Software protection method, system, device and medium for Windows system

By creating protection drivers and registering callback functions under Windows system, monitoring and blocking process handles that do not comply with preset policies, the problem of lack of effective protection for malicious processes during software running in the existing technology is solved, and effective protection of the software is achieved.

CN114238947BActive Publication Date: 2025-06-24SUPCON TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202111450408.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-11-30
Publication Date
2025-06-24
Estimated Expiration
2041-11-30

AI Technical Summary

Technical Problem

The existing technology lacks effective protection for malicious processes when the software is running, cannot identify the initiator of the behavior, and cannot reasonably protect third-party software.

Method used

By creating a guard driver under Windows system, register a callback function to monitor the operation of creating a process handle, and cancel permissions for process handles that do not comply with the policy based on the preset guard policy.

Benefits of technology

It realizes effective operation protection for the software, can identify and block access to malicious processes, and supports protection of third-party software.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114238947B_ABST
    Figure CN114238947B_ABST
Patent Text Reader

Abstract

The present invention relates to a method for protecting the operation of software in a Windows system. The method includes: First, create a protection driver under the Windows system; Second, register, through the protection driver, a callback function for monitoring the creation of process handles; Then, obtain the target process information and / or source process information of the process handle; Finally, based on the target process information and / or source process information, for a process that does not conform to the preset protection policy, deny the permission of the process handle. The present invention is a software protection solution based on the Windows platform. By registering a callback function through the constructed protection driver to monitor the handles associated with all processes created by the system, and the permission of the handle can be changed to prevent specific access, providing effective operation protection for the protected software in the protection policy. Moreover, the present invention also provides a configuration modification function, supporting adding third-party programs to the protection policy and protecting them at any time.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of computer software security, and particularly to a software operation protection method, system, device, and medium for Windows systems. Background Art

[0002] The Windows operating system allows software to perform operations such as debugging and modifying other software programs during operation. This not only provides convenience for developers but also makes the software vulnerable to attacks. There are risks such as being maliciously debugged, injected, and forcibly closed during software operation.

[0003] Currently, the more commonly used protection method is to transform the target process. Under the Windows operating system, an application can call the system API to check whether it is in a debugged state, and can also hook some of its internal functions to check whether its own program has been maliciously injected or modified through algorithms. When these risks are detected, methods such as actively exiting can be taken to protect its own information from being stolen or tampered with. The protection technology based on the software itself must modify the software code. Therefore, for third-party provided software that cannot be modified, this method cannot be used for protection. General technologies also cannot identify the initiator of the behavior and are not applicable in situations where only specific objects are allowed to debug. At the same time, although some protection technologies can identify malicious operations, they lack effective countermeasures. Usually, the method selected when it is found that it has been debugged or injected is to actively exit the program, which is unacceptable in some application scenarios. Summary of the Invention

[0004] (1) Technical Problems to be Solved

[0005] In view of the above-mentioned shortcomings and deficiencies of the prior art, the present invention provides a software operation protection method, system, device, and medium for Windows systems, which solves the technical problems that the existing software protection technology lacks effective protection against malicious processes, cannot identify the initiator of the behavior, and cannot reasonably protect third-party software.

[0006] (2) Technical Solutions

[0007] To achieve the above object, the main technical solutions adopted by the present invention include:

[0008] In the first aspect, an embodiment of the present invention provides a software operation protection method for Windows systems, including:

[0009] Create a protection driver under the Windows system;

[0010] Register a callback function for monitoring the creation of process handles through the protection driver;

[0011] Obtain the target process information and / or source process information of the process handle based on the input parameters of the callback function and the PsGetCurrentProcessId function;

[0012] Based on the target process information and / or source process information, for processes that do not meet the preset protection policy, cancel the permissions of the process handle.

[0013] Optionally, after creating the protection driver under the Windows system, it further includes:

[0014] Create an interface configuration tool for communicating and interacting with the protection driver;

[0015] After logging in to the interface configuration tool using encryption verification, view and / or modify the protection policy stored in the protection driver through the interface configuration tool;

[0016] Wherein, binary encrypted data streams are used for information transfer between the interface configuration tools.

[0017] Optionally, registering a callback function for monitoring the creation of process handles through the protection driver includes:

[0018] After the protection driver starts, call the system api through the protection driver to register the callback function ObjectPreCallback, and keep the callback function ObjectPreCallback running continuously to monitor the creation of handles for all processes.

[0019] Optionally, the protection driver is set to start automatically with the Windows system.

[0020] Optionally, creating a process handle includes: creating a handle associated with each process for accessing the target program through the NtOpenProcess function.

[0021] Optionally, based on the target process information and / or source process information, for processes that do not meet the preset protection policy, canceling the permissions of the process handle includes:

[0022] Compare the target process information and / or source process information of the handle with the protection policy stored in the protection driver;

[0023] If it is confirmed as prohibited access, start the protection operation, and cancel the read, write, and close permissions of the handle for the target process.

[0024] Optionally, the level of the protection driver is ring0 level, and the level of the configuration tool program is ring3 level.

[0025] In a second aspect, an embodiment of the present invention provides a software operation protection system for a Windows system, including:

[0026] A program creation module, configured to create a protection driver under the Windows system and an interface configuration tool for communicating and interacting with the protection driver;

[0027] A function registration module, configured to register, through the protection driver, a callback function for monitoring the creation of a process handle;

[0028] A process information acquisition module, configured to obtain, by a user, target process information and / or source process information of a process handle based on the incoming parameters of the callback function and the PsGetCurrentProcessId function;

[0029] An authority judgment module, configured to cancel the authority of a process handle for a process that does not conform to a preset protection policy based on the target process information and / or source process information;

[0030] Wherein, binary encrypted data streams are used for information transmission between the interface configuration tools; and protection policies are stored in the protection driver.

[0031] In a third aspect, an embodiment of the present invention provides a software operation protection system for a Windows system, including:

[0032] At least one database;

[0033] And a memory communicatively connected to the at least one database;

[0034] Wherein, the memory stores instructions executable by the at least one database, and the instructions are executed by the at least one database so that the at least one database can execute a software operation protection method for a Windows system as described above.

[0035] In a fourth aspect, an embodiment of the present invention provides a computer-readable medium, on which computer-executable instructions are stored, and when the executable instructions are executed by a processor, a software operation protection method for a Windows system as described above is implemented.

[0036] (III) Advantageous Effects

[0037] The beneficial effects of the present invention are as follows: The present invention is a software protection solution based on the Windows platform. By constructing a protection driver to register callback functions to monitor the handles associated with all processes created by the system, and the permissions of the handles can be changed to prevent specific access, providing effective operation protection for the protected software in the protection policy. Moreover, the present invention also provides an interface configuration tool to implement the configuration modification function, supporting adding third-party programs to the protection policy and protecting them at any time. BRIEF DESCRIPTION OF THE DRAWINGS

[0038] Figure 1 It is a schematic flowchart of a software operation protection method for a Windows system provided by an embodiment of the present invention;

[0039] Figure 2 It is a specific flowchart of a software operation protection method for a Windows system provided by an embodiment of the present invention after step S1;

[0040] Figure 3 It is a specific flowchart of step S4 of a software operation protection method for a Windows system provided by an embodiment of the present invention;

[0041] Figure 4 It is a schematic diagram of the composition of a software operation protection system for a Windows system provided by an embodiment of the present invention;

[0042] Figure 5 It is a schematic diagram of the structure of a computer system of a software operation protection device for a Windows system provided by an embodiment of the present invention;

[0043] Figure 6 It is a schematic overall flowchart of a software operation protection method for a Windows system provided by an embodiment of the present invention.

[0044]

DESCRIPTION OF THE REFERENCE NUMERALS

[0045] 100: Software operation protection system for Windows system; 110: Program creation module; 120: Function registration module; 130: Process information acquisition module; 140: Permission judgment module;

[0046] 200: Computer system; 201: CPU; 202: ROM; 203: RAM; 202: First bus; 205: I / O interface; 206: Input part; 207: Output part; 208: Storage part; 209: Communication part; 210: Driver; 211: Removable medium. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0047] For a better explanation and understanding of the present invention, the following will describe the present invention in detail with reference to the accompanying drawings and through specific embodiments.

[0048] As Figure 1 shown, a software operation protection method for a Windows system proposed by an embodiment of the present invention includes: First, create a protection driver under the Windows system; Second, register a callback function for monitoring the creation of process handles through the protection driver; Then, obtain the target process information and / or source process information of the process handle based on the incoming parameters of the callback function and the PsGetCurrentProcessId function; Finally, based on the target process information and / or source process information, for processes that do not meet the preset protection policy, cancel the permissions of the process handle.

[0049] The present invention is a software protection solution based on the Windows platform. By registering a callback function through the constructed protection driver to monitor the handles associated with all processes created by the system, and the permissions of the handles can be changed to prevent specific access, providing effective operation protection for the protected software in the protection policy. And the present invention also provides an interface configuration tool to implement the configuration modification function, supporting adding third-party programs to the protection policy and protecting them at any time.

[0050] To better understand the above technical solution, the exemplary embodiments of the present invention will be described in more detail below with reference to the accompanying drawings. Although the exemplary embodiments of the present invention are shown in the drawings, it should be understood that the present invention can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided to enable a clearer and more thorough understanding of the present invention and to fully convey the scope of the present invention to those skilled in the art.

[0051] Specifically, the present invention provides a software operation protection method for a Windows system, including:

[0052] S1. Create a protection driver under the Windows system.

[0053] As Figure 2 shown, after step S1, it further includes:

[0054] F11. Create an interface configuration tool for communicating and interacting with the protection driver.

[0055] F12. After using the encrypted verification to log in to the interface configuration tool, view and / or modify the protection policy stored in the protection driver through the interface configuration tool.

[0056] Wherein, binary encrypted data streams are used for information transmission between the so-called interface configuration tools.

[0057] S2. Register a callback function for monitoring the creation of process handles through the protection driver.

[0058] Further, step S2 includes: After the protection driver is started, call the system api through the protection driver to register the callback function ObjectPreCallback, and keep the callback function ObjectPreCallback running continuously to monitor the creation of handles for all processes.

[0059] Further, creating a process handle includes: creating a handle for accessing the target program associated with each process through the NtOpenProcess function.

[0060] The protection driver is set to start automatically with the Windows system.

[0061] S3. Obtain the target process information and / or source process information of the process handle based on the incoming parameters of the callback function and the PsGetCurrentProcessId function.

[0062] Among them, both the callback function and the incoming parameters are defined by Windows. The incoming parameter is the structure _OB_PRE_OPERATION_INFORMATION, which contains members Operation, Flags, Object, ObjectType, CallContext, and Parameters. The present invention mainly uses the Operation member to judge whether the behavior is to create a handle, uses the Object member to obtain the information of the target process, and uses the Parameters member to implement permission adjustment. The PsGetCurrentProcessId function is a function provided by the Windows system and can be directly called in the above callback function.

[0063] In the above description, a handle is an identifier of an object or instance in the Windows system. If a program wants to access other system objects such as processes and threads, it must first create a handle of the object and access it through the handle; Intel classifies the privileges of CPU instructions, where ring0 is the highest and ring3 is the lowest. In the Windows system, ring3 is the level where regular software runs, and ring0 is the level where the operating system kernel program runs. Preferably, the level of the protection driver is ring0, and the level of the configuration tool program is ring3. The present invention provides effective and configurable operation protection for ring3 software through the ring0 protection driver.

[0064] S4. Based on the target process information and / or source process information, cancel the permissions of the process handle for processes that do not meet the preset protection policy.

[0065] As shown in Figure 3 Figure, step S4 includes:

[0066] S41. Compare the target process information and / or source process information of the handle with the protection policies stored in the protection driver.

[0067] The protection policies include two types: ① The list of protected programs ② Exceptions that can access protected programs. The former indicates which programs are protected by the solution of the present invention, and the latter indicates which programs, as exceptions, can still access protected programs. For each access, the protection driver can obtain the information of the accessing program (i.e., the "source process") and the accessed program (i.e., the "target process"), and determine whether to perform protection by comparing the two lists. Currently, the configuration and matching of the process list are represented by the path of the exe file where the process is located (such as C:\folder\process.exe).

[0068] S42. If it is confirmed that access is prohibited, start the protection operation, and cancel the read, write, and close permissions of the handle for the target process.

[0069] As shown in Figure 4 Figure, a software operation protection system 100 for a Windows system provided by an embodiment of the present invention includes:

[0070] A program creation module 110, which is used to create a protection driver under the Windows system and an interface configuration tool for communicating and interacting with the protection driver.

[0071] A function registration module 120, which is used to register, through the protection driver, a callback function for monitoring the creation of process handles.

[0072] A process information acquisition module 130, where the user obtains the target process information and / or source process information of the process handle according to the incoming parameters of the callback function and the PsGetCurrentProcessId function.

[0073] A permission judgment module 140, which is used to cancel the permissions of the process handle for processes that do not conform to the preset protection policies based on the target process information and / or source process information.

[0074] Among them, binary encrypted data streams are used for information transmission between the said interface configuration tools; protection policies are stored in the protection driver.

[0075] Since the system / apparatus described in the above embodiments of the present invention is the system / apparatus adopted for implementing the method of the above embodiments of the present invention, those skilled in the art can understand the specific structure and variations of the system / apparatus based on the method described in the above embodiments of the present invention, and thus will not be elaborated herein. Any system / apparatus adopted for the method of the above embodiments of the present invention falls within the scope of protection of the present invention.

[0076] In addition, an embodiment of the present invention further provides a software operation protection system for a Windows system, including: at least one database; and a memory communicatively connected to the at least one database; wherein the memory stores instructions executable by the at least one database, and the instructions are executed by the at least one database to enable the at least one database to execute a software operation protection method for a Windows system as described above.

[0077] Figure 5 FIG. is a schematic structural diagram of a computer system of a software operation protection device for a Windows system provided by an embodiment of the present invention. Refer to Figure 5 , which shows a schematic structural diagram of a computer system 200 of a software operation protection device for a Windows system suitable for implementing an embodiment of the present application. Figure 5 The shown software operation protection device for a Windows system is merely an example and should not impose any limitation on the functions and usage scope of the embodiments of the present application.

[0078] As Figure 5 shown, the computer system 200 includes a central processing unit (CPU) 201, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 202 or a program loaded from a storage section 208 into a random access memory (RAM) 203. In the RAM 203, various programs and data required for the operation of the computer system 200 are also stored. The CPU 201, the ROM 202, and the RAM 203 are connected to each other via a bus 204. An input / output interface (I / O interface) 205 is also connected to the bus 204.

[0079] The following components are connected to the I / O interface 205: an input section 206 including a keyboard, a mouse, etc.; an output section 207 including, for example, a cathode ray tube (CRT), a liquid crystal display (LCD), etc., and a speaker, etc.; a storage section 208 including a hard disk, etc.; and a communication section 209 including a network interface card such as a LAN card, a modem, etc. The communication section 209 performs communication processing via a network such as the Internet. The drive 210 is also connected to the I / O interface 205 as required. A removable medium 211, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 210 as required so that a computer program read from it can be installed into the storage section 208 as required.

[0080] Specifically, according to an embodiment of the present invention, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present invention includes a computer program product that includes a computer program carried on a computer-readable medium, and the computer program contains program codes for performing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network through the communication section 209, and / or installed from the removable medium 211. When the computer program is executed by a central processing unit (CPU) 201, the above functions defined in the system of the present application are executed.

[0081] In addition, the present invention also provides a computer-readable medium, which may be included in the device described in the above embodiment; or may exist separately without being assembled into the device. The above computer-readable medium carries one or more programs, and when the above one or more programs are executed by the device, the device includes the following method steps:

[0082] S1. Create a protection driver under the Windows system.

[0083] S2. Register a callback function for monitoring the creation of a process handle through the protection driver.

[0084] S3. Obtain the target process information and / or source process information of the process handle based on the incoming parameters of the callback function and the PsGetCurrentProcessId function.

[0085] S4. Based on the target process information and / or source process information, cancel the permissions of the process handle for processes that do not meet the preset protection policy.

[0086] In a specific embodiment, the protection driver is a filter.sys file, and when installed, the system is automatically loaded by modifying the registry. The interface configuration tool is a config.exe application program, which can be directly double-clicked and run when needed.Figure 6 As shown, the present invention includes two programs: a protection driver at the ring0 level and a configuration tool program at the ring3 level. It involves a total of 3 major processes:

[0087] (1) Boot self-start and configuration of the driver: When the protection driver is installed, by setting the startup method, it can be set to start with the Windows system. After that, the protection driver calls ObRegisterCallbacks() to register callback functions and starts monitoring the creation of each process handle.

[0088] (2) Configuration change operation: The protection policy is stored in the driver. Users can view and modify this configuration through the interface configuration tool. The present invention uses the communication port function provided by Windows to complete the communication between the ring3-level configuration tool and the ring0-level driver program, and ensures data reliability through encryption. Among them, binary encrypted data streams are used to transfer information between the interface configuration tool and the protection driver, and at the same time, the configuration tool uses encrypted login verification to ensure that the configuration cannot be modified casually.

[0089] (3) Protection execution: Under the Windows operating system, if an operation such as debugging, terminating, or memory reading and writing is to be performed on a program, the handle of the process must be created first through NtOpenProcess(). The protection driver in the present invention can monitor the creation operation of all process-related handles on the current machine through callbacks, that is, any attempt to access a program is monitored. After receiving the callback, the protection driver can obtain the target process of the current handle and the information of the source process that attempts to create this handle by passing in parameters or through the PsGetCurrentProcessId() function. Compare this information with the current protection policy. If access is prohibited, the protection operation is started. The driver will adjust the permissions of the handle, cancel the read, write, close, and other permissions of the handle for the target process, and the user of the handle will not be able to have these permissions, and thus will not be able to perform corresponding operations on the target process, playing a protective role.

[0090] In summary, the present invention provides a software operation protection method, system, device, and medium for the Windows system. When using the present invention, the driver program and the configuration program need to be installed into the computer through the installation package first, and the driver program will be configured to start automatically when the computer boots. Then, the program to be protected is selected through the configuration program, policies are added and saved, and the driver program will protect the software running in the system according to the policies. For the creation of process handles not allowed by the policies, the driver program will cancel the permissions of their handles, thereby preventing their access to the protected processes. Therefore, the present invention adopts an external protection solution based on the Windows system, uses the Windows kernel driver to monitor all process accesses in the system, and directly intercepts illegal accesses through the driver. The software protection at the driver level used in the present invention, combined with the configuration tool, can provide configurable protection policies, enabling the software to be protected from attacks such as debugging and injection while not affecting the normal operation of the software, and can also provide effective protection for third-party programs.

[0091] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, system, or computer program product. Therefore, the present invention can adopt the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0092] The present invention is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, and the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions.

[0093] It should be noted that in the claims, any reference signs placed between parentheses should not be construed as limiting the claim. The word "comprising" does not exclude the presence of components or steps not listed in the claims. The word "a" or "an" placed before a component does not exclude the presence of a plurality of such components. The present invention can be implemented by means of hardware including several different components and by means of a suitably programmed computer. In the claims listing several devices, several of these devices can be embodied by the same hardware. The use of the words first, second, third, etc. is only for convenience of expression and does not indicate any order. These words can be understood as part of the component name.

[0094] In addition, it should be noted that in the description of this specification, the descriptions of terms such as "one embodiment", "some embodiments", "embodiment", "example", "specific example", or "some examples" mean that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic descriptions of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described can be combined in any one or more embodiments or examples in a suitable manner. In addition, without contradiction, those skilled in the art can combine and combine the different embodiments or examples described in this specification and the features of different embodiments or examples.

[0095] Although the preferred embodiments of the present invention have been described, those skilled in the art can make additional changes and modifications after learning the basic creative concepts. Therefore, the claims should be construed to include the preferred embodiments and all changes and modifications that fall within the scope of the present invention.

[0096] Obviously, those skilled in the art can make various modifications and variations to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalent technologies, the present invention should also include these modifications and variations.

Claims

1. A software running protection method for Windows system, characterized in that, Including: Create a ring0-level protection driver under the Windows system, and the protection driver is set to start automatically with the Windows system; Create a ring3-level interface configuration tool that communicates and interacts with the protection driver, and binary encrypted data streams are used for information transfer between the interface configuration tool and the protection driver; After logging in to the interface configuration tool using encrypted authentication, view and / or modify the protection policies stored in the protection driver through the interface configuration tool; Register a callback function for monitoring the creation of process handles through the protection driver, including: when the protection driver starts, call the system api through the protection driver to register the callback function ObjectPreCallback, and keep the callback function ObjectPreCallback running continuously to monitor the creation of handles for all processes; Obtain the target process information and / or source process information of the process handle based on the incoming parameters of the callback function and the PsGetCurrentProcessId function; Based on the target process information and / or source process information, perform a double comparison with the protected program list and the accessible exception list in the protection policy, and cancel the permissions of the process handle for processes that do not meet the preset protection policy.

2. The software running protection method for a Windows system according to claim 1, wherein, Creating a process handle includes: creating a handle associated with each process for accessing the target program through the NtOpenProcess function.

3. The software running protection method for a Windows system according to claim 1, wherein Based on the target process information and / or source process information, canceling the permissions of the process handle for processes that do not meet the preset protection policy includes: Compare the target process information and / or source process information of the handle with the protection policy stored in the protection driver; If it is confirmed that access is prohibited, start the protection operation, and cancel the read, write, and close permissions of the handle for the target process.

4. A software running protection system for Windows system, characterized in that, Including: A program creation module for creating a ring0-level protection driver under the Windows system and a ring3-level interface configuration tool that communicates and interacts with the protection driver, and the protection driver is set to start automatically with the Windows system; A function registration module for registering a callback function for monitoring the creation of process handles through the protection driver, including: when the protection driver starts, call the system api through the protection driver to register the callback function ObjectPreCallback, and keep the callback function ObjectPreCallback running continuously to monitor the creation of handles for all processes; A process information acquisition module for the user to obtain the target process information and / or source process information of the process handle based on the incoming parameters of the callback function and the PsGetCurrentProcessId function; A permission judgment module for performing a double comparison with the protected program list and the accessible exception list in the protection policy based on the target process information and / or source process information, and canceling the permissions of the process handle for processes that do not meet the preset protection policy; Among them, Before registering a callback function for monitoring the creation of a process handle through the protection driver, it further includes: creating a ring3-level interface configuration tool for communicating and interacting with the protection driver; after logging in to the interface configuration tool using encryption verification, viewing and / or modifying the protection policies stored in the protection driver through the interface configuration tool; using a binary encrypted data stream for information transfer between the interface configuration tools; and protection policies are stored in the protection driver.

5. A software running protection system for Windows system, characterized in that, It includes: At least one database; And a memory communicatively connected to the at least one database; Among them, the memory stores instructions executable by the at least one database, and the instructions are executed by the at least one database to enable the at least one database to execute a software operation protection method for a Windows system according to any one of claims 1-3.

6. A computer-readable medium having computer-executable instructions stored thereon, characterized in that, When the executable instructions are executed by a processor, a software operation protection method for a Windows system according to any one of claims 1-3 is implemented.