Linear cryptanalysis is a method used to break encryption standards like DES. It involves finding linear approximations between plaintext, ciphertext, and key bits that hold with probability greater than 50%. These approximations are used to determine partial key bits using maximum likelihood algorithms on known or ciphertext-only data. For S-DES, the method finds a linear expression involving S-box inputs/outputs that predicts a key bit with 78% accuracy, allowing recovery of multiple key bits.