I dunno about their claim that "it doesn't really achieve anything"...
I don't really know how they implement the stuff, but a filter driver could detect an incoming buffer overflow (or other exploit) attempt before it activates. Keep in mind that you don't necessarily need to write anything to disk - there's been at least a couple of worms that only ever lived in memory.