A METHOD FOR FORMING A SOCIAL ENGINEER PROFILE BASED ON A DETECTED PHISHING ATTACK ON AN INFORMATION SYSTEM
DOI:
https://doi.org/10.31673/2409-7292.2026.032709Abstract
Phishing attacks remain one of the most widespread cyber threat vectors, as they combine technical mechanisms
for compromising information systems with social engineering techniques. At the same time, existing phishing detection
approaches are primarily focused on analyzing the technical parameters of an attack and do not provide a formalized
transition from detection results to identifying the characteristics of the attacker, which complicates cyberattack
attribution, cyber threat intelligence, and information security incident response. The aim of this study is to develop a
method for constructing a social engineer profile based on the analysis of a detected phishing attack on an information
system. The proposed method is based on extending a generalized tuple by integrating a set of attacker profile features
formed according to the set-theoretic classification model of modern social engineering attack implementation approaches
and the parameters of the detected phishing attack. The method consists of four main stages: constructing a formalized
representation of the phishing attack, determining the characteristics of the social engineer profile, constructing an
integrated social engineer profile, and visualizing the resulting profile. Unlike existing approaches, the proposed method
provides a formalized transition from the parameters of a detected phishing attack to the construction of an integrated
profile of its perpetrator. The proposed method was validated using a representative phishing attack, resulting in the
construction of a social engineer profile, identification of its key characteristics, and generation of a diagram that provides
a graphical representation of the resulting profile. The obtained results can be used to support cyberattack attribution,
cyber threat intelligence, information security incident response, and the development of countermeasures against social
engineering attacks.
Keywords: phishing, social engineer profile, attacker profile, social engineering, cyber threat intelligence,
information security.
References
1.Bada M., Nurse J.R.C. Profiling the Cybercriminal: A Systematic Review of Research // 2021 International
Conference on Cyber Situational Awareness, Data Analytics and Assessment (CyberSA). IEEE, 2021. P. 1–8. https://doi.
org/10.1109/CyberSA52016.2021.9478246
2.Nguyen V. Attribution of Spear Phishing Attacks: A Literature Survey. Edinburgh, Australia: Defence Science
and Technology Organisation (DSTO), Technical Report, 2013. 167 p. URL: https://apps.dtic.mil/ sti/pdfs/ ADA589740.
pdf.
3.Rogndokken M.R., Delport P.M.J., van Niekerk J. Facilitating Informed Cyberattack Attributions: The PACT
Model // Procedia Computer Science. Vol. 263. 2025. P. 399-409. https://doi.org/10.1016/j.procs.2025.07.049.
4.Корченко А., Іванченко Є., Сатибалдієва Ф., Жумангалієва Н., Давиденко К. Метод формування
еталонного субдовкілля для виявлення фішингових URL-адрес // Захист інформації. 2023. № 2. Т. 25. С. 82–95.
https://doi.org/10.18372/2410-7840.25.17757.
5.Корченко А. О., Давиденко К. О., Аскеров М. Г., Журов Ю. С. Метод формалізації багатовимірного
еталонного субдовкілля для виявлення фішингових URL-адрес // Сучасний захист інформації. 2026. № 2(66). С.
70–87. https://doi.org/10.31673/2409-7292.2026.021105.
6.Корченко А. Методи ідентифікації аномальних станів для систем виявлення вторгнень: монографія.
Київ: Компринт, 2019. 361 с.
7.Safi A., Singh S. A Systematic Literature Review on Phishing Website Detection Techniques // Journal of King
Saud University – Computer and Information Sciences. 2023. Vol. 35. P. 590-611. https://doi.org/10.1016/ j.jksuci.
2023.01.004.
8.Alkawaz M.H., Steven S.J., Hajamydeen A.I., Ramli R. A Comprehensive Survey on Identification and Analysis
of Phishing Website Based on Machine Learning Methods // 2021 IEEE Symposium on Computer Applications &
Industrial Electronics (ISCAIE). 2021. P. 82-87. https://doi.org/10.1109/ISCAIE51753.2021.9431794.
9.Basit A., Zafar M., Liu X., Javed A.R., Jalil Z., Kifayat K. A Comprehensive Survey of AI-Enabled Phishing
Attacks Detection Techniques // Telecommunication Systems. 2021. Vol. 76, No. 1. P. 139–154. https://doi.org/10.1007/
s11235-020-00733-2.
10. Korchenko O., Korchenko A., Zybin S., Davydenko K. An Approach for Classifying Socio-Technical Attacks
// Radioelectronic and Computer Systems. 2025. № 2. P. 230–252. https://doi.org/10.32620/reks.2025.2.15.
11. Корченко О., Корченко А., Зибін С., Давиденко К. Сучасні підходи реалізації соціотехнічних атак //
Information Technology: Computer Science, Software Engineering and Cyber Security. 2025. № 2. С. 48–71.
https://doi.org/10.32782/IT/2025-2-6.
12. Корченко А., Давиденко К. Теоретико-множинний підхід до класифікації сучасних методів
соціотехнічних атак // ITSec: Безпека інформаційних технологій: матеріали XIV Міжнар. наук.-техн. конф.
(Тернопіль, 22–24 травня 2025 р.). Тернопіль–Київ: ЗУНУ–ДУІКТ, 2025. С. 109–111.
13. Корченко А. А. Кортежная модель формирования набора базовых компонент для выявления кибератак
// Правове, нормативне та метрологічне забезпечення системи захисту інформації в Україні. 2014. Вип. 2(28).
С. 29-36.