Your WAF sees requests.
JevSec sees behavior.
JevSec is a self-hosted behavioral security triage layer that groups activity across requests, combines deterministic evidence with local Qwen3-4B decisions, and surfaces structured findings for human review.
More review coverage, with the caveats left visible.
On a deterministic held-out CSIC replay sample, JevSec Hybrid detected 39 anomalous windows versus 30 for the static-rule baseline. That is a 30% relative increase in detections on this sample, with one additional false review among 105 normal windows.
Keep the WAF. Add behavioral context beside it.
Request-level enforcement
Strong at known request syntax, exploit indicators, anomaly rules and immediate enforcement decisions.
- SQLi / XSS / traversal signatures
- Request anomaly scoring
- Inline allow / block
Cross-request review context
Aggregates short behavior windows and highlights sequence, frequency, context and rule/model disagreement.
- Behavior windows
- Local Qwen3-4B
- Human-review oriented findings
Privacy-aware by design.
Local model
Current decision provider is Qwen3-4B through a local Jev-compatible service.
Whitelisted context
Cookies, Authorization values, passwords and API keys are not retained for model context.
Shadow mode first
JevSec does not automatically ban IPs, alter firewall state or block requests.
Reproducible evaluation
Fixed seeds, validation-only threshold fitting, held-out reporting and explicit failure analysis.
The current model is not production-proven.
Current semi-real risk-score AUROC is 0.473 for Qwen3-4B and 0.454 for Hybrid. The current gain is incremental review coverage, not strong global risk ranking.
CSIC 2010 is an experimental dataset. Replay IPs, timestamps and response codes are evaluation scaffolding, not original production observations.
Request-level exploit syntax remains squarely in the domain of mature WAFs. JevSec is a complementary behavioral review layer.
Run it, break the assumptions, challenge the benchmark.
The most useful feedback right now is about false positives, missing behavior classes, sequence design and fair evaluation.