MODEL FOR ASSESSING CORPORATE ENVIRONMENT VULNERABILITY TO SOCMINT ATTACKS BASED ON GRAPH METRICS ANALYSIS
DOI:
https://doi.org/10.28925/2663-4023.2026.34.1354Keywords:
OSINT, SOCMINT, cybersecurity, graph theory, betweenness centrality, social engineering, Counter-SOCMINT, digital footprint, compartmentalizationAbstract
The article develops and experimentally validates a method for the quantitative assessment of corporate environment vulnerability to SOCMINT attacks based on the apparatus of complex network theory. The relevance of the study is driven by the rapid growth in the volume of open data on social platforms, which is increasingly exploited by attackers to passively reconstruct an enterprise's internal organizational structure and prepare highly targeted social engineering attacks. It is shown that traditional information security audit approaches fail to provide a quantitative formalization of the personnel contact network topology, which precludes the targeted identification of structurally vulnerable employees. To address this problem, a two-level graph model of the corporate environment is formalized, combining a weighted internal communication graph of official interactions with a vector of employees’ external open exposure. The use of normalized betweenness centrality is justified for identifying nodes that act as structural “bridges” between departments regardless of their hierarchical rank. On this basis, an integral multiplicative vulnerability index is developed, combining the topological visibility of a node with a coefficient of the functional criticality of its role, by analogy with the classical risk paradigm “probability × consequences”. The experiment confirmed the method’s ability to reveal hidden critical data-leakage nodes. A set of differentiated Counter-SOCMINT recommendations has been formulated regarding the compartmentalization of personnel digital footprints, the decentralization of internal information flows, and the transition to continuous monitoring of the organization’s topological risks.
Downloads
References
Kemp, S. (2026). Global social media statistics. DataReportal. https://datareportal.com/social-media-users
Ivkova, V., & Opirsky, I. (2025). OSINT TECHNOLOGIES AS A THREAT TO STATE CYBERSECURITY. Electronic professional scientific publication "Cybersecurity: Education, Science, Technology", 3(27), 165–179.. https://doi.org/10.28925/2663-4023.2025.27.749
Omand, D., Bartlett, J., & Miller, C. (2012). Introducing Social Media Intelligence (SOCMINT). Intelligence and National Security, 27(6), 801–823. https://doi.org/10.1080/02684527.2012.716965
MITRE ATT&CK. (2020). Gather victim identity information (Technique T1589). MITRE Corporation. https://attack.mitre.org/techniques/T1589/
Krombholz, K., Hobel, H., Huber, M., & Weippl, E. (2015). Advanced social engineering attacks. Journal of Information Security and Applications, 22, 113–122. https://doi.org/10.1016/j.jisa.2014.09.005
Verizon Business. (2026). 2026 Data Breach Investigations Report. https://www.verizon.com/business/resources/reports/dbir/
Edwards, M., Larson, R., Green, B., Rashid, A., & Baron, A. (2017). Panning for gold: Automatically analysing online social engineering attack surfaces. Computers & Security, 69, 18–34. https://doi.org/10.1016/j.cose.2016.12.013
Pastor-Galindo, J., Nespoli, P., Gomez Marmol, F., & Martinez Perez, G. (2020). The Not Yet Exploited Goldmine of OSINT: Opportunities, Open Challenges and Future Trends. IEEE Access, 8, 10282–10304. https://doi.org/10.1109/access.2020.2965257
Fire, M., Goldschmidt, R., & Elovici, Y. (2014). Computationally identifying key actors in online social networks. Computers in Human Behavior, 40, 1–13. https://doi.org/10.1016/j.chb.2014.07.039
Hayes, D. R., & Cappa, F. (2018). Open-source intelligence for risk assessment. Business Horizons, 61(5), 689–697. https://doi.org/10.1016/j.bushor.2018.02.001
Bilge, L., Strufe, T., Balzarotti, D., & Kirda, E. (2009). All your contacts are belong to us: Automated identity theft attacks on social networks. In Proceedings of the 18th International Conference on World Wide Web (WWW ’09) (pp. 551–560). ACM. https://doi.org/10.1145/1526709.1526784
Freeman, L. C. (1977). A set of measures of centrality based on betweenness. Sociometry, 40(1), 35–41. https://doi.org/10.2307/3033543
Ho, G., Cidon, A., Gavish, L., Schweighauser, M., Paxson, V., Savage, S., Voelker, G. M., & Wagner, D. (2019). Detecting and characterizing lateral phishing at scale. In Proceedings of the 28th USENIX Security Symposium (pp. 1273–1290). USENIX Association. https://www.usenix.org/system/files/sec19-ho.pdf
Sepehrzadeh, H. (2023). A method for insider threat assessment by modeling the internal employee interactions. International Journal of Information Security, 22(5), 1385–1393. https://doi.org/10.1007/s10207-023-00697-9
Joint Task Force Transformation Initiative. (2012). Guide for Conducting Risk Assessments (NIST Special Publication 800-30, Rev. 1). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-30r1
Ivkova, V., & Opirsky, I. (2025). Investigation of the possibility of integrating the compartmentalization method into the protection of information in open sources. Computer systems and network. 2025. Vol. 7, No. 2. P. 71–83. URL: https://doi.org/10.23939/csn2025.02.071
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Валерія Івкова, Леонід Бортнік

This work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.