Linear Cryptanalysis Linear cryptanalysis tries to take advantage of high probability occurrences of linear expressions involving plaintext bits ciphertext" bits(actually we shall use bits from the 2nd last round output), and subkey bits It is a known plaintext attack 2222 Linear Cryptanalysis • Linear cryptanalysis tries to take advantage of high probability occurrences of linear expressions involving plaintext bits, "ciphertext" bits (actually we shall use bits from the 2nd last round output), and subkey bits. • It is a known plaintext attack