Taiwan Malware Analysis Net (抬丸郎)
Malware in Taiwan — IT2FO-based Hybrid Malware Behavior Analysis
TWMAN(Taiwan Malware Analysis Net,暱稱「抬丸郎」)是 TonTon Huang 碩士至博士初期開發的惡意程式動態分析平台,衍生自 SecureWorks 的 Truman 0.1,以 GNU GPL v3 授權開源。其核心創新是導入 Hierarchical Interval Type-2 Fuzzy Ontology (IT2FO) 模型,透過模糊邏輯語意表達惡意程式行為的不確定性,實現混合型惡意行為分析。
MiT(Malware in Taiwan)為 TWMAN 的進化版本,實作了 IT2FLS-based 惡意程式分析機制,進一步強化模糊本體論的推理能力,並在多個 IEEE 國際會議上發表成果。
TWMAN / MiT 採用分層式模糊本體論架構進行惡意程式行為的語意化分析:
基於 SecureWorks Truman 0.1 動態分析沙箱,GNU GPL v3 授權開源,可供學術界自由使用與擴充。
採用階層式 Interval Type-2 Fuzzy Ontology,以語意方式表達行為不確定性,超越傳統二元分類框架。
整合 Fuzzy Markup Language (FML),實現跨平台的惡意程式行為語意描述與交換標準。
演進路徑:TWMAN(2008–2011)→ TWMAN+(2012–2013)→ MiT(2013–2014)→ R2-D2(2017–2018,CNN 彩色視覺化)。
TWMAN / MiT 研究獲國科會 (NSC) 多項計畫及產學合作支持:
台英合作 — Type-2 Fuzzy Ontology for Malware Analysis
與英國合作:Type-2 模糊本體論惡意程式行為分析研究
Type-2 Fuzzy Ontology-based Intelligent Agent for Healthcare
基於 Type-2 模糊本體論的智慧型代理人系統(三年期計畫)
雲端資訊安全與防駭系統建置 (II)
Cloud information security & anti-hacker systems
NUTN × Acer eDC — 惡意程式分析平台
國立臺南大學 × Acer e-Enabling Data Center 產學合作計畫
NCHC 支援原始 TWMAN 運行期間:2008/11/17 – 2011/09/28
BBC
"Taiwan's front-line battle against mobile phone fraud" — 引用 TonTon Huang 在詐騙電話與行動惡意程式研究上的長期積累。
NVIDIA Developer Blog
"AI Improves the Frequency and Quality of Mobile App Notifications" — 深度介紹從 TWMAN 到 R2-D2 的 GPU 加速惡意程式分析研究歷程。
@article{twman2014softcomputing,
title={IT2FS-based ontology with soft-computing mechanism for malware behavior analysis},
author={Huang, TonTon Hsien-De and Lee, Chang-Shing and Wang, Mei-Hui and Kao, Hung-Yu},
journal={Soft Computing},
volume={18},
number={2},
pages={267--284},
year={2014},
publisher={Springer}
}