Why kernel drivers in Anti-Cheat aren't so bad
blog.levitati.ng
blog.levitati.ng
This goes back much further.
Sony DRM running kernel drivers was 2005 and there were video game anti-cheat programs using similar approaches around the same time.
It was also around this time that Joanna Rutkowska was giving talks at blackhat and defcon on her research (redpill and bluepill) and rootkits which led to discussion, research, and media articles on anti-cheat and other applications.
> This is good for stopping cheaters because a common way to bypass anti-cheat systems is to load cheats before the anti-cheat system starts and either modify system components to contain the cheat or to have the cheat tamper with the anti-cheat system as it loads. Running the driver at system startup time makes this significantly more difficult.
but it looks like it really is needed:
> by 2015 or so, pretty much all the sophisticated, organized cheat-selling organizations were using kernel drivers.