MiniFilter文件加密场景:如何区分复制粘贴与普通文件读取请求
区分文件读取与复制粘贴操作的MiniFilter实现思路
Great question—this is such a common headache when building file system filters that need to handle metadata alongside encrypted content. The bad news is there’s no single "this is a copy-paste" flag in IRP_MJ_READ or IRP_MJ_CREATE, but the good news is there are plenty of indirect clues you can combine to make an accurate call:
1. 从IRP_MJ_CREATE请求里找线索
- Check for the
FILE_OPEN_FOR_BACKUP_INTENTflag inCreateOptions: Most copy operations (like dragging files in File Explorer or usingcopyin Command Prompt) open the source file with backup intent. This is because the system needs access to extended metadata (alternate data streams, security attributes, etc.) that regular read requests don’t care about. Heads up though—legit backup tools use this flag too, so don’t rely on it alone. - Pair with
CreateDispositionand process info: If you seeFILE_OPEN_EXISTINGpaired with backup intent, cross-check the requesting process (usePsGetProcessImageFileNameto see if it’sexplorer.exe,cmd.exe, or a known copy utility). This helps you tell user-initiated copies apart from system backup jobs.
2. 分析IRP_MJ_READ的上下文细节
- Look at the
RequestorMode: Kernel-mode initiated reads often mean system-level copy operations (like SMB file transfers or background system syncs), while user-mode reads could be anything from a text editor opening a file to File Explorer copying it. It’s not a definitive check, but it’s a useful signal. - Track metadata queries before reads: Copy operations almost always start with
IRP_MJ_QUERY_INFORMATIONrequests (to grab file size, creation time, etc.) before reading the actual content. If your filter sees a burst of metadata queries followed by a full-file read, that’s a pretty strong indicator it’s a copy operation.
3. 更可靠的端到端追踪方案
Instead of trying to flag individual READ/Create requests, focus on the full copy workflow—it’s more reliable:
- When a source file is opened with signs of being copied (backup intent + metadata queries), attach a custom file context (using
FsRtlInsertFileSystemContext) to mark it as "in copy". - When you see an
IRP_MJ_CREATEfor a new target file (withFILE_CREATEdisposition), check if there’s an associated source file in your context. Then, when the target getsIRP_MJ_SET_INFORMATIONrequests, sync the source’s encrypted metadata over to the target. - This way, you don’t miss metadata syncing even if the copy operation uses weird read patterns.
关键提醒
- Don’t rely on just one signal—copy operations can come from dozens of tools, each with slightly different behavior. Test with File Explorer drag-and-drop,
cmd copy,robocopy, and network transfers to cover edge cases. - Avoid hardcoding process names—third-party copy tools won’t be on your initial list, so build flexible logic instead.
内容的提问来源于stack exchange,提问作者Krag
相关产品推荐
相关产品推荐

