Research Extension · Cyber · Network Analysis · Computational Methods
Empirical methods paper · December 2025 · approx. 4,900 words
Abstract
Cyber-conflict research faces an unusual empirical problem: much of the information researchers would most like to observe is missing, uncertain, contested, or deliberately concealed. Rather than treating this missingness purely as a limitation, this paper asks whether network structure can help interpret these structured unknowns.
Using the Cyber Events Database, the study represents cyber incidents relationally by connecting attributes including actor type, target industry, event subtype, motive, target country, and actor country. Network measures and community detection are used to identify recurring structures within known incidents, after which an exploratory inference procedure evaluates unknown attributes according to their structural proximity to observed categories.
The results suggest that missing cases often align with dominant incident ecosystems, particularly criminal-financial activity and high-frequency exploitation patterns. At the same time, the exercise reveals an important limitation: network inference tends to reproduce the dominant structure of the underlying dataset and may therefore amplify reporting biases or struggle to detect genuinely novel threats.
The paper is best understood as a proof of concept for treating uncertainty itself as relational information rather than simply discarding incomplete observations.
The paper therefore deliberately opts for a methodological proof of concept rather than causal inference or prediction.
Research Question
How can network analysis help interpret structured unknowns in cyber incidents?
Method
01 — Cyber Incident Data
The study uses the Cyber Events Database, containing 14,981 raw incident observations before cleaning.
02 — Relational Representation
Cyber incidents are transformed into a multipartite network connecting actor types, motives, event types, industries, target countries, and actor countries.
03 — Structural Analysis
Centrality measures and Louvain community detection are used to identify prominent categories, connectors, and recurring incident ecosystems.
04 — Relational Inference
Undetermined values are evaluated against the observed network context of each incident. Candidate categories with the strongest weighted connections to the incident’s known attributes are treated as the most plausible structural match.
The inference process is thus relational and probabilistic in nature; it makes no claim to definitive attribution.
What the Analysis Found
The inferred unknowns concentrate strongly around already dominant nodes in the network. Criminal actors and financial motives dominate many inferred cases, while common exploitation methods and major target environments also receive disproportionate weight.
At the geopolitical level, the procedure frequently aligns unknown target cases with the United States and unknown actor-country cases with Russia. These results should not be interpreted as definitive attribution. They partly reflect the structure and reporting biases of the underlying dataset.
Network inference is better at locating unknowns within known structures than at discovering genuinely new structures.
That is the primary methodological limitation. The paper explicitly concludes that the model reproduces existing patterns more easily than it detects new or under-reported threats.
Why This Matters
The methodological interest of the paper lies less in any individual inferred cyber incident than in a different way of thinking about missing data.
Cyber missingness is often politically structured: secrecy, attribution problems, uneven reporting capacity, and strategic incentives affect what becomes observable. A relational approach therefore asks whether missing information can sometimes be interpreted through the wider patterns in which it is embedded.
This shifts the analytical emphasis away from treating cyber incidents as isolated observations and toward understanding cyberspace as a structured system of recurring relations and co-occurrences.
Why I Am Returning To This
This project was an early empirical exploration of the broader network perspective that now forms a larger part of my research agenda.
Its strongest contribution is not the specific inference procedure itself, which remains deliberately exploratory. Instead, it demonstrates how network thinking changes the kinds of questions that can be asked about incomplete political data.
The project therefore connects naturally to my current work on network theory, computational methods, epistemic uncertainty, and the distinction between identifying statistical patterns and producing defensible explanations. Future versions could improve the inference procedure, use longitudinal networks, compare alternative cyber datasets, and examine whether similar relational approaches can be used in other politically opaque domains.
Related Research Directions
02 — Network Analysis & International Relations
The paper is an empirical example of treating observations as components of a wider relational system.
07 — Philosophy of Computational Social Science
Its treatment of missingness, uncertainty, inference, and the limits of computational conclusions connects directly to questions about what computational evidence can justify.
Read the Original Paper
This is the original December 2025 research paper. The network-inference approach is exploratory and its outputs should be interpreted as structural associations rather than definitive attribution.