Skip to content

Sync score-adjusted rules after Sova corpus update - #85

Merged
haeter525 merged 1 commit into
ev-flow:masterfrom
pulorsok:sync-scores-after-sova
Jul 31, 2026
Merged

haeter525 merged 1 commit into
ev-flow:masterfrom
pulorsok:sync-scores-after-sova

Conversation

@pulorsok

Copy link
Copy Markdown
Member

The malware corpus now includes 14 Sova samples (MITRE S1062), so score_adjustment retrained the whole rule pool against it. This PR carries the resulting weights for 272 rules.

Only the score field changes — crime descriptions, API pairs, permissions, and labels are untouched. Verified: every changed line in the diff is a "score" line.

No new rule for Sova

Two candidate rules were drafted from the Sova samples and trained. Both were rejected:

Candidate API pair Outcome
Clipboard overwrite ClipData.newPlainText + ClipboardManager.setPrimaryClip Trained to -1.74 — legitimate apps (WhatsApp clones, React Native / Flutter clipboard modules) use the identical pair, so it fires more on benign than on malware
Suppress app icon getPackageManager + setComponentEnabledSetting Duplicates existing rule #79 (score +1.73)

Sova's report therefore rests on existing rules and is published separately in ev-flow/quark-engine#957.

Sample verification

Quark flagged 14 of 14 Sova samples as high-risk with these weights (detection rate 100%).

The malware corpus now includes 14 Sova samples, so score_adjustment
retrained the whole rule pool against it. This commit carries the
resulting weights for 272 rules. Only the score field changes; crime
descriptions, API pairs, permissions, and labels are untouched.

Sova itself ships no new rule. Two candidates were drafted and
trained, and both were rejected: a clipboard-overwrite pair
(ClipData.newPlainText + ClipboardManager.setPrimaryClip) trained to
-1.74 because legitimate apps use the same pair, and an icon-hiding
pair duplicated the existing rule ev-flow#79.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@haeter525
haeter525 merged commit cfb8759 into ev-flow:master Jul 31, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants