EaseFilter File System Filter Driver SDK

Software information
Windows 7/Vista/XP/Server
EaseFilter Inc.
File size:
4.32 Mb
Date added:
March 26, 2015
Product page:
Description from the Publisher

It is always very important to protect your company’s confidential and sensitive data, although you can apply the NTFS security and firewall policies, it might not provide enough information to you , you still want to know who accesses the files, including the user name and process name, and you also want to know which file was accessed and when this file was accessed. If a file was modified, you also want to know who modified it and what content was changed. You want to get the alert for any unauthorized file access in real-time. The Windows File System Filter Driver can create a secure file access environment, protecting data from unauthorized access and distribution, and create the change auditor for Windows File Servers proactively tracks, audits, reports and alerts on vital changes in real time and without the overhead of native auditing. You will instantly know who made what change, and get the original and current values for fast troubleshooting.

A file system filter driver intercepts requests targeted at a file system or another file system filter driver. By intercepting the request before it reaches its intended target, the filter driver can extend or replace functionality provided by the original target of the request. File system filtering services are available through the filter manager in Windows. The Filter Manager provides a framework for developing File Systems and File System Filter Drivers without having to manage all the complexities of file I/O. The Filter Manager simplifies the development of third-party filter drivers and solves many of the problems with the existing legacy filter driver model, such as the ability to control load order through an assigned altitude. A filter driver developed to the Filter Manager model is called a minifilter. Every minifilter driver has an assigned altitude, which is a unique identifier that determines where the minifilter is loaded relative to other minifilters in the I/O stack. Altitudes are allocated and managed by Microsoft.

What is the file access? The file access is an I/O operation to a file, there are two types of file access: read access and write access, read access will not change the file, write access will change the file data, file information or file security. To access a windows file, you have to invoke the Win32 API which was exported by Windows subsystems service, the most frequently used Windows API to a file is ”CreateFile”, “ReadFile”, “WriteFile”, “MoveFile”. “DeleteFile”. In this section, we will explain how to monitor and control these APIs with windows file system filter driver in detail.

I/O operations are layered, when a user application invokes a Win32 API, the I/O manager intercepts this call, sets up one or more I/O request packets (IRPs), and routes them through possibly layered drivers to physical devices, if a file system filter driver was installed and registered with the volume which the file was located, it can intercept this I/O, then the filter driver can pass through this I/O to next layer driver or complete this I/O. If the filter driver passes through this I/O, the filter driver can intercept this I/O request which comes back from the Windows file system if the post I/O operation was registered. If the filter driver completes this I/O, the request will not pass down to the Windows file system, the filter driver can return your won status and appropriate data to the user application.

The filter driver can register a preoperation callback routine, a postoperation callback routine, or both. When the filter driver intercepts the I/O request, it can get the caller’s process name, user’s SID (Security Identifier) which it can decode the user name, domain name, the filter driver also can get the current I/O information, the I/O type (create, read, write, rename, delete…), the file name and the file information ( file size, file time, file attributes…). If the filter driver only wants to monitor this I/O request, it can send those informations to the user, if the filter driver wants to control this I/O request, it can denied this I/O request, or modify the I/O data and return status.

The below figure shows how the EaseFilter driver monitors and controls the Windows file access, the EaseFilter SDK includes two parts, one part is the filter driver running in the Windows kernel, the other part is the user mode monitor and control module. Here is the steps for specific File_Create I/O request, normally most of the I/O requests start with a File_Create request to open or create a file first, then follow with other requests( read,write,delete…).

To develop file systems and file system filter drivers, use the Windows Driver Kit (WDK),which is provided by Microsoft. Even with the resources available in the Windows Driver Kit (WDK) developing file systems is certainly a challenge. To simplify your development and to provide you with a robust and well-tested file system filter driver that works with all versions and patch releases of the Windows operating systems supported by Microsoft, EaseFilter Inc. offers the file system filter driver SDK which provides a complete, modular environment for building active file system filters in your application. With the EaseFilter file system filter driver SDK, you can develop your own filter driver application with c++/c# or other languages.

EaseFilter File System Mini Filter Driver SDK is a mature commercial product. It provides a complete modular framework to the developers even without driver development experience to build the filter driver within a day. The SDK includes the modules from code design to the product installation, it includes all the basic features you need to build a filter driver:

  1. The communication module.
    It demonstrates how to set up the communication channel between the filter driver and your user mode application, send and receive the messages between them.
  2. The debug and trace module.
    You can print or trace the debug message with WPP trace module, and you also can use the system event log to log the information from the filter driver.
  3. The configuration module.
    This module shows how to manage the configuration setting for the filter driver, includes the managed folders.
  4. The file context module.
    This module demonstrate how to trace every file I/O request, with the user information, process information and file information.
  5. The I/O request packet handler module.
    This is the most important module, the SDK demonstrates how to intercept the I/O requests, modify the I/O data. It means you can build your own custom filter driver easily based on the SDK.
Users reviews & testimonials

This software is not reviewed yet.

Product tags
call, system utilities, mie docs file managent, post scrpit driver for pagemaker 6.5, justin bieber cam file, filter briker, booking system, windows xp system requirements, driver updates, irrigation system, server monitor, expandrive without encryption, ef file catalog, driver key, system error detector, driver acer 4750g xp, mob filter, driver d33006 video, point system for behavior modification, content management system, d33006 ethernet driver, pc camera driver, urdu123 call, driver bluetooth acer 4750g for xp, driver card d33006, pa server monitor, file shredder, du monitor, system report, acer 4750g driver xp, anti filter gpass, call from urdu123, call of duty, motherboard driver, audio driver, realtek audio driver, behavior modification point system, file cure, advance system care, bluetooth driver, metric system calculator, d33006 graphics card driver, operating system, bluetooth file sender, driver update utility, webcam driver, call of duty 4, payroll system, vga d33006 driver, call urdu123, anti filter, backup driver, vga driver, video driver, quantam sound driver software, blood bank system, system info, codecanyon booking system, snap shots hospital system, driver hp desjet1000, file hide, quantam sound driver, jogos 123 call 2009, gold price monitor, d33006 driver, monitor, driver utility, driver acer aspire 4750g, driver for sound system, file encrypter, quick time directshow filter, usb driver, audio system, canon driver, bus driver, hp pavilon dv6700 driver, invoice system, ini file, system optimize expert, japanese school system, file watch, driver backup, payroll system software, system restore, file eraser, sound driver, driver modem gsm, crack call of duty, metric system, driver, hardware sensors monitor, blood bank system report, billing system, file monitor, d33006 graphic card driver, system optimize expert review, driver d33006, transparent, system of a down ringtones, meteorology activities, folder monitor, system, tai driver d33006, microsoft direct sound driver, rule, driver real player 123, gsm modem driver 4.0.1710, driver simulator pesawat terbang, encryption, driver acer aspire 4750g for xp, 123urdu call, math activities, hp 3535 driver, packet monitor, file lock, driver update program, mobile entertainment system, intel d33006 vga driver, urdu 123 call, sis 7012 driver, file, toshiba vga driver, driver 4750g, driver 4750g for xp, d33006 xp driver, file compressor, heart monitor, driver acer 4750g for xp, aspire 4750g driver for xp, snmp monitor, encryption package, d33006 audio driver, lan driver, expert system designer, cdr file, bluetooth driver installer, hp 520 audio driver, pos system, flv directshow filter, acer 4750g xp driver, gegabyte motherboard driver, driver xp acer 4750g, driver 4750g xp, driver updater, camguard security system, invoicing system, d33006 driver vga, system mechanic, xp system requirements, monitor 2011 testy, vb coding for petrol pump system, urdu call 123, virtual com driver, acer driver 4750g xp, driver check, navigation system, new file, file joiner, driver hp deskjet f2280, driver xp acer 4750g for xp, justin bieber on cam file, 123 call, system fix, filter, decrypt, mainmedia audio pitch directshow filter, teaching metric system, driver vga d33006, file sorter, security system, driver acer aspire 4750g xp, personal finance activities, driver wifi, monitor tool, d33006 vga driver, call for heroes, goldwave editor driver, wssecure application monitor, freeware file sorter, bootup system, fly, refog terminal monitor, file locker, 4750g driver xp
Other downloads from this publisher

The EaseFilter Registry Filter Driver Library provides you to develop the Windows registry security application. It allows you to monitor Registry access, and protect Registry access in real time.

Easefilter process monitor and control library is a library provides you to develop the Windows security application to monitor and control the Windows running processes. It allows your application to protect against malware

File System Monitor Library can monitor the file system activities on the fly. With file system monitor filter you can monitor the file activities on file system level, capture file open, create, overwrite, read, write, query file information

EaseFilter Folder Locker Library allows you to develop the secure file and folder locker software, a folder locker application can prevent your protected files from being read,written,deleted, renamed, copied out of the protected folder.

EaseTag Automated Tiered Storage Library enables you to create cloud auto-tiering software with a data storage technique which automatically moves data between high-cost local disk and low-cost remote cloud storage.