Главная
АИ #41 (327)
Статьи журнала АИ #41 (327)
Social network analysis (SNA): from theoretical foundations to applications and ...

Social network analysis (SNA): from theoretical foundations to applications and security in the digital age

7 октября 2026

Цитирование

Tran T. H., Nguyen B. C. Social network analysis (SNA): from theoretical foundations to applications and security in the digital age // Актуальные исследования. 2026. №41 (327). URL: https://apni.ru/article/16111-social-network-analysis-sna-from-theoretical-foundations-to-applications-and-security-in-the-digital-age

Аннотация статьи

Social network analysis examines relationships among actors to explain how social structure shapes access to information, collaboration, and collective behavior. Digital platforms have expanded observable interactions while creating challenges of measurement, causal interpretation, privacy, and security. This report introduces SNA foundations and methods, then discusses applications in communication, business, education, public services, and digital security. Particular attention is given to fake accounts, coordinated manipulation, and the protection of relational data. Meaningful network analysis requires clear relationship definitions, a transparent workflow, and careful validation of findings and their practical implications.

Текст статьи

1. Introduction

Social network analysis (SNA) studies patterns of relationships among people, groups, or organizations. Its central question concerns how an actor’s position in a network affects opportunities and constraints. A person with few direct connections may still connect otherwise separated communities, while a highly connected actor may mainly circulate information within one close group. These differences are difficult to capture through individual attributes alone.

SNA is broader than the analysis of social media. Its data may come from interviews, friendship nominations, organizational communication, scientific collaboration, or digital interaction records. Online platforms provide extensive traces of following, replying, sharing, and participating, but those actions represent different relationships. A follow link, for example, does not automatically indicate friendship, agreement, or actual exposure to every message.

2. Theoretical Foundations

A network is commonly represented as a graph G = (V, E), where V contains actors and E contains defined ties. Edges may be directed, as in a message sent from one account to another; undirected, as in a mutually recognized collaboration; or weighted, as in interaction frequency. Bipartite networks connect two actor types, such as users and discussion groups. Temporal networks preserve when interactions occur, and multilayer networks distinguish different kinds of ties.

Granovetter’s theory of weak ties explains how relatively weak relationships can connect social circles and provide access to information unavailable within tightly connected groups [1, p. 1360-1380]. Freeman distinguishes degree, closeness, and betweenness as different concepts of centrality [2, p. 215-239]. Watts and Strogatz show how high local clustering can coexist with short network paths [3, p. 440-442]. Community analysis identifies groups with relatively dense internal connections [4, p. 7821-7826]. Together, these ideas link local relationships, intermediary positions, and overall network organization.

3. Core Methods and Analytical Workflow

3.1. Measuring Position and Structure

Analytical measures should follow the research question. For a simple undirected graph with n actors, normalized degree centrality is k/(n − 1), where k is an actor’s number of neighbors. Network density is 2m/[n(n − 1)], where m is the number of edges. These expressions assume no self-loops or parallel edges. Directed and weighted networks require appropriate definitions; comparing their values without a common construction rule can be misleading.

Table

Principal SNA measures and interpretation limits

Measure

Analytical use

Interpretation limit

Degree/strength

Direct connectivity / total tie weight

Activity is not necessarily influence

Betweenness

Potential brokerage on shortest paths

Actual diffusion may use other paths

Closeness

Reach through short paths

Disconnected graphs need explicit handling

Eigenvector centrality

Connections to well-connected actors

Depends on direction and network structure

Clustering/density

Local closure / overall connectedness

Sensitive to network size and tie definitions

Community structure

Groups with stronger internal connections

Clusters do not automatically reveal beliefs

Community detection examines grouping patterns rather than individual prominence. The Girvan–Newman method illustrates this idea through the removal of edges with high edge betweenness [4, p. 7821-7826]. Other methods optimize different objectives, so community assignments depend on algorithm choice, resolution, and the observed network. A visual cluster is evidence of a structural pattern, not proof of ideological agreement or coordinated activity.

3.2. From Data to Validated Findings

A practical workflow begins by defining the population, time window, and meaning of each tie. Data are then collected through authorized sources, cleaned, and converted into a graph. Duplicate accounts, missing observations, repeated interactions, and automated activity should be documented. Analysts calculate relevant measures, inspect visualizations, and test sensitivity to sampling, edge thresholds, and alternative time windows.

Visualization helps formulate questions but should be supported by quantitative checks. Predictive tasks require a temporal split: information collected after the prediction date must not enter training. Evaluation should compare network features with suitable non-network baselines and inspect errors across groups. Similar behavior among connected actors may reflect shared preferences or circumstances rather than interpersonal influence; observational homophily and contagion can be confounded [5, p. 211-239].

4. Application Directions in the Digital Age

4.1. Public Opinion and Information Diffusion

Networks of replies, mentions, and reposts reveal interaction communities and topic diffusion pathways. Combining network structure with text analysis helps identify emerging issues and accounts connecting discussion groups. Sentiment requires separate validation; it cannot be inferred from network position alone.

Vosoughi, Roy, and Aral examined the diffusion of verified true and false news on Twitter and found substantial differences in their spreading patterns [6, p. 1146-1151]. Their result demonstrates the value of studying cascades, but does not justify labeling a new message false from network shape alone. Fact verification, topic, collection period, and platform context remain necessary. Visible online discussion also cannot automatically represent the opinions of an entire population.

4.2. Marketing and Organizational Collaboration

Businesses can examine referral networks, customer communities, and communication between teams. Network-informed partner selection considers audience connections alongside follower counts. Organizational networks can reveal knowledge brokers, isolated teams, or dependence on a few intermediaries. These patterns require contextual interpretation and are not direct measures of individual productivity.

Business evaluation should link network-informed interventions to outcomes such as qualified referrals or reduced coordination delays. Randomized or carefully designed comparisons are preferable for estimating effects; a network map alone cannot establish commercial or organizational improvement.

4.3. Education and Public Services

In digital learning environments, discussion and collaboration networks can help instructors examine participation, peer support, and group integration. A learner with few visible interactions may require additional support, but may also prefer independent study or communicate outside the observed platform. Interpretation should combine network evidence with task outcomes and learner feedback. Public-service applications can similarly map cooperation among agencies or community organizations to locate gaps in communication and service coordination.

4.4. Digital Security and Graph-Based Prediction

In digital security, SNA complements account-level checks by examining relationships among potentially abusive actors. SybilRank illustrates how social graph properties can help prioritize suspected fake accounts for review [9, p. 197-210]. Coordination networks can also link accounts through repeated shared content, reposting, or temporal patterns to investigate manipulation campaigns [10, p. 455-466]. These methods can support the assessment of scams, malicious amplification, and suspicious interaction groups. Coordination alone does not establish harmful intent: legitimate campaigns and public events can produce similar patterns. Analyst verification, false-positive assessment, and preservation of supporting evidence are therefore essential. Where authorized, network findings should be combined with authentication records, message content, and incident context rather than used as automatic accusations.

GraphSAGE aggregates neighborhood features to represent previously unseen nodes [7], supporting classification and link prediction. Security applications require temporal validation, checks for manipulated links, and simpler baselines. Predictive alerts should guide investigation rather than establish malicious behavior.

5. Limitations and Future Directions

Network findings depend on which actors and ties are observed. Missing private interactions, platform-specific participation, account changes, and uneven sampling can distort centrality and community structure. Large datasets do not remove these biases. A defensible report should state its network boundary, sampling process, and uncertainty, and should avoid treating an observed digital network as a complete social system.

Privacy protection requires more than deleting names. Research on human mobility shows that behavioral traces can permit re-identification even when direct identifiers are removed [8]. Although mobility data differ from social graphs, the finding illustrates risks in linking rich digital records. SNA datasets should use data minimization, access controls, and aggregation where appropriate. Encryption, access logging, and defined retention periods help protect relationship records that could otherwise expose sensitive contacts or enable targeted social engineering. Sensitive individual labels require a justified purpose and safeguards.

Promising directions include temporal and multilayer analysis, and graph learning that combines structure with validated content features. Language models may assist with extracting candidate entities, relations, or topics, but outputs require source verification. Security research should test robustness against fabricated links, changing attacker behavior, and coordinated evasion. Causal designs and transparent uncertainty remain necessary to distinguish description, prediction, and intervention effects.

6. Conclusion

SNA provides a relational framework for understanding connectivity, brokerage, communities, and diffusion. Digital applications extend to communication, business, education, public services, and security. It can support threat investigation while also revealing sensitive relationships that require protection. Practical value depends on clear tie definitions, appropriate methods, and contextual validation. Responsible use combines network evidence with domain knowledge and distinguishes structural patterns from causal explanations and verified security incidents.

Список литературы

  1. Granovetter M.S. (1973). The strength of weak ties. American Journal of Sociology, No. 78(6), P. 1360-1380. doi:10.1086/225469.
  2. Freeman L.C. (1978/1979). Centrality in social networks: Conceptual clarification. Social Networks, No. 1(3), P. 215-239. doi:10.1016/0378-8733(78)90021-7.
  3. Watts D.J., Strogatz S.H. (1998). Collective dynamics of small-world networks. Nature, No. 393, P. 440-442. doi:10.1038/30918.
  4. Girvan M., Newman M.E.J. (2002). Community structure in social and biological networks. PNAS, No. 99(12), P. 7821-7826. doi:10.1073/pnas.122653799.
  5. Shalizi C.R., Thomas A.C. (2011). Homophily and contagion are generically confounded in observational social network studies. Sociological Methods & Research, No. 40(2), P. 211-239. doi:10.1177/0049124111404820.
  6. Vosoughi S., Roy D., Aral S. (2018). The spread of true and false news online. Science, No. 359(6380), P. 1146-1151. doi:10.1126/science.aap9559.
  7. Hamilton W., Ying Z., Leskovec J. (2017). Inductive representation learning on large graphs. Advances in Neural Information Processing Systems, 30. https://proceedings.neurips.cc/paper/2017/hash/5dd9db5e033da9c6fb5ba83c7a7ebea9-Abstract.html
  8. de Montjoye Y.-A., Hidalgo C.A., Verleysen M., Blondel V.D. (2013). Unique in the crowd: The privacy bounds of human mobility. Scientific Reports, 3, 1376. doi:10.1038/srep01376.
  9. Cao Q., Sirivianos M., Yang X., Pregueiro T. (2012). Aiding the detection of fake accounts in large scale social online services. NSDI, P. 197-210. https://www.usenix.org/conference/nsdi12/technical-sessions/presentation/cao
  10. Pacheco D., Hui P.-M., Torres-Lugo C., Truong B.T., Flammini A., Menczer F. (2021). Uncovering coordinated networks on social media: Methods and case studies. ICWSM, No. 15(1), P. 455-466. doi:10.1609/icwsm.v15i1.18075.

Поделиться

28
Обнаружили грубую ошибку (плагиат, фальсифицированные данные или иные нарушения научно-издательской этики)? Напишите письмо в редакцию журнала: info@apni.ru

Похожие статьи

Другие статьи из раздела «Информационные технологии»

Все статьи выпуска
Актуальные исследования

#41 (327)

Прием материалов

3 октября - 9 октября

осталось 2 дня

Размещение PDF-версии журнала

14 октября

Размещение электронной версии статьи

сразу после оплаты

Рассылка печатных экземпляров

28 октября