AUTOMATED METADATA ANALYSIS AS AN INFORMATION LEAKAGE VECTOR
DOI:
https://doi.org/10.28925/2663-4023.2026.34.1341Keywords:
metadata, cybersecurity, information leakage, deanonymization, OSINT tools, digital profiling, social engineering, spear phishing, Privacy by Design, Content Disarm and Reconstruction (CDR)Abstract
This paper investigates a fundamental problem of modern cybersecurity—the automated collection and analysis of metadata, which functions as the “invisible digital DNA” of electronic documents, media files, and network communications. The study challenges the dangerous “illusion of security,” whereby users and organizations focus primarily on the cryptographic protection of visible content while overlooking hidden transit, descriptive, and structural artifacts. The paper provides a comprehensive analysis of the specific architectural vulnerabilities of popular formats (Microsoft Office, PDF, and JPEG) and, based on real-world incidents, demonstrates how the integration of OSINT tools with artificial intelligence algorithms transforms these digital traces into instruments for deanonymization, physical reconnaissance, and the preparation of highly targeted spear-phishing attacks. To empirically validate the theoretical framework, the paper presents the results of an extended experimental study involving a sample of 100 digital objects across 9 different formats. The research revealed a critical level of background sensitive-information leakage, with successful author deanonymization achieved in 77% of cases. To algorithmize protection processes, a mathematical model for quantitative threat assessment, the Metadata Information Risk Score (MIRS), was developed and statistically validated, with its accuracy confirmed by an F1-score of 98%. The study also demonstrates that conventional basic data-scrubbing techniques are ineffective against deep XML structures in office documents. In conclusion, the paper substantiates the need for multilayered defensive strategies to counter these threats, ranging from comprehensive content decomposition technologies such as Content Disarm and Reconstruction (CDR) and NIST de-identification standards to the fundamental implementation of the “Privacy by Design” concept.
Downloads
References
Joint Task Force. (2020). Security and privacy controls for information systems and organizations (NIST SP 800-53). NIST Technical Series Publications. https://nvlpubs.nist.gov
Wikipedia contributors. (n.d.). Exif. In Wikipedia, The Free Encyclopedia. https://en.wikipedia.org/wiki/Exif
Eckersley, P. (2010). How unique is whose web browser? The role of demographics in browser fingerprinting among US users. Privacy Enhancing Technologies Symposium (PETS). https://petsymposium.org
Wu, Z., et al. (2023). Rendered private: Making GLSL execution uniform to prevent WebGL-based browser fingerprinting. USENIX Security Symposium. https://usenix.org
Infosec Institute. (2021). Information gathering using Maltego. https://infosecinstitute.com
Eskandari, S., et al. (2023). The masks we (think we) wear: Privacy threats of browser-extension wallets in the Web3 ecosystem. Privacy Enhancing Technologies Symposium (PETS). https://petsymposium.org
Hou, S., et al. (2023). Breadcrumbs in the digital forest: Tracing criminals through torrent metadata with OSINT. arXiv. https://arxiv.org
Roy, S., et al. (2024). Context-aware spear phishing: Generative AI-enabled attacks against individuals via public social media data. arXiv. https://arxiv.org
Vectra AI. (2023). AI phishing: How attackers achieve 54% click rates in 5 minutes. https://vectra.ai
Hern, A. (2018). Fitness tracking app Strava gives away location of secret US army bases. The Guardian. https://theguardian.com
The Record. (2023). Russian naval officer killed near home may have been tracked on Strava app. The Record Media. https://therecord.media
Wikipedia contributors. (n.d.). Rafic Hariri. In Wikipedia, The Free Encyclopedia. https://en.wikipedia.org/wiki/Rafic_Hariri
Kurz, H., et al. (2021). Shadow attacks: Hiding and replacing content in signed PDFs. NDSS Symposium. https://ndss-symposium.org
Tenable. (2022). CVE-2022-25641 vulnerability details. Tenable Research. https://tenable.com
BRG. (2023). Nervous system: How legal tech helped catch the BTK killer. Berkeley Research Group. https://thinkbrg.com
Make Tech Easier. (2017). In May 2017, an NSA contractor named Reality Winner mailed a printed classified document. https://maketecheasier.com
Voisin, J. (2023). MAT2 - Metadata Anonymisation Toolkit [GitHub repository]. GitHub. https://github.com/jvoisin/mat2
MediaCircle. (2022). Clearswift adaptive redaction. https://mediacircle.de
Red Eagle Tech. (2023). What is content disarm and reconstruction (CDR)? Complete guide. https://redeagle.tech
Garfinkel, S. (2023). De-identifying government datasets: Techniques and governance (NIST SP 800-188). NIST Technical Series Publications. https://nvlpubs.nist.gov
NIST. (2020). NIST informative references for the Privacy Framework. https://nist.gov
Dataintelo. (2024). Metadata removal tools market research report 2034. https://dataintelo.com
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Максим Мельничук, Іван Опірський

This work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.