METHOD AND SYSTEM FOR KERNEL ROUTINE CALLBACKS
First Claim
1. A method comprising:
- hooking a pre-callback handler and a post-callback handler to a pre-existing operating system of a computing device;
obtaining, by the pre-callback handler, a kernel routine request for a kernel routine to be performed in a kernel mode of the operating system;
determining, by the pre-callback handler, whether to allow the kernel routine to be performed based on parameters of the kernel routine request;
upon determining that the kernel routine is allowed to be performed, causing the kernel routine to be performed in the kernel mode to generate kernel routine results;
determining, by the post-callback handler, whether to allow the kernel routine results of the kernel routine to be returned;
upon determining that the kernel routine results of the kernel routine are allowed to be returned, causing the kernel routine results of the kernel routine to be returned to an application that is executed in a non-kernel mode of the operating system.
3 Assignments
0 Petitions
Accused Products
Abstract
Systems and methods are provided for kernel routine callbacks. Such methods may include hooking a pre-callback handler and a post-callback handler to a pre-existing operating system of a computing device. According to the pre-callback handler, a kernel routine request for a kernel routine to be performed in a kernel mode of the operating system is obtained, whether to allow the kernel routine to be performed is determined, and the kernel routine is caused to be performed in the kernel mode to generate kernel routine results. According to the post-callback handler, whether to allow the kernel routine results of the kernel routine to be returned is determined, and the kernel routine results of the kernel routine is caused to be returned to an application that is executed in a non-kernel mode of the operating system.
6 Citations
20 Claims
-
1. A method comprising:
-
hooking a pre-callback handler and a post-callback handler to a pre-existing operating system of a computing device; obtaining, by the pre-callback handler, a kernel routine request for a kernel routine to be performed in a kernel mode of the operating system; determining, by the pre-callback handler, whether to allow the kernel routine to be performed based on parameters of the kernel routine request; upon determining that the kernel routine is allowed to be performed, causing the kernel routine to be performed in the kernel mode to generate kernel routine results; determining, by the post-callback handler, whether to allow the kernel routine results of the kernel routine to be returned; upon determining that the kernel routine results of the kernel routine are allowed to be returned, causing the kernel routine results of the kernel routine to be returned to an application that is executed in a non-kernel mode of the operating system. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10)
-
-
11. A computing system comprising:
-
one or more processors; and a memory storing instructions, when executed by the one or more processors, cause the computing system to; obtain, by a pre-callback handler hooked to an operating system of the computing system, a kernel routine request for a kernel routine to be performed in a kernel mode of an operating system of the computing system; determine, by the pre-callback handler, whether to allow the kernel routine to be performed based on parameters of the kernel routine request; upon determining that the kernel routine is allowed to be performed, cause the kernel routine to be performed in the kernel mode to generate kernel routine results; determine, by a post-callback handler that is also hooked to the operating system of the computing system, whether to allow the kernel routine results of the kernel routine to be returned; upon determine that the kernel routine results of the kernel routine are allowed to be returned, cause the kernel routine results of the kernel routine to be returned to an application that is executed in a non-kernel mode of the operating system. - View Dependent Claims (12, 13, 14, 15, 16, 17, 18, 19, 20)
-
Specification