Skip to content

Latest commit

 

History

2 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 

Repository files navigation

CipherHook: OS-Level File Encryption

Developer: Eder Gutiérrez
Date: February 24, 2026

1. Introduction

This project implements a comprehensive cybersecurity system focused on cryptography using Python. Unlike a standard linear script, this program is designed as an event-driven daemon (background process) capable of proactively monitoring the file system, including recursive subdirectories.

The primary objective is to solve the speed limitations of the RSA algorithm and the key exchange vulnerability of AES by combining both into a robust, fast, and automated system. It ensures data integrity without constant user intervention, provides real-time terminal feedback, and maintains an audit log.

2. Development: Tools and Logic

A. Tech Stack

Tool Role in Project
Python 3.x Core development language.
PyCryptodome Implementation of RSA (Asymmetric) and AES-256 (Symmetric) algorithms.
Watchdog Kernel event management for real-time directory monitoring.
Pathlib Advanced manipulation of file paths and extensions.
Zlib Data compression prior to encryption to optimize storage.
Logging Native library used for technical audit logs.

B. Hybrid Cryptography Logic

The system operates under the following mathematical workflow to ensure both security and efficiency:

  1. Symmetric Encryption: A random 16-byte Session Key is generated to encrypt the file using AES-EAX. $$C = E_{AES_K}(P)$$
  2. Asymmetric Encryption: The Session Key is encrypted using the RSA-2048 Public Key. $$K_{enc} = E_{RSA_Pub}(K)$$
  3. Packaging: A payload is constructed by concatenating the encrypted key, the nonce, the authenticity tag, and the encrypted content, all encoded in Base64 for portability.

C. Event-Driven Architecture

  • Observer Pattern: Implemented via the watchdog library, subscribing to file system events where on_closed acts as the primary trigger.
  • Security Filters: A custom suffix system (.ederLockAlgorithm) was developed to prevent infinite encryption loops.
  • Lifecycle Management: A "Secure Deletion" policy using path.unlink() ensures the original plaintext file is destroyed immediately after successful encryption.
  • User-Friendly Interface: Real-time visual guidance in the terminal to monitor ongoing processes.

3. Conclusion

This implementation demonstrates that information security depends not only on algorithmic robustness but also on the supporting architecture. By integrating event-based monitoring, the system evolves from a manual tool into an automated, transparent security service. Using industry standards like RSA-2048 and AES-EAX guarantees that data remains inaccessible without the corresponding private key, laying the groundwork for complex data protection systems in private clouds.

4. Installation and Usage Guide

A. Prerequisites

  • Python 3.10 or higher.
  • Pip (Python package manager).

B. Environment Setup

It is highly recommended to use a virtual environment (venv) to avoid dependency conflicts.

  1. Create the virtual environment:

    python3 -m venv venv
  2. Activate the environment:

    source venv/bin/activate
  3. Install dependencies:

    pip install -r requirements.txt

C. Running the System

Launch the main script with the following command:

python main.py

Follow the on-screen instructions to generate RSA keys or start directory monitoring for encryption/decryption.

About

An event-driven cybersecurity daemon in Python that provides real-time, automated file system encryption. Combines the speed of AES-EAX with the security of RSA-2048 to create a seamless hybrid cryptography pipeline, featuring active directory monitoring and secure plaintext deletion.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages