发明名称 SYSTEM AND METHOD FOR PROVIDING ACCESS TO ORIGINAL ROUTINES OF BOOT DRIVERS
摘要 Disclosed are systems and methods for detecting access of boot driver routines by malware. An example method includes identifying, by the driver interceptor, the one or more boot drivers that have been loaded into memory but not yet initialized; installing, by the driver interceptor, an interceptor handler operable to intercept calls of initialization routines of the one or more identified boot drivers; intercepting, by the driver interceptor, program calls to the initialization routines of the one or more identified boot drivers; storing, by intercept handler, information about the boot driver that is provided by the driver in the course of its initialization, wherein information contains at least address of the entry point for one or more routines of the boot driver; and providing access, by driver interceptor, to the routines of the boot driver by previously stored addresses of the entry points.
申请公布号 EP3029564(A1) 申请公布日期 2016.06.08
申请号 EP20150156673 申请日期 2015.02.26
申请人 KASPERSKY LAB, ZAO 发明人 RUSAKOV, VYACHESLAV E.;KIRZHEMANOV, ANDREY L.;PARSHIN, YURY G.
分类号 G06F9/44;G06F21/56;G06F21/57 主分类号 G06F9/44
代理机构 代理人
主权项
地址