Jev in production › SQL and data pipelines

Jev IDS

Jev classifies network flow records as attack or benign on the NSL-KDD dataset; vendor claims 7.7x faster than an LLM at similar precision (author).

Open on GitHub ↗

7.7xmeasured against a baseline, as published by the source
Use
SQL and data pipelines
Industry
Security
Form
Open-source tool
Stage
Beta
Listed
2026-10-01
Found via
github
Repository
jev-sec/jev-ids
Stars
18
Forks
1
Last push
2026-10-10
Language
Python
License
MIT

The README opens with

Intrusion detection in one request. Show TypeSafe's Jev one network flow and five labeled examples. It answers whether the flow is an attack and which kind, in half a second, with no text to parse.

Jev IDS was tested on NSL-KDD, a reference benchmark of the cybersecurity community, against a state-of-the-art LLM (Gemini 3.6 Flash on Vertex AI), a classic machine-learning model (Random Forest) and an unsupervised one (Isolation Forest): 2,000 flows, three seeds, k from 0 to 8 examples per category. Given the same five examples (k = 1), Jev IDS was:

Badge

For the project's own README, linking back here:

Listed in Jev in production

Also used for sql and data pipelines