IP Library Granted Patent US 7,647,308
Granted Patent B2
US 7,647,308 · App. 11/594,096 · Granted Jan 12, 2010

Method and system for the detection of file system filter driver based rootkits

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,647,308
App. No.
11/594,096
Granted
Jan 12, 2010
Kind
B2
Abstract

A method, system, and computer program product for detecting hidden files and folders that may be installed by or as part of a rootkit provides the capability to identify the method that is used to hide the files and folders, will continue working even if the operating system is modified, and is suitable for real-time detection of hidden files and folders. A method for detecting a rootkit comprises the steps of generating a plurality of query input/output request packets, each query input/output request packet requesting information relating to a file system directory folder, transmitting a generated query input/output request packet to each file system driver object, receiving a result including the requested information relating to a file system directory folder from each file system driver object, and determining differences among each result, to determine information relating to a file system directory folder that is removed by at least one file system driver object.

Claims (35)

1. A method for detecting a rootkit, comprising the steps of:

generating a plurality of query input/output request packets, each query input/output request packet requesting information relating to a file system directory folder;

transmitting a generated query input/output request packet to each file system driver object;

receiving a result including the requested information relating to a file system directory folder from each file system driver object; and

determining differences among each result, to determine information relating to a file system directory folder that is removed by at least one file system driver object.

2. The method of claim 1 , wherein each file system driver object comprises one of a base file system driver object, a file system filter driver object, a rootkit file system filter driver object, or an input/output manager.

3. The method of claim 1 , wherein the result including the requested information includes a listing of files and folders that are present in the file system directory folder.

4. The method of claim 1 , wherein the differences are determined by determining at least one file or folder that is present in a result including a listing of files and folders received from at least one file system driver object is not present in a result including a listing of files and folders received from at least one other file system driver object.

5. The method of claim 4 , wherein each file system driver object comprises one of a base file system driver object, a file system filter driver object, a rootkit file system filter driver object, or an input/output manager.

6. A system for detecting a rootkit comprising:

a processor operable to execute computer program instructions;

a memory operable to store computer program instructions executable by the processor; and

computer program instructions stored in the memory and executable to perform the steps of:

generating a plurality of query input/output request packets, each query input/output request packet requesting information relating to a file system directory folder;

transmitting a generated query input/output request packet to each file system driver object;

receiving a result including the requested information relating to a file system directory folder from each file system driver object; and

determining differences among each result, to determine information relating to a file system directory folder that is removed by at least one file system driver object.

7. The system of claim 6 , wherein each file system driver object comprises one of a base file system driver object, a file system filter driver object, a rootkit file system filter driver object, or an input/output manager.

8. The system of claim 6 , wherein the result including the requested information includes a listing of files and folders that are present in the file system directory folder.

9. The system of claim 6 , wherein the differences are determined by determining at least one file or folder that is present in a result including a listing of files and folders received from at least one file system driver object is not present in a result including listing of files and folders received from at least one other file system driver object.

10. The system of claim 9 , wherein each file system driver object comprises one of a base file system driver object, a file system filter driver object, a rootkit file system filter driver object, or an input/output manager.

11. A computer program product for detecting a rootkit comprising:

a computer readable storage medium;

computer program instructions, recorded on the computer readable storage medium, executable by a processor, for performing the steps of

generating a plurality of query input/output request packets, each query input/output request packet requesting information relating to a file system directory folder;

transmitting a generated query input/output request packet to each file system driver object,

receiving a result including the requested information relating to a file system directory folder from each file system driver object; and

determining differences among each result, to determine information relating to a file system directory folder that is removed by at least one file system driver object.

12. The method of claim 11 , wherein each file system driver object comprises one of a base file system driver object, a file system filter driver object, a rootkit file system filter driver object, or an input/output manager.

13. The method of claim 11 , wherein the result including the requested information includes a listing of files and folders that are present in the file system directory folder.

14. The method of claim 11 , wherein the differences are determined by determining at least one file or folder that is present in a result including a listing of files and folders received from at least one file system driver object is not present in a result including a listing of files and folders received from at least one other file system driver object.

15. The method of claim 14 , wherein each file system driver object comprises one of a base file system driver object, a file system filter driver object, a rootkit file system filter driver object, or an input/output manager.

16. The method of claim 1 , wherein each generated query input/output request packet is sent directly to a dispatch routine of each file system driver object.

17. The method of claim 1 , wherein the result from each file system driver object is stored in a separate result memory.

18. The method of claim 1 , wherein each generated query input/output request packet is sent directly to base file system driver object dispatch routines and to dispatch routines of every file system driver object layered on top of a base file system volume device object.

Assignments (10)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 8, 2006
From: SALLAM, AHMED
To: MCAFEE, INC.
Reel/Frame 018531/0823 →