Invention Grant
- Patent Title: Tracking driver load and unload on windows OS
-
Application No.: US15834071Application Date: 2017-12-07
-
Publication No.: US10860393B2Publication Date: 2020-12-08
- Inventor: Prasad Dabak , Leena Soman , Goresh Musalay
- Applicant: NICIRA, INC.
- Applicant Address: US CA Palo Alto
- Assignee: NICIRA, INC.
- Current Assignee: NICIRA, INC.
- Current Assignee Address: US CA Palo Alto
- Agency: SU IP Consulting
- Priority: IN201741014343 20170422
- Main IPC: G06F9/54
- IPC: G06F9/54 ; G06F9/445

Abstract:
A method is provided for a kernel driver in an operating system to detect loading of images into memory and unloading of the images from memory. The method includes registering a callback routine for load-image notifications, receiving a load-image notification for an image and recording loading of the image, storing original code at or about an entry point of the image, and patching redirect stub code over the original code at or about the entry point. The method also includes receiving, from the redirect stub code, a redirected call to or about the entry point to execute a routine in the image. The redirected call identifies a driver object representing the image. The method further includes, based on the driver object, providing a mechanism to intercept unloading of the image and recording the unloading of the image.
Public/Granted literature
- US20190278636A1 TRACKING DRIVER LOAD AND UNLOAD ON WINDOWS OS Public/Granted day:2019-09-12
Information query