发明授权
US09032525B2 System and method for below-operating system trapping of driver filter attachment
有权
驱动器过滤器附件的操作系统捕获的系统和方法
- 专利标题: System and method for below-operating system trapping of driver filter attachment
- 专利标题(中): 驱动器过滤器附件的操作系统捕获的系统和方法
-
申请号: US13075101申请日: 2011-03-29
-
公开(公告)号: US09032525B2公开(公告)日: 2015-05-12
- 发明人: Ahmed Said Sallam
- 申请人: Ahmed Said Sallam
- 申请人地址: US CA Santa Clara
- 专利权人: McAfee, Inc.
- 当前专利权人: McAfee, Inc.
- 当前专利权人地址: US CA Santa Clara
- 代理机构: Baker Botts L.L.P.
- 主分类号: G06F21/00
- IPC分类号: G06F21/00 ; G06F21/56
摘要:
A system for protecting an electronic system against malware includes an operating system configured to execute on the electronic device, a driver coupled to the operating system, and a below-operating-system security agent. The below-operating-system security agent is configured to identify one or more resources for changing filters of the driver, trap an attempted access of the one or more resources that originates from the operational level of the operating system, access one or more security rules to determine whether the attempted access is indicative of malware, and operate at a level below all of the operating systems of the electronic system accessing the one or more resources for changing filters of the driver.
公开/授权文献
信息查询