CPU or GPU.
2,400+ PCAP Training Samples
Training dataset includes exemplary malware samples from 2020–2026, over 2,400 PCAP files (malware + normal traffic) and 80 GB of AI tag data.
Nvidia DGX Spark 128 GB
Local hardware: Nvidia DGX Spark 128 GB VRAM. Enhanced edition supports enterprise cascading across multiple DGX Spark devices.
MITRE ATT&CK Aligned
Detects T0843, T1048, T1071, T1078, T1102, T1132, T1571, T1572, T1595 and produces packet forensics reports with the corresponding MITRE IDs.
4 Language Reports
ANMAS supports English, Traditional Chinese, Japanese and Vietnamese natively, matching multi-region enterprise security team needs.
Local / Cloud Switchable
Local AI: Phi-4, Gemma, GPT-OSS. Cloud AI: ChatGPT, Gemini, Claude-compatible APIs. Switch freely based on data-sovereignty requirements.
MASA・Mobile & IoT Extension Module
ANMAS-MASA uses Virtual WIFI to inspect multiple smartphones, tablets and IoT devices in parallel (up to 30 devices, 24+ hours).
Virtual WIFI
MASA provides Virtual WIFI. The mobile device only needs Airplane Mode + WIFI on — no app installation, no USB connection. Sensitive data stays fully protected.
Multi-Device Parallel Inspection
Supports iPhone, Android, Arduino, Raspberry Pi, ESP. Inspect multiple devices simultaneously across 24+ hour windows.
Communication Chip Detection
Records the chip manufacturer information and confirms whether its network activity complies with supply chain regulations.
Voice Eavesdropping Detection
By comparing the phone's muted state with packet traffic, malware-driven background mic relays can be discovered.
Intermittent Beeping Detection
LLM behavior analysis catches malware that sends short signals to its monitor every few seconds to minutes.
C&C Relay Detection
To evade allow/deny lists, many malware route through C2 relay hosts. MASA's LLM analysis surfaces these relays early.
Large Upload Detection
For malware continuously sending screens and files back to attackers, AI flags abnormal bandwidth spikes.
Traffic Micro-Variation Alerts
First/second-order differences on packet time-length polynomials detect slow APT attacks and low-volume file exfiltration that humans cannot see.
Drone / UAV & IoT Supply Chain Communication Inspection
Traditional supply chains rely only on producer-provided documents — leaving information gaps and hidden risks. UAV communication modules require a more comprehensive inspection framework.
Flight Control Module
Signal reception, computation and flight control — the most critical communication node on any UAV.
Power Drive Module
Motor, electronic speed controller (ESC) and propeller control-signal communication.
Smart Imaging Module
AI imaging chips, infrared (IR) cameras and camera-module data transmission.
Comm & Positioning Module
Long-range wireless link, GNSS positioning and obstacle-avoidance radar comms security.
Power Management Module
High-efficiency PRM regulators and DC-DC converters telemetry.
5 Supply-Chain Safety Mechanisms
Origin
Origin documents & import/export records verification
Communication
UAV/USV comm-module runtime data
Site
Office & production-line network monitoring
Mobile
MDM-paired detection of hidden mobile comms
Personnel
Office sensitive-file control mechanisms
IoT Device Risk Case: iLife A11 Robot Vacuum
In 2025, engineer Harishankar Narayanan discovered that the iLife A11 robot vacuum had been uploading users' 3D indoor maps, furniture positions and movement tracks to servers in mainland China — with no notification in the companion app. Reverse engineering revealed Android (Linux) with ADB wide open and a "remote shutdown" command in internal logs. This is precisely the kind of invisible communication risk that ANMAS / MASA is designed to detect.
4-Step Workflow・AI-Generated Report
From packet capture to auditable report output, AI completes the entire workflow without manual intervention.
Choose Mode
One-off / Continuous / Travel mode
Scan Device
Non-intrusive packet capture
AI Analysis
Dual-engine matching and behavior modeling
AI Report
Auto-generates ISO compliance report, compared with prior records
★ Hi-res workflow screenshots (from ANMAS PDF p.10–13) will be updated at the next release.
ISO-27001 Compliance Report
Complete, auditable, downloadable — AI-generated outputs become direct evidence of compliance.
Executive Summary
Overall risk score, threat-level distribution, and trend chart compared with previous reports.
Detail Table
Item-by-item anomaly details: source IP, destination, timeline, AI confidence.
Recommended Actions
Specific remediation suggestions for detected risks, mapped to ISO-27001 controls.
Patents and Certifications
ANMAS's core technology is built on multiple granted invention patents and is fully aligned with the ISO-27001 international ISMS standard.
Method & system for non-intrusive network packet analysis
External packet capture with AI behavior analysis identifies abnormal communications without any app installation (covers IoT and mobile).
Hybrid cloud-local AI dual-engine security analysis architecture
Hybrid LLM + SLM architecture balances depth of analysis with data sovereignty.
RAG-based threat intelligence matching method
Application of retrieval-augmented generation to security, improving identification of novel threats.
ISO-27001 Aligned
Compliant with international ISMS standard
AI Algorithm Validation
Third-party AI dual-engine validation
ISO-27017 Cloud Security
Cloud service information security
APPI Compliant
Japan personal information protection
★ Hi-res scans of AI and ISO certificates will be updated before official launch.
