You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

MiniFilter文件加密场景:如何区分复制粘贴与普通文件读取请求

区分文件读取与复制粘贴操作的MiniFilter实现思路

Great question—this is such a common headache when building file system filters that need to handle metadata alongside encrypted content. The bad news is there’s no single "this is a copy-paste" flag in IRP_MJ_READ or IRP_MJ_CREATE, but the good news is there are plenty of indirect clues you can combine to make an accurate call:

1. 从IRP_MJ_CREATE请求里找线索

  • Check for the FILE_OPEN_FOR_BACKUP_INTENT flag in CreateOptions: Most copy operations (like dragging files in File Explorer or using copy in Command Prompt) open the source file with backup intent. This is because the system needs access to extended metadata (alternate data streams, security attributes, etc.) that regular read requests don’t care about. Heads up though—legit backup tools use this flag too, so don’t rely on it alone.
  • Pair with CreateDisposition and process info: If you see FILE_OPEN_EXISTING paired with backup intent, cross-check the requesting process (use PsGetProcessImageFileName to see if it’s explorer.exe, cmd.exe, or a known copy utility). This helps you tell user-initiated copies apart from system backup jobs.

2. 分析IRP_MJ_READ的上下文细节

  • Look at the RequestorMode: Kernel-mode initiated reads often mean system-level copy operations (like SMB file transfers or background system syncs), while user-mode reads could be anything from a text editor opening a file to File Explorer copying it. It’s not a definitive check, but it’s a useful signal.
  • Track metadata queries before reads: Copy operations almost always start with IRP_MJ_QUERY_INFORMATION requests (to grab file size, creation time, etc.) before reading the actual content. If your filter sees a burst of metadata queries followed by a full-file read, that’s a pretty strong indicator it’s a copy operation.

3. 更可靠的端到端追踪方案

Instead of trying to flag individual READ/Create requests, focus on the full copy workflow—it’s more reliable:

  • When a source file is opened with signs of being copied (backup intent + metadata queries), attach a custom file context (using FsRtlInsertFileSystemContext) to mark it as "in copy".
  • When you see an IRP_MJ_CREATE for a new target file (with FILE_CREATE disposition), check if there’s an associated source file in your context. Then, when the target gets IRP_MJ_SET_INFORMATION requests, sync the source’s encrypted metadata over to the target.
  • This way, you don’t miss metadata syncing even if the copy operation uses weird read patterns.

关键提醒

  • Don’t rely on just one signal—copy operations can come from dozens of tools, each with slightly different behavior. Test with File Explorer drag-and-drop, cmd copy, robocopy, and network transfers to cover edge cases.
  • Avoid hardcoding process names—third-party copy tools won’t be on your initial list, so build flexible logic instead.

内容的提问来源于stack exchange,提问作者Krag

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 07:07:37