The invention relates to a module and a method for LINUX host computing environment safety protection, which belong to the field of computer
system safety, and solve the safety threats to an LINUX host. The module comprises an
executable file protection module, an anomalous detection module and an inner core key
data structure protection module, wherein the
executable file protection module is used for registering, canceling, completeness protection functions of an
executable program, and carrying out completeness detection before the operation of any program so as to ensure the
process safety of a
user state loaded in an
internal memory; the anomalous detection module is used for setting up a process lawful action set, extracting process actions in a
system during the operation process, and jugging whether the process action is anomalous or not through being matched with a normal action so as to prevent the process from being infected by a rogue program; and the inner core key
data structure protection module is used for providing the
backup, completeness detection and
recovery functions of the inner core important
data structure in the
operating system, detecting whether the inner core important data structure is modified or not during the operation process, and recovering the important data structure according to the previous
backup if the inner core important data structure is modified. The module and the method can completely and effectively protect the operation environment safety of the LINUX host.