Self-hosted behavioral security triage powered by local Qwen3-4B.
Your WAF sees requests. JevSec sees behavior.
Project page · Technical write-up · Benchmark · Architecture · Roadmap
Request-level WAFs are strong at matching exploit syntax and known request patterns. JevSec is aimed at the layer above that: short sequences of activity that become suspicious only when viewed together.
JevSec groups web activity into behavior windows, combines deterministic evidence with local-model decisions, and produces structured findings for human review.
Nginx / JSONL
│
▼
privacy-aware normalization
│
▼
behavior windows
│
├── deterministic rules
│
└── local Qwen3-4B
│
▼
BENIGN / REVIEW / HIGH_RISK / UNCERTAIN
│
▼
local SQLite + dashboard
JevSec complements a WAF. It does not replace WAF enforcement.
Deterministic held-out sample:
- 250 test windows
- 145 anomalous / 105 normal
- local Qwen3-4B
- thresholds selected from validation only
- shadow-mode review, not automated blocking
| System | Recall | Precision | Observed FPR | Anomalies detected |
|---|---|---|---|---|
| Static rules | 20.69% | 100.00% | 0.00% | 30 / 145 |
| Qwen3-4B | 23.45% | 97.14% | 0.95% | 34 / 145 |
| JevSec Hybrid | 26.90% | 97.50% | 0.95% | 39 / 145 |
Headline: Hybrid detected 39 vs 30 anomalous windows compared with the static-rule baseline — 30% more detections — while adding 1 false review among 105 normal windows.
For windows containing only one anomalous request mixed with normal requests, recall moved from 16.67% to 25.00% (+50% relative on that small subgroup).
Current risk-score AUROC remains weak:
- Static rules: 0.522
- Qwen3-4B: 0.473
- Hybrid: 0.454
So the result is evidence of incremental review coverage, not evidence that the model globally ranks risk well, detects unknown vulnerabilities in production, or outperforms a mature WAF at request-level exploit signatures.
See public benchmark v2, OWASP CRS comparison, and failure analysis.
| Traditional request-level WAF | JevSec | |
|---|---|---|
| Primary view | Individual HTTP request | Activity across a behavior window |
| Best fit | Request syntax / signatures / exploit indicators | Sequence, frequency, context, rule-model disagreement |
| Output | Allow / block / anomaly score | Review-oriented risk finding |
| Model | Usually not required | Local Qwen3-4B |
| Deployment | Enforcement layer | Shadow / triage layer |
| Relationship | Keep it | Add JevSec beside it |
The OWASP CRS report in this repository intentionally treats the two systems as complementary rather than as interchangeable products.
- Self-hosted — core application and decision workflow stay local.
- Local AI — current supported model is Qwen3-4B through local-jev.
- Privacy-aware context — the model receives whitelisted aggregate features rather than raw request paths, cookies, Authorization values, or user-agent strings.
- Behavior windows — aggregate by source IP and optional pseudonymous session identity.
- Explainable evidence — rule/model evidence is kept with each finding.
- Shadow mode first — no automatic firewall changes, bans, or request blocking.
- Reproducible evaluation — fixed seeds, validation-only threshold fitting, held-out test reporting.
Requirements: Python 3.12, uv, Git.
git clone https://github.com/ccjmcc/jevsec.git
cd jevsec
./scripts/demo.shOpen:
http://127.0.0.1:8000
The first local-model launch downloads Qwen3-4B weights.
UI-only smoke test:
SDE_DECISION_PROVIDER=mock ./scripts/demo.shsecurity-engine shadow --nginx /var/log/nginx/access.logShadow mode tails logs and emits structured findings. It does not block requests, change network configuration, or ban addresses.
On Linux:
cp .env.example .env
docker compose up --buildOn Apple Silicon, run local-jev natively if you want Apple GPU acceleration.
JevSec is intentionally conservative about what reaches the model:
- cookies are not retained;
- Authorization values are not retained;
- passwords and API keys are discarded;
- unknown JSON fields are discarded;
- user/session identifiers are pseudonymized before aggregation;
- model outputs are advisory.
Read PRIVACY.md, SECURITY.md, and THREAT_MODEL.md.
Research Alpha / shadow-mode engineering prototype.
The next milestones are real-world shadow validation, better sequence context, stronger risk ranking, and tighter WAF-signal fusion. See the roadmap.
- Architecture
- Usage
- Benchmark index
- OWASP CRS comparison
- Failure analysis
- Privacy
- Security policy
- Threat model
- Press kit
- Roadmap
- Contributing
MIT. See LICENSE.