首页>
外国专利>
Systems and methods for preventing windows kernel code or drivers from being executed
Systems and methods for preventing windows kernel code or drivers from being executed
展开▼
机译:防止执行Windows内核代码或驱动程序的系统和方法
展开▼
页面导航
摘要
著录项
相似文献
摘要
Systems and methods for preventing drivers from being loaded in Windows® OS kernel space. A security driver according to aspects of the invention is loaded in kernel space and is configured to register a filter to provide a notification in the event of an ImageLoad. So configured, the Windows® kernel provides a notification on all executables being loaded to the kernel on a first method and all file system related activities for a second method before executing them. The user may then selectively determine whether the executable or the file system related activities may be executed.
展开▼