Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

27 results about "Filter driver" patented technology

A filter driver is a Microsoft Windows driver that extends or modifies the function of peripheral devices or supports a specialized device in the personal computer. It is a driver or program or module that is inserted into the existing Driver Stack to perform some specific function. A filter driver should not affect the normal working of the existing driver stack in any major way. Written either by Microsoft or the vendor of the hardware, any number of filter drivers can be added to Windows. Upper level filter drivers sit above the primary driver for the device (the function driver), while lower level filter drivers sit below the function driver and above the bus driver.

A configuration file protection method based on dynamic redirection

The present invention provides a configuration file protection method based on dynamic redirection, which relates to the field of information security technology. The configuration file protection method includes the following steps: based on the system identifying the configuration file to be protected and transferring it to a safe storage location, based on the software and hardware characteristics of the user terminal device, a highly simulated bait configuration file is generated in the original path of the configuration file to be protected; based on the file system filter driver, the process requesting access to the configuration file to be protected is automatically captured and passed to the redirection decision engine, and the redirection decision engine is used to determine the process requesting access; when the request process is determined to be a legal behavior, the system redirects the access path to the real configuration file; when it is determined to be an abnormal or suspicious request, the request process path will be redirected to the bait configuration file, inducing the process to access forged data. The configuration file protection method provided by the present invention realizes transparent protection of the client configuration file, improving security and obfuscation.
Owner:GUANGZHOU UNIVERSITY

Desktop environment-oriented interactive management and control method for Linux sandbox lightweight process auditing

The invention relates to the technical field of computer security, in particular to a desktop environment-oriented interactive management and control method for Linux sandbox lightweight process auditing. Comprising the following steps: constructing a dynamic hierarchical sandbox environment based on a namespace and a control group of a Linux kernel, and carrying out bidirectional binding on a specified directory of a host machine and a virtual directory in a sandbox through a preset environment variable mapping rule to realize isolation and dynamic adaptation of a process running environment; loading an intelligent file filter driver with context sensing capability, and performing multi-dimensional monitoring on file operation behaviors of processes in the sandbox in combination with a dynamic probe technology of a kernel mode; constructing a real-time auditing model based on the behavior feature vector, performing security level evaluation on the process operation behavior through the model, and triggering a corresponding management and control strategy according to an evaluation result; according to the method and the device, accurate auditing and dynamic management and control of process behaviors can be realized, so that the safety and the flexibility of the sandbox are improved.
Owner:ZHEJIANG ELECTRONIC INFORMATION PROD INSPECTION & RES INST (ZHEJIANG INFORMATIZATION & INDUSTRIALIZATION INTEGRATION PROMOTION CENT)

Virtual canary files to mitigate ransomware attacks

ActiveUS12694101B2Virtual memoryAttack
Provided is a computer agent and method to detect and prevent ransomware attacks early without losing customer data, without polluting the customer's file system or consuming any space on a storage device. The computer agent installs a kernel mode layered file system driver which is attached to encryption level group of a filter manager. With this layered file system filter driver design, it creates virtual canary files in directories which appear like normal files to any user or application though these files will not reside on disk. These virtual canary files are spread as baits across the file system to detect and prevent any malicious attack from any process or application. So that the Virtual Canary Files do not consume a large amount of memory, internal structures representing Virtual Canary Files are placed in virtual memory, but actual contents of the Virtual Canary Files do not reside in virtual memory. Other embodiments disclosed.
Owner:THALES DIS CPL USA INC

Managing file system access policies

A method for protecting resources on a computer file system. Also provided, is a computer program product configured to adapt a computer to carry out the method comprising: a file system filter driver
Owner:CRISTIE SOFTWARE LTD

Enterprise terminal leakage prevention method and system based on kernel encryption and file redirection

This invention relates to the field of data encryption, specifically disclosing a method and system for preventing data leakage on enterprise terminals based on kernel encryption and file redirection. The method includes the following steps: S1. At the terminal layer, a secure terminal is deployed, and the C-Y drives of the terminal hard drive are fully encrypted using the VeraCrypt kernel driver. An isolated, unencrypted Z drive is created as a dedicated external network drive. S2. On the secure terminal, kernel-level permission control is executed through the loaded MiniFilter file system filtering driver, including: intercepting and verifying software installation and execution requests, and only allowing software within the whitelist issued by the policy server to start. This invention significantly improves the security of enterprise terminal data by deploying hard drive encryption and partition creation technology based on the VeraCrypt kernel driver on the enterprise terminal. Full encryption of some partitions on the terminal hard drive and the creation of an isolated dedicated external network drive effectively isolate sensitive internal network data from potentially risky external network environments.
Owner:厦门工学院

Generating file chunk change information for backups

The invention relates to generating file block change information for a backup. Example implementations relate to computer data storage. In some examples, a file system scanner identifies files in a file system, where each file includes a logical block, and where the file system is included in a backup. A file system scanner generates a read buffer to store logical blocks of a file. The block filter driver determines that the read buffer includes a predefined signature, and in response determines whether the logical block has been modified in the backup. In response to determining that the logical block has been modified in the backup, the block filter driver sets a modification flag in the read buffer to a value indicating that the logical block has been modified.
Owner:HEWLETT PACKARD ENTERPRISE DEV LP

Implementation system and method for USB flash disk encryption

The invention relates to the technical field of data security, in particular to a USB flash disk encryption implementation system and method. The system comprises a data partition management module used for forming a common data partition and a hidden encryption partition; the transparent encryption and decryption module is realized based on a file system filter driver and is used for encrypting and decrypting the hidden encryption partition data in real time; the identity authentication module is used for verifying user identity information and dynamically mounting the hidden encryption partition after the user identity information passes the verification; and the security isolation module is used for establishing a security data transmission channel and monitoring an access state, and automatically unloading the hidden encryption partition when a condition is met. The method comprises the steps of partition creation, request interception, identity verification, dynamic mounting, real-time encryption and decryption and automatic unloading. According to the invention, security level-to-level management and transparent encryption and decryption of U disk data are realized, and the problems of poor compatibility and complex operation in the prior art are solved.
Owner:LIUZHOU NULON PORT DIGITAL TECHNOLOGY CO LTD

A method for protecting designated paths and files from tampering

The present application belongs to the technical field of computer data security, and particularly relates to a method for protecting specified paths and files from tampering, which comprises the following steps: registering a relevant main function code callback routine in a Windows file system filtering driver framework, and constructing an interception layer for intercepting I / O requests; constructing an access control list with PID and file object path as key values in a kernel non-paging memory; synchronously extracting PID and target file complete path in the callback routine, and judging according to system processes, exemption lists, and protection paths / types, and rejecting the request if it does not meet the conditions; and achieving dynamic management of strategies by establishing a control channel. The present application solves the problem of strategy failure caused by volume path changes by hiding file persistent volume IDs in the system; adopts hierarchical data structures and concurrent synchronization mechanisms to ensure efficient queries and little impact on disk IO performance; and supports multi-dimensional fine control with the help of multi-layer control switches and scenario-based templates.
Owner:成都傲梅科技有限公司

File access system and method, electronic device, storage medium and program product

The invention provides a file access system and method, electronic equipment, a storage medium and a program product, and belongs to the technical field of computers, and the system comprises a sending module which creates a file object corresponding to an access request based on the access request of an application program, and sends the file object to a file filtering driving module, the access request comprises an identifier of a to-be-accessed file; the file filtering driving module is used for determining a target cache region accessed by the access request according to the permission type of the application program, the identifier of the to-be-accessed file and a first section of object pointer and a second section of object pointer associated with a file object in the stream context information; and the encryption and decryption module is used for determining an encryption and decryption strategy for the to-be-accessed file in the target cache region based on the permission type of the application program and the type of the access request. The method and the device are used for solving the problem of how to stably and conveniently realize secure encryption and decryption caching of enterprise data.
Owner:LENS SYST INTEGRATION CO LTD

Data management and control method and device, computer equipment, storage medium and program product

The invention relates to a data management and control method and device, computer equipment, a storage medium and a program product. Receiving a first management and control strategy sent by the zero-trust agent through the management and control service, determining a device type according to a device identifier of an inserted device when the filter driver service monitors that the computer device has a device insertion event, and storing the storage device when the device type is the storage device. And performing data management and control according to the first management and control strategy under the condition that the equipment identifier is not located in the first equipment identifier set and the second equipment identifier set. According to the embodiment of the invention, the management and control service and the filter driver service are deployed in the computer equipment with the zero-trust agent, and the zero-trust identity authentication characteristic is combined, so that the user can be quickly identified, the first management and control strategy and the management and control object of the first management and control strategy are positioned more accurately, the safety operation efficiency is effectively improved, and the false alarm noise point is reduced.
Owner:CHINA TELECOM CLOUD TECH CO LTD

Container storage interface filter driver-based use of a non-containerized-based storage system with containerized applications

A method includes receiving, by a container storage interface (CSI) filter driver executing on a node of a container-based cluster managed by a container orchestrator, a request to perform a storage system-based control plane operation associated with a containerized application executing on the node; determining, by the CSI filter driver, that the storage system-based control plane operation is to be performed with respect to a legacy storage system configured to store data for one or more non-containerized applications; and generating, by the CSI filter driver based on the determining that the storage system-based control plane operation is to be performed with respect to the legacy storage system, a command configured to direct a storage interface driver associated with the legacy storage system to perform the storage system-based control plane operation.
Owner:PURE STORAGE INC

Offline file automatic encryption synchronization method and system

The invention provides an off-line file automatic encryption synchronization method and system, and the method comprises the steps: intercepting an I / O request through a kernel mode file filter driver, and initializing monitoring when a write release event is captured; performing stability judgment based on a sliding window on the monitored object, calculating a discrete difference fluctuation ratio, and confirming that writing is complete after convergence; calculating the local information entropy of the file to generate a weighted feature sensing fingerprint, and performing duplicate removal through Hamming distance comparison; generating a dynamic key based on the system epoch time to perform streaming encryption; only uploading the missing ciphertext data block according to a missing bitmap fed back by the server; and the server side decrypts the restored file and generates a chained hash log for solidification storage. According to the method, the file writing state can be accurately judged, data damage is prevented, and efficient duplicate removal, incremental transmission and whole-process credible traceability are achieved.
Owner:THREE GORGES SMART WATER TECH CO LTD

Windows system cross-process malicious behavior detection method and device

The invention discloses a Windows system cross-process malicious behavior detection method, which comprises the following steps of: monitoring the calling of a user mode program on a cross-process memory write-in API (Application Program Interface) through a hook system service scheduling table or a filter drive program of a Windows system, and when detecting that a source process executes memory write-in operation on a target process; when it is monitored that the target process executes the predefined sensitive behavior operation, obtaining a thread call stack address sequence corresponding to the sensitive behavior operation in real time; and comparing the thread call stack address sequence with the injection operation record, and if at least one instruction address in the call stack falls into a memory address range written into the target process by the source process, judging that the sensitive behavior operation forms a malicious behavior initiated by the source process. An injection behavior traceability basis is established by monitoring cross-process memory write-in operation, and accurate behavior traceability of remote code injection attacks is realized for the first time in combination with an address space matching mechanism of a sensitive behavior call stack.
Owner:BEIJING BIG DATA CENT

Method for protecting specified path and file from being tampered

The invention belongs to the technical field of computer data security, and particularly relates to a method for protecting a specified path and a file from being tampered, which comprises the following steps of: registering a related main function code callback routine in a Windows file system filter drive framework, and constructing an interception layer for intercepting an I / O (Input / Output) request; constructing an access control list taking PID and file object paths as key values in a kernel non-paging memory; pID and a complete path of a target file are synchronously extracted in a callback routine, hierarchical judgment is performed according to a system process, an exemption list and a protection path / type, and a request is rejected if a condition is not met; through establishing a control channel, strategy dynamic management is realized. According to the method, the file persistence volume ID is hidden through the system, so that the problem of strategy failure caused by volume path change is solved; a hierarchical data structure and a concurrent synchronization mechanism are adopted to ensure efficient query and small influence on disk IO performance; by means of a multi-layer control switch and a scenarized template, multi-dimensional fine control is supported.
Owner:成都傲梅科技有限公司

Encrypted storage device for realizing data stealth through bottom layer driven reconstruction

The invention discloses encrypted storage equipment for realizing data stealth through bottom-layer driven reconstruction, belongs to the technical field of computer data security storage, and solves the problem of data storage security. According to the scheme, an embedded processor is adopted to run a customized Linux system, and a physical storage module is divided into a CD-ROM read-only partition, a configuration storage partition, a data storage partition and a log storage partition; intercepting an access request of an operating system to a storage module through a kernel layer file filter driver, and only exposing a CD-ROM partition and hiding other partitions when equipment is connected; and the special resource manager is preset in the CD-ROM partition, and decrypts the data storage partition through a national cryptographic algorithm and provides a virtual file interface after verifying that the user password is matched with a preset key. The device is mainly used for a data storage scene of a high-security demand scene, only the CD-ROM read-only partition is presented on an unauthorized computer, and ransomware scanning and data stealing attacks are effectively blocked.
Owner:GUANGXI POLYTECHNIC

Generating file block change information for a backup

Example implementations relate to the storage of computer data. In some examples, a file system scanner identifies files in a file system, where each file consists of logical blocks and the file system is contained in a backup. The file system scanner creates a read buffer to store a logical block of a file. A block filter driver detects that the read buffer contains a predefined signature and then determines whether the logical block in the backup has been modified. In response to the detection that the logical block in the backup has been modified, the block filter driver sets a change flag in the read buffer to a value indicating that the logical block has been changed.
Owner:HEWLETT PACKARD ENTERPRISE DEV LP

Enterprise terminal leakage prevention method and system based on kernel encryption and file redirection

The invention relates to the field of data encryption, and particularly discloses an enterprise terminal leakage prevention method and system based on kernel encryption and file redirection, and the method comprises the following steps: S1, deploying a security terminal on a terminal layer, carrying out the whole encryption of a C-Y disk of a terminal hard disk through employing a VeraCrypt kernel driver, and creating an isolated and unencrypted Z disk as an external network dedicated disk; s2, executing kernel-level authority control on the security terminal through a loaded MiniFilter file system filter driver, including intercepting and verifying a software installation and execution request, and only allowing software in a software white list issued by a strategy server to start; according to the method, a hard disk encryption and partition creation technology based on a VeraCrypt kernel driver is deployed at the enterprise terminal, so that the security of enterprise terminal data is greatly improved. The method comprises the following steps of: performing full disk encryption on partial partitions of a terminal hard disk, creating an isolated extranet special disk, and effectively isolating intranet sensitive data from a possible risk environment of an extranet;
Owner:厦门工学院

Managing file system access policies

A method of protecting access to files on a computer file system is disclosed. A kernel-mode file system filter driver controls access to stored policies. Some access policies will cause the file system filter driver to send a request to a user-mode policy configuration service. The user-mode policy configuration service includes features allowing safe autoconfiguration of policies for new applications, and safe reconfiguration of policies for updated applications.
Owner:CRISTIE SOFTWARE LTD

Storage System Optimization Operations Coordinated by a Container Storage Interface Filter Driver

An illustrative method may include passing, by a CSI filter driver, requests received at a node of a cluster to a CSI driver associated with a storage system, the requests comprising requests for the CSI driver to perform control plane operations with respect to the storage system, wherein the storage system is configured to store data associated with one or more containerized applications executing on the node; determining, by the CSI filter driver based on attributes associated with the control plane operations, a usage profile associated with the storage system, the usage profile representative of how the storage system is used in connection with the one or more containerized applications; and performing, by the CSI filter driver based on the usage profile, an optimization operation with respect to how the storage system is used in connection with the one or more containerized applications.
Owner:PURE STORAGE INC

Data loss vulnerability detection

An information management system can detect instances in which data is being stored in a non-standard file path and can alert the user of the client computing device, modify the storage policy to include the non-standard file path, and / or initiate a secondary copy operation to prevent data loss of the data stored in the non-standard file path. For example, a client computing device may execute a filter driver that monitors interactions with files in the file system. The filter driver can identify any non-standard file paths not subject to a storage policy that include files in which interactions occurred. For a non-standard file path, the filter driver can determine whether the frequency of interaction with files in the non-standard file path satisfies a threshold frequency. If the threshold is satisfied, then the filter driver may determine that the files should be subject to the storage policy and take appropriate action.
Owner:COMMVAULT SYSTEMS INC

Block-level additional backup method and system supporting file exclusion

The invention discloses a block-level additional backup method and system supporting file exclusion, and relates to the technical field of data backup and recovery, and the method comprises the following steps: deploying and initializing a file system filter driver; configuring an exclusion file rule, and creating an initial exclusion bitmap; dynamically monitoring the change of the storage space of the excluded file; in cooperation with a block-level backup driver, backup data filtering is achieved; according to the method, a file system sensing layer is introduced into a block-level backup process, data blocks corresponding to files located in an exclusion list can be accurately recognized before and after backup, the data blocks are skipped in a backup data set, and the data blocks in the backup data set are subjected to consistency verification and exclusion bitmap maintenance. According to the method, transmission and storage of invalid data are eliminated from the source, particularly for data which are written frequently but have no reserved value, the reduction effect of the backup data volume is particularly remarkable, and consistency processing is synchronously carried out on file system metadata while specified file data blocks are eliminated.
Owner:HANGZHOU XINHE DATA TECH CO LTD

Power unstructured file use control method and device, equipment, medium and program product

The invention relates to a power unstructured file use control method and device, computer equipment, a computer readable storage medium and a computer program product. The method is applied to an electric power trusted data space, and comprises the following steps: determining an electric power unstructured file, file information and a user main body, and obtaining file use requirement information; based on the file information and the file use requirement information, determining a use control scheme for the power unstructured file; intercepting a use operation for the power unstructured file according to the file filter driver; determining a user permission corresponding to the use operation and a permission requirement corresponding to the use operation in the use control scheme; under the condition that the user permission meets the permission requirement, the use operation is allowed; and prohibiting the use operation under the condition that the user permission does not meet the permission requirement. By adopting the method, the power unstructured file circulation based on the power trusted data space can be realized on the basis of ensuring the data security.
Owner:CHINA SOUTHERN POWER GRID BIG DATA SERVICE CO LTD

Driver full-link behavior acquisition and data attribution method and system

The invention discloses a driver full-link behavior collection and data attribution method and system, and the method comprises the steps: obtaining sorting sample data according to a generation rule of a goods source list when a driver accesses the goods source list, transmitting the sorting sample data to a specific kafka top, and generating a sorting sample kafka message; the method comprises the following steps: acquiring behavior data when a driver accesses a goods source list, sending the behavior data to a specific kafka topic, and generating a driver behavior kafka message; according to filtered driver behavior kafka messages, sorting samples and driver behaviors are associated through an flink real-time calculation task and sent to a new downstream kafka message, then associated data fall into a hive table through an flink sink task, and after big data ETL processing, the data are used for algorithm model training. According to the method, the coverage, timeliness and accuracy of the model training data are comprehensively improved.
Owner:NANJING MANYUN COLD CHAIN TECH CO LTD

Directory tree deletion as supported file system operation

The system described herein introduces a file system operation that enables a file system to delete a directory tree without overhead associated with opening each file in the directory tree, marking the file for deletion, and closing the file. Thus, the file system can delete directories and files in the directory tree without communicating with a filter driver in the operating system, and remains transparent to the filter driver. File system operations are implemented via a directory tree deletion attribute included in a request to delete a directory tree. The file system may perform file system operations in a foreground manner or a latency manner based on directory tree deletion attributes specifying foreground deletion or latency deletion, respectively. By operating files and directories in a single call, the file system can optimize overhead associated with security checks and data transfer across users to kernel boundaries.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Time-based virtual machine reversion

Recovery points can be used for replicating a virtual machine and reverting the virtual machine to a different state. A filter driver can monitor and capture input / output commands between a virtual machine and a virtual machine disk. The captured input / output commands can be used to create a recovery point. The recovery point can be associated with a bitmap that may be used to identify data blocks that have been modified between two versions of the virtual machine. Using this bitmap, a virtual machine may be reverted or restored to a different state by replacing modified data blocks and without replacing the entire virtual machine disk.
Owner:COMMVAULT SYSTEMS INC

Data recovery method, storage medium and equipment

The invention discloses a data recovery method, a storage medium and equipment, a file filter driver is combined with an interception program in a shutdown process to realize a system recovery function, and the file filter driver is adopted to monitor an operation behavior of disk data without influencing operation of other processes in a system, so that the system recovery efficiency is improved. According to the method and the device, the data of the whole disk does not need to be backed up, the performance loss of the operating system is reduced, meanwhile, the disk data is restored through the stored operation record by monitoring and recording the operation of the disk data in the shutdown process, the restoration process of the device is realized from the disk data level, and the reliability of the device is improved. And the whole operating system does not need to be restored, so that the data restoration efficiency is improved.
Owner:GUANGZHOU SHIZHEN INFORMATION TECH CO LTD

Directory tree delete as a supported file system operation

The system described herein introduces a file system operation that enables a file system to delete a directory tree without the overhead associated with opening each file in the directory tree, marking the file for deletion, and closing the file. Accordingly, the file system is able to delete directories and files in the directory tree independent of communicating with, and being transparent to, filter drivers in the operating system. The file system operation is implemented via a directory tree delete attribute included in a request for deletion of a directory tree. The file system can perform the file system operation in a foreground manner or in a deferred manner based on the directory tree delete attribute respectively specifying foreground deletion or deferred deletion. By operating on files and directories in a single invocation, the file system can optimize overheads related to security checks and data transfer across a user-to-kernel boundary.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC