MODEL FOR ASSESSING CORPORATE ENVIRONMENT VULNERABILITY TO SOCMINT ATTACKS BASED ON GRAPH METRICS ANALYSIS

Authors

DOI:

https://doi.org/10.28925/2663-4023.2026.34.1354

Keywords:

OSINT, SOCMINT, cybersecurity, graph theory, betweenness centrality, social engineering, Counter-SOCMINT, digital footprint, compartmentalization

Abstract

The article develops and experimentally validates a method for the quantitative assessment of corporate environment vulnerability to SOCMINT attacks based on the apparatus of complex network theory. The relevance of the study is driven by the rapid growth in the volume of open data on social platforms, which is increasingly exploited by attackers to passively reconstruct an enterprise's internal organizational structure and prepare highly targeted social engineering attacks. It is shown that traditional information security audit approaches fail to provide a quantitative formalization of the personnel contact network topology, which precludes the targeted identification of structurally vulnerable employees. To address this problem, a two-level graph model of the corporate environment is formalized, combining a weighted internal communication graph of official interactions with a vector of employees’ external open exposure. The use of normalized betweenness centrality is justified for identifying nodes that act as structural “bridges” between departments regardless of their hierarchical rank. On this basis, an integral multiplicative vulnerability index is developed, combining the topological visibility of a node with a coefficient of the functional criticality of its role, by analogy with the classical risk paradigm “probability × consequences”. The experiment confirmed the method’s ability to reveal hidden critical data-leakage nodes. A set of differentiated Counter-SOCMINT recommendations has been formulated regarding the compartmentalization of personnel digital footprints, the decentralization of internal information flows, and the transition to continuous monitoring of the organization’s topological risks.

Downloads

Download data is not yet available.

References

Kemp, S. (2026). Global social media statistics. DataReportal. https://datareportal.com/social-media-users

Ivkova, V., & Opirsky, I. (2025). OSINT TECHNOLOGIES AS A THREAT TO STATE CYBERSECURITY. Electronic professional scientific publication "Cybersecurity: Education, Science, Technology", 3(27), 165–179.. https://doi.org/10.28925/2663-4023.2025.27.749

Omand, D., Bartlett, J., & Miller, C. (2012). Introducing Social Media Intelligence (SOCMINT). Intelligence and National Security, 27(6), 801–823. https://doi.org/10.1080/02684527.2012.716965

MITRE ATT&CK. (2020). Gather victim identity information (Technique T1589). MITRE Corporation. https://attack.mitre.org/techniques/T1589/

Krombholz, K., Hobel, H., Huber, M., & Weippl, E. (2015). Advanced social engineering attacks. Journal of Information Security and Applications, 22, 113–122. https://doi.org/10.1016/j.jisa.2014.09.005

Verizon Business. (2026). 2026 Data Breach Investigations Report. https://www.verizon.com/business/resources/reports/dbir/

Edwards, M., Larson, R., Green, B., Rashid, A., & Baron, A. (2017). Panning for gold: Automatically analysing online social engineering attack surfaces. Computers & Security, 69, 18–34. https://doi.org/10.1016/j.cose.2016.12.013

Pastor-Galindo, J., Nespoli, P., Gomez Marmol, F., & Martinez Perez, G. (2020). The Not Yet Exploited Goldmine of OSINT: Opportunities, Open Challenges and Future Trends. IEEE Access, 8, 10282–10304. https://doi.org/10.1109/access.2020.2965257

Fire, M., Goldschmidt, R., & Elovici, Y. (2014). Computationally identifying key actors in online social networks. Computers in Human Behavior, 40, 1–13. https://doi.org/10.1016/j.chb.2014.07.039

Hayes, D. R., & Cappa, F. (2018). Open-source intelligence for risk assessment. Business Horizons, 61(5), 689–697. https://doi.org/10.1016/j.bushor.2018.02.001

Bilge, L., Strufe, T., Balzarotti, D., & Kirda, E. (2009). All your contacts are belong to us: Automated identity theft attacks on social networks. In Proceedings of the 18th International Conference on World Wide Web (WWW ’09) (pp. 551–560). ACM. https://doi.org/10.1145/1526709.1526784

Freeman, L. C. (1977). A set of measures of centrality based on betweenness. Sociometry, 40(1), 35–41. https://doi.org/10.2307/3033543

Ho, G., Cidon, A., Gavish, L., Schweighauser, M., Paxson, V., Savage, S., Voelker, G. M., & Wagner, D. (2019). Detecting and characterizing lateral phishing at scale. In Proceedings of the 28th USENIX Security Symposium (pp. 1273–1290). USENIX Association. https://www.usenix.org/system/files/sec19-ho.pdf

Sepehrzadeh, H. (2023). A method for insider threat assessment by modeling the internal employee interactions. International Journal of Information Security, 22(5), 1385–1393. https://doi.org/10.1007/s10207-023-00697-9

Joint Task Force Transformation Initiative. (2012). Guide for Conducting Risk Assessments (NIST Special Publication 800-30, Rev. 1). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-30r1

Ivkova, V., & Opirsky, I. (2025). Investigation of the possibility of integrating the compartmentalization method into the protection of information in open sources. Computer systems and network. 2025. Vol. 7, No. 2. P. 71–83. URL: https://doi.org/10.23939/csn2025.02.071

Downloads


Abstract views: 16

Published

2026-09-24

How to Cite

Ivkova, V., & Bortnik, L. (2026). MODEL FOR ASSESSING CORPORATE ENVIRONMENT VULNERABILITY TO SOCMINT ATTACKS BASED ON GRAPH METRICS ANALYSIS. Electronic Professional Scientific Journal «Cybersecurity: Education, Science, Technique», 2(34), 620–629. https://doi.org/10.28925/2663-4023.2026.34.1354