You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在WFP内核驱动中获取自身过滤器删除通知?

Great question! You’re absolutely correct that there’s no direct kernel-mode equivalent to the user-space FwpmFilterSubscribeChanges0 API for tracking WFP filter deletions. But don’t worry—there are a few solid workarounds to detect when your filter gets removed and respond accordingly. Let’s walk through them:

1. User-Space Subscription + Kernel Notification (Most Reliable)

Since the user-space API already handles change tracking out of the box, this is the easiest and most efficient approach:

  • In your user-space helper app, call FwpmFilterSubscribeChanges0 and pass in the unique key of the filter your driver added. This will trigger a notification every time that filter is modified or deleted.
  • When you get a FWPM_CHANGE_TYPE_DELETE event for your filter, use an IPC method like IOCTLs, named pipes, or shared memory to send an alert to your kernel driver.
  • Your driver can then immediately re-add the filter, log the deletion attempt, or take any other defensive action you need.

This method avoids kernel-side polling and leverages WFP’s built-in tracking, so it’s low-overhead and real-time.

2. Kernel-Mode Periodic Polling (No User-Space Needed)

If you can’t rely on a user-space component, you can implement periodic checks in your driver to verify your filter’s existence:

  • Create a delayed work item (using IoCreateWorkItem and IoQueueWorkItem) that runs on a fixed interval (e.g., every 10-30 seconds—adjust based on how quickly you need to react).
  • In the work item’s callback, use the kernel-mode FwpmFilterGetByKey0 API to try fetching your filter by its key.
  • If the call returns STATUS_NOT_FOUND, your filter has been deleted. You can then re-add it with FwpmFilterAdd0 or handle the event as required.

Keep in mind this isn’t real-time, but it’s a solid kernel-only solution for scenarios where user-space isn’t an option.

3. Advanced: Tie Filter to a Custom Callout

For a more sophisticated kernel-only approach, you can link your filter to a custom callout owned by your driver:

  • Register a callout with WFP (via FwpmCalloutAdd0 in kernel mode) and set it as a required dependency for your filter.
  • When your filter is deleted, WFP will decrement the reference count on your callout. You can monitor this change using ObRegisterCallbacks on the callout object, or by tracking the callout’s lifecycle directly in your driver.
  • This lets you detect deletions directly in the kernel without polling or user-space help, but it’s more complex to implement correctly.

Quick Tips:

  • Always use the same unique filter key when adding and checking for your filter—this ensures you’re targeting the exact object you created.
  • When re-adding the filter, consider setting a high priority or using a provider with elevated permissions to make it harder for other apps to delete it again.

内容的提问来源于stack exchange,提问作者user3664223

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.12 04:53:09