AUTOMATED METADATA ANALYSIS AS AN INFORMATION LEAKAGE VECTOR

Authors

DOI:

https://doi.org/10.28925/2663-4023.2026.34.1341

Keywords:

metadata, cybersecurity, information leakage, deanonymization, OSINT tools, digital profiling, social engineering, spear phishing, Privacy by Design, Content Disarm and Reconstruction (CDR)

Abstract

This paper investigates a fundamental problem of modern cybersecurity—the automated collection and analysis of metadata, which functions as the “invisible digital DNA” of electronic documents, media files, and network communications. The study challenges the dangerous “illusion of security,” whereby users and organizations focus primarily on the cryptographic protection of visible content while overlooking hidden transit, descriptive, and structural artifacts. The paper provides a comprehensive analysis of the specific architectural vulnerabilities of popular formats (Microsoft Office, PDF, and JPEG) and, based on real-world incidents, demonstrates how the integration of OSINT tools with artificial intelligence algorithms transforms these digital traces into instruments for deanonymization, physical reconnaissance, and the preparation of highly targeted spear-phishing attacks. To empirically validate the theoretical framework, the paper presents the results of an extended experimental study involving a sample of 100 digital objects across 9 different formats. The research revealed a critical level of background sensitive-information leakage, with successful author deanonymization achieved in 77% of cases. To algorithmize protection processes, a mathematical model for quantitative threat assessment, the Metadata Information Risk Score (MIRS), was developed and statistically validated, with its accuracy confirmed by an F1-score of 98%. The study also demonstrates that conventional basic data-scrubbing techniques are ineffective against deep XML structures in office documents. In conclusion, the paper substantiates the need for multilayered defensive strategies to counter these threats, ranging from comprehensive content decomposition technologies such as Content Disarm and Reconstruction (CDR) and NIST de-identification standards to the fundamental implementation of the “Privacy by Design” concept.

Downloads

Download data is not yet available.

References

Joint Task Force. (2020). Security and privacy controls for information systems and organizations (NIST SP 800-53). NIST Technical Series Publications. https://nvlpubs.nist.gov

Wikipedia contributors. (n.d.). Exif. In Wikipedia, The Free Encyclopedia. https://en.wikipedia.org/wiki/Exif

Eckersley, P. (2010). How unique is whose web browser? The role of demographics in browser fingerprinting among US users. Privacy Enhancing Technologies Symposium (PETS). https://petsymposium.org

Wu, Z., et al. (2023). Rendered private: Making GLSL execution uniform to prevent WebGL-based browser fingerprinting. USENIX Security Symposium. https://usenix.org

Infosec Institute. (2021). Information gathering using Maltego. https://infosecinstitute.com

Eskandari, S., et al. (2023). The masks we (think we) wear: Privacy threats of browser-extension wallets in the Web3 ecosystem. Privacy Enhancing Technologies Symposium (PETS). https://petsymposium.org

Hou, S., et al. (2023). Breadcrumbs in the digital forest: Tracing criminals through torrent metadata with OSINT. arXiv. https://arxiv.org

Roy, S., et al. (2024). Context-aware spear phishing: Generative AI-enabled attacks against individuals via public social media data. arXiv. https://arxiv.org

Vectra AI. (2023). AI phishing: How attackers achieve 54% click rates in 5 minutes. https://vectra.ai

Hern, A. (2018). Fitness tracking app Strava gives away location of secret US army bases. The Guardian. https://theguardian.com

The Record. (2023). Russian naval officer killed near home may have been tracked on Strava app. The Record Media. https://therecord.media

Wikipedia contributors. (n.d.). Rafic Hariri. In Wikipedia, The Free Encyclopedia. https://en.wikipedia.org/wiki/Rafic_Hariri

Kurz, H., et al. (2021). Shadow attacks: Hiding and replacing content in signed PDFs. NDSS Symposium. https://ndss-symposium.org

Tenable. (2022). CVE-2022-25641 vulnerability details. Tenable Research. https://tenable.com

BRG. (2023). Nervous system: How legal tech helped catch the BTK killer. Berkeley Research Group. https://thinkbrg.com

Make Tech Easier. (2017). In May 2017, an NSA contractor named Reality Winner mailed a printed classified document. https://maketecheasier.com

Voisin, J. (2023). MAT2 - Metadata Anonymisation Toolkit [GitHub repository]. GitHub. https://github.com/jvoisin/mat2

MediaCircle. (2022). Clearswift adaptive redaction. https://mediacircle.de

Red Eagle Tech. (2023). What is content disarm and reconstruction (CDR)? Complete guide. https://redeagle.tech

Garfinkel, S. (2023). De-identifying government datasets: Techniques and governance (NIST SP 800-188). NIST Technical Series Publications. https://nvlpubs.nist.gov

NIST. (2020). NIST informative references for the Privacy Framework. https://nist.gov

Dataintelo. (2024). Metadata removal tools market research report 2034. https://dataintelo.com

Downloads


Abstract views: 13

Published

2026-09-24

How to Cite

Melnychuk, M., & Opirskyy, I. (2026). AUTOMATED METADATA ANALYSIS AS AN INFORMATION LEAKAGE VECTOR. Electronic Professional Scientific Journal «Cybersecurity: Education, Science, Technique», 2(34), 503–522. https://doi.org/10.28925/2663-4023.2026.34.1341

Most read articles by the same author(s)

1 2 3 > >>