This invention relates to a real-time detection method for
encryption hijacking on Linux platforms based on multi-dimensional behavioral characteristics. This method relies on a closed-loop governance
system formed by the collaborative analysis and
processing module and the decision output module. The triggering logic of the three-layer cascaded analysis is as follows: the resource monitoring layer performs real-time monitoring and initial anomaly screening of
system-level hardware resource indicators, outputting
system-level
risk status identifiers; when any monitoring indicator is abnormal, the behavior analysis layer is activated; the behavior analysis layer collects and analyzes process-level behavioral characteristics, outputting a
list of suspicious processes and their risk scores; when the process risk
score exceeds a set threshold, the essence detection layer is triggered; the essence detection layer performs
encryption hijacking essence behavior
verification on suspicious processes, completing the final decision. The main objective of this invention is to eliminate reliance on
variable features and instead construct a detection mechanism that is difficult to circumvent, has a low
false alarm rate, and can respond in real
time based on the core essence behavior of
encryption hijacking.