如何让内核驱动创建的文件仅对指定系统应用开放权限?
内核驱动文件权限控制:仅允许指定系统应用访问
我正在开发内核驱动,目前通过CreateFile创建文本文件实现内核与系统应用间的数据传输,代码如下:
handle=CreateFile(TEXT("\\\\.\\" FILE_NAME), GENERIC_READ | GENERIC_WRITE, 0, NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
该文件由内核驱动写入、系统应用读取,但当前任意用户均可读写该文件,存在安全隐患。我需要实现禁止普通用户访问,但允许指定系统应用访问的权限控制。
经过研究,我已实现禁止所有用户访问该文件的逻辑,代码如下:
ea[1].grfAccessPermissions = ACCESS_SYSTEM_SECURITY | READ_CONTROL | WRITE_DAC | GENERIC_ALL; ea[1].grfAccessMode = DENY_ACCESS; ea[1].grfInheritance = NO_INHERITANCE; ea[1].Trustee.TrusteeForm = TRUSTEE_IS_SID; ea[1].Trustee.ptstrName = reinterpret_cast<char*>(&everyone_sid); dwRes = SetEntriesInAclA(2, ea, NULL, &pNewDACL); if (ERROR_SUCCESS != dwRes) { printf("SetEntriesInAcl Error %u\n", dwRes); //TODO: goto Cleanup; } PSECURITY_DESCRIPTOR pSD = NULL; // Initialize a security descriptor. pSD = (PSECURITY_DESCRIPTOR)LocalAlloc(LPTR, SECURITY_DESCRIPTOR_MIN_LENGTH); if (NULL == pSD) { printf("error"); } if (!InitializeSecurityDescriptor(pSD, SECURITY_DESCRIPTOR_REVISION)) { printf("error"); } // Add the ACL to the security descriptor. if (!SetSecurityDescriptorDacl(pSD, TRUE, // bDaclPresent flag pNewDACL, FALSE)) // not a default DACL { printf("error"); } SECURITY_ATTRIBUTES sa; // Initialize a security attributes structure. sa.nLength = sizeof(SECURITY_ATTRIBUTES); sa.lpSecurityDescriptor = pSD; sa.bInheritHandle = FALSE; HANDLE hFile = CreateFileA(filename, GENERIC_ALL, 0, &sa, CREATE_NEW, FILE_ATTRIBUTE_NORMAL, NULL);
但现在另一项目中的系统应用无法访问该文件,应用代码如下:
int main() { std::cout << "Hello World!\n"; std::fstream testfile; //basically in another project testfile.open("created_file.txt", ios::out); testfile.write("elo",3); testfile.close(); }
我认为可以通过获取目标进程的SID并为其授予完全访问权限来解决问题,但不清楚如何获取进程SID。
内容的提问来源于stack exchange,提问作者szefitoo
相关产品推荐
相关产品推荐

