LOCAL AI · ZERO CLOUD · REAL-TIME THREAT DETECTION

AI Network & OT Malicious-packet Analysis System

ANMAS & MASAS combine 20+ years of NSPA packet forensics research with Huge Diamond engineering. Powered by fine-tuned Small Language Models (SLMs) and RAG retrieval, deep PCAP analysis is executed 100% on-premises, detecting APTs, zero-day threats, and SCADA/OT protocol anomalies with sensitive data never leaving your network.

SLM Language Model RAG Retrieval On-prem Inference Zero Cloud Dependency MITRE ATT&CK Mapping OT / SCADA Defense
// 01 · Product Overview

What is ANMAS & MASAS?

ANMAS is an AI-driven deep packet analysis system. A fine-tuned Small Language Model (SLM) paired with Retrieval-Augmented Generation (RAG) runs entirely on local hardware, no cloud upload required, protecting your most sensitive data. It connects directly to NAS packet directories, continuously analyzes large volumes of daily PCAP files, and automatically generates structured security reports mapped to the MITRE ATT&CK framework.

// 01

Fine-tuned AI Models

Trained on 400+ malware samples and 5,000+ PCAP patterns with continuous learning (LoRA/QLoRA), deep inference runs on your own hardware.

GPT-OSS · GEMMA · PHI4 · GGUF
// 02

Automated Bulk Packet Pipeline

Connects directly to packet directories or NAS devices, continuously processing accumulated PCAP files and auto-generating reports, dramatically reducing SOC workload.

PCAP PIPELINE · 24/7
// 03

MITRE ATT&CK Mapping

Automatically flags lateral movement, covert channels and other threat patterns, mapping anomalies to techniques such as T1048, T1486 and T0843 with clear remediation guidance.

T1048 · T1486 · T1071 · T0843
// 04

Fully Optimized for On-prem

Native support for NVIDIA DGX Spark, compatible with LM Studio, Ollama and open frameworks. Sensitive data never leaves your premises, ISO-27001 compliant.

AIR-GAPPED · ISO-27001

ANMAS Benchmark Metrics

99.2%
Detection Accuracy
99.5%
Recall
98.7%
Precision
99.1%
F1 Score
// 02 · Threat Scenarios

What threats can ANMAS detect?

Traditional IDS/IPS struggle to spot low-and-slow covert attacks within massive traffic volumes. ANMAS specializes in identifying malicious behavior hidden inside seemingly normal communications, automatically mapped to MITRE ATT&CK.

C2

Covert APT Communications

Long-dwelling APT actors using low-rate, covert C2 channels disguised as normal enterprise traffic.

EXFILTRATION

Data-theft Transmissions

Infected endpoints exfiltrating sensitive data, detect data-leak behavior in outbound packets.

RANSOMWARE

Ransomware Encryption Activity

SMB access-denied anomalies and mass file-encryption behavior, early warning of lateral ransomware spread.

SCANNING

Suspicious Network Scanning

Anomalous ARP and port scans, recon activity detected in the early stages of an attack.

// 03 · MASAS Mobile & OT Defense

MASAS Mobile & OT/SCADA Security System

MASAS inspects mobile devices (iPhone/Android), IoT modules, and critical industrial control equipment (IED, PLC, OPC, HMI, MTU, RTU, DAS, BOM) via virtual Wi-Fi and local AI inference without agent installation or USB connection.

📱 MASAS MOBILE / IOT

Smartphone & IoT Diagnostics

Post-travel mobile security checks, corporate audit, and IoT chip vendor verification. Parallel inspection of up to 30 devices simultaneously for beaconing, GPS tracking, and trojan comms.

🏭 MASAS OT / SCADA

Critical Infrastructure & ICS Defense

Analyzes Modbus and DNP3 industrial protocols in real time. Detects HMI command tampering, OPC elevation of privilege (EoP), and DoS floods in air-gapped environments.

// 04 · Comparison

Cloud AI vs ANMAS Local SLM

Where cloud LLMs suffer from privacy risks, latency, and huge hardware footprint, ANMAS solves every challenge with a lightweight SLM purpose-built for network PCAP forensics.

Criteria ☁️ Cloud AI (LLM) 🛡️ ANMAS / MASAS (SLM)
Unknown Threat Detection ✗ Reactive (known signatures only) ✓ Real-time sub-millisecond anomaly detection
Sensitive Data Privacy ✗ Data passes through public cloud ✓ 100% On-premises, zero cloud data leaks
Detection Latency ✗ Internet round-trip latency ✓ Sub-millisecond local inference
On-premise Deployment ✗ Too large to deploy locally ✓ Runs on commodity servers or QNAP NAS
PCAP Specialization ✗ General-purpose model (hallucination risk) ✓ PCAP-specialized, 99.2% high accuracy
OT / SCADA Protocol Support ✗ Not supported ✓ Modbus / DNP3 protocol supported
// 05 · Deployment Plans

Two deployment options

Whether you choose the high-performance split architecture or the streamlined all-in-one box, packet data is processed 100% on-premises.

Plan A: Integrated

INTEGRATED
QNAP NAS + NVIDIA DGX Spark GB10
  • 128 GB unified memory | Grace Blackwell Superchip
  • Scalable split deployment: NAS handles PCAP storage & scheduling, DGX Spark dedicated to AI inference
  • Supports large and extra-large LLM models
Best for: Large enterprises / SOC centers / Financial institutions

Plan B: Flagship All-in-One

FLAGSHIP ALL-IN-ONE
GPU-Equipped QNAP NAS
  • ≥ 48 GB VRAM (RTX 6000 ADA / RTX Pro 6000 class)
  • Single-box integration: packet capture and AI analysis on the same device, lower rack space and power costs
  • Runs small-to-mid SLMs (7B~34B), seamless upgrade path to Plan A
Best for: Mid-size enterprises / MSSPs
// 06 · Developer

About NSPA (Developer)

ANMAS & MASAS are commercialized AI security solutions backed by 20+ years of research from the Network Packet Analysis Security Association (NSPA).

20+ Years Research & 5,000+ PCAPs

Founded in 2002, holding over 5,000 PCAP samples and 400+ malware behavioral profiles.

NSPA Class A~D Certifications

Establishes professional packet analysis certifications for security engineers and researchers.

Global Network

Backed by NSPA International (nspacert.org), NSPA Taiwan (nspa-cert-tw.org), and NSPA Japan (nspacert.jp).

// 07 · Purchase & POC

Where to buy & request a POC

ANMAS is developed by HugeDiamond and brought to market by master distributor Sanwan together with QNAP and Spes. Enterprises, SOC providers, research institutions and government agencies are welcome to contact us for purchase or proof-of-concept evaluation.

MANUFACTURER
HugeDiamond
ANMAS Manufacturer · Core Technology

The maker of ANMAS, specialists in network packet forensics and AI-driven security analysis technology.

🌐 www.hugediamond.net
MASTER DISTRIBUTOR
Sanwan (三丸)
Packet Forensics, Security & Integration · Sales Contact

Master distributor of ANMAS. Packet forensics expertise, AI model fine-tuning and security consulting, your technical POC liaison.

✉ [email protected]
Spes
System Integration & Services · Sales Contact

Product sales, system integration, deployment planning and managed services. Email us to book a demo or request a POC.

✉ [email protected] ✉ [email protected]
QNAP Systems
Joint Solution Partner

Enterprise storage, networking, servers and AI hardware platform, providing the NAS, ADRA NDR and GPU foundation.

CyberQ
Security Media Partner

Security trends and solution coverage, follow the latest ANMAS news and events.

Book a demo · Contact the sales team

Email us to schedule an online or on-site demonstration of ANMAS.