How Web Network Investigations Improve Threat-Level and Attribution Assessments of Influence Operations
An analysis of 827 cognitive-warfare and FIMI reports (2022-2026): investigations centered on website networks lead on both threat description and attribution
Reporting on cognitive warfare and FIMI (Foreign Information Manipulation and Interference) has developed around the analysis of fake account networks on social media. Yet scoring 827 reports published between 2022 and 2026 (including two Japanese documents published in 2020) against a common set of indicators locates the highest standard of description elsewhere: in investigations whose principal object is websites and the networks they form, that is, in web network investigation of influence operations. That category ranks highest in describing the severity of the threat, and holds the largest share of reports in which the description of the attacking actor keeps pace with it.
Section 1 summarizes the results, Section 2 contrasts SNS-focused investigation, centered on social networking services, with web-focused investigation, Section 3 presents the empirical analysis of the 827 reports and its limits, Section 4 the outlook, Section 5 the challenges facing Japan, and Section 6 the conclusion.
1. Summary
The material is evaluation data held by Kasouken (仮創研, an organization that conducts LLM-based thought experiments and research analysis: https://note.com/ichi_twnovel/m/mcbf381f39cea ); LLM stands for large language model. Kasouken continuously rates reports published by government agencies, research institutes and private companies with its 24-item report evaluation framework, which scores a report's comprehensiveness across 24 items on a five-point scale. The 827 reports analyzed here, published between 2022 and 2026 (including two Japanese documents published in 2020), comprise 730 from Western institutions, 50 from Japanese institutions and 47 from South Korean and Taiwanese institutions.
Each was sorted into one of four categories according to whether its principal object of investigation was accounts and posts on social media or websites and site networks. Reports centered on website investigation rank highest in the major category "Confirmation of Threat-Level Exceedance," and in the major category "Attribution" (identifying the actor behind an operation) their 3.37 stands effectively level with the composite SNS-and-web type at 3.39. The difference is not confined to the means: attribution equals or exceeds the threat description in 48.0% of website-centered reports against 35.1% of SNS-centered ones. In the task this field has always found hardest, investigations that follow web networks reach a comparatively high level.
The claim that follows is simple. Expanding web network investigation of influence operations can effectively raise the precision of investigation, both in grasping the level of the threat and in inferring the actor behind it.
This is, however, an observation based on correlation. The institutions conducting web network investigations are already concentrated among a few technically capable organizations, and web-network operations contain a large element of illegality and concealment from the outset. These two biases may be pushing the result upward; Section 3 sets them out explicitly.
In Figure 1 the horizontal axis is the standard of description of the threat's severity, the vertical axis that of identifying the attacking actor, both scored from 1 to 5. Colored areas show where each category clusters most densely and large markers their means; below the diagonal dotted line, attribution has not caught up with the threat description.
2. The Difference Between SNS-Focused and Web-Focused Investigation
Reports were classified by principal object into four groups: centered on SNS investigation, centered on website investigation, a composite of the two, and other. "Other" covers policy recommendations, opinion surveys, annual overviews and similar reports that do not empirically track a specific operation. The exposure of coordinated account networks on social media counts as SNS investigation.
SNS-focused investigation is defined by the provenance of its data. Posts, accounts and diffusion links are observable only within bounds set by a few platform companies, and pseudonymity blocks the route to the entity behind an account: what can be established often goes no further than the existence of coordinated behavior by a single operator, not who that operator is. Deleted accounts take the traces with them, and a change in the terms on which an API (a data access interface) is provided severs the tracking itself. Even platform companies' own takedown reports usually attribute only at the level of a country or an operation, rarely naming the operating organization.
Web-focused investigation rests instead on public technical traces: domain registration records, shared DNS (which maps domain names to servers) and hosting, TLS certificates (the electronic certificates sites hold in order to encrypt communications), advertising account identifiers, the fingerprints of site-building systems (common features in configuration and modification habits), and past versions preserved in web archives. Cross-referencing these can show that sites unrelated on their face share an operator, and can reach the operating company or individual. It also opens access to the flow of money through advertising revenue and contracting, which SNS-focused investigation lacks, and because past versions survive it supports continuous monitoring of when sites were added and when the source of distributed content changed.
Existing work shows how far the actual entity can be reached. In 2023 the French government agency VIGINUM officially named two Russian companies, Structura and Social Design Agency, as operators of a network of sites impersonating news organizations (known as Doppelganger). Recorded Future pointed to the involvement of the American John Mark Dougan and others in operating the fake news site network CopyCop. Citizen Lab and EU DisinfoLab exposed PAPERWALL, a network of Chinese-linked sites posing as local newspapers. In each case attribution advanced to a company or personal name.
Table 1: Comparison of what can be identified
Two structural reasons have nonetheless kept the center of gravity on social media. Fake accounts and pile-ons are readily picked up by the media and readily treated as a political problem; and analytical tools that visualize relationships among accounts and measure posting trends are widely distributed, so the threshold for entry is low.
This is the streetlight effect, an established term in English: the parable of a person who drops a key at night and searches under the bright streetlight rather than where it fell, naming the habit by which search concentrates where searching is easy. Social media, easy to observe and easy to publicize, lies under the streetlight. The key, the operating body of the operation and the substance of its funding, often lies outside the light.
The spread of tools cuts both ways. Tools guarantee a certain standard of result even without specialist training and have broadened the base of the field, but analysis is constrained to the range a tool supports. Two consequences are more serious. The overall picture is lost, so only the interior of the observable platform is presented as the shape of the influence operation. And work drifts case by case, cases the tools handle being analyzed first while intractable objects quietly fall out of scope. Because what was not investigated never appears in a report, this omission is invisible to the reader.
3. Empirical Analysis: Evaluation Data from 827 Cognitive Warfare Reports
Kasouken's 24-item report evaluation framework scores a report's comprehensiveness across 24 items on a five-point scale, where a full account scores 5 and no mention scores 1. Two of its major categories are used here. "Confirmation of Threat-Level Exceedance" measures how fully a report describes whether the operation constitutes an illegal act or a violation of terms of service, and whether it involves concealment of the actor or evasion of sanctions; it is the mean of two items and runs from 1 to 5. "Attribution" measures how fully a report describes the identification of the attacking actor and of the funding source, likewise the mean of two items. The difference between them, attribution minus threat level, is called the gap here; a negative value means the severity of the threat has been described but not who is responsible.
Across all 827 reports the mean is 3.38 for threat level against 2.88 for attribution. The center of gravity lies below the line where the two are equal, that is, below the diagonal dotted line in Figure 1: description in this field is broadly in a state where the threat can be told but attribution cannot. Weakest of all is the identification of funding sources. Of the 827 reports, 300 (36%) contain no mention whatsoever, and including inadequate mentions the figure reaches 511 (62%). To the question of who is paying, the majority of reports give no answer.
Table 2: Results by category of investigative object
The ordering is clear. Reports centered on website investigation rank highest on threat level and follow the composite type (3.39) by a narrow margin on attribution at 3.37, with a gap close to the smallest; the composite type sits alongside them, then SNS investigation, then other.
The difference should not be read too heavily. The median gap is −0.50 for all four categories, exactly equal: take one typical report and, whatever the category, attribution lags the threat by half a step. The categories differ in the means and in the tails, observable as a difference in composition, namely how many reports a category contains in which attribution catches up and how many lag by 1 point or more. The share lagging by one point or more is 33.3% for website investigation and 27.8% for the composite type, against 43.2% for SNS investigation and 40.4% for other. Investigations that follow web networks contain a distinctly lower proportion of reports in which attribution has been left far behind.
In Figure 2 the four categories of investigative object run vertically and the region of the producing institution (Western, South Korean and Taiwanese, Japanese) horizontally; within each cell the points are individual reports, the large markers and figures their mean. The pale gray points are all 827 reports, a background against which each cell's position can be compared.
The first fact this shows is the extreme narrowness of the set of implementing institutions. Of the 75 reports centered on website investigation, 71 (94.7%) came from Western institutions, as did 35 of the 36 composite reports. The work is concentrated in a few institutions with technical investigative capability, among them the Atlantic Council's DFRLab, Recorded Future, Mandiant, VIGINUM, NewsGuard, EU DisinfoLab and Citizen Lab. That web investigation requires the methodologies of digital forensics (the technical analysis of electronic traces) and OSINT (investigative methods based on publicly available information), and that few organizations have been able to carry it out, is reflected directly in these numbers. Restricted to web network investigations by Western institutions, the figures are 3.72 for threat level, 3.46 for attribution and −0.26 for the gap, making the ordering among categories sharper still.
Second, there is a hierarchy by the region of the producing institution.
Figure 3 draws, for each region, the range in which its reports cluster most densely, together with the mean; the upper right indicates fuller description of both threat and attribution. The 730 reports from Western institutions stand at 3.50 and 3.01, the 47 from South Korean and Taiwanese institutions at 2.99 and 2.09, and the 50 from Japanese institutions at 2.08 and 1.79, lining up from upper right to lower left.
The main cause of this regional difference lies less in capability than in the mix of investigation types. The nine SNS investigations by South Korean and Taiwanese institutions score 3.94 for threat level and 2.94 for attribution, on a par with the 373 by Western institutions (3.46 and 2.96) and in fact higher on the threat description. Where empirical investigation is carried out, the standard is not inferior to that of Western institutions. What pulls the regional averages down is the weight of non-empirical categories such as policy recommendations, opinion surveys and annual overviews, whose share differs sharply: 88% for Japan, 72% for South Korea and Taiwan, 34% for the West. The problem is not the capacity to conduct empirical investigation but the number of empirical investigations.
South Korean and Taiwanese institutions show one further characteristic: their gap, at −0.90, is the largest of the three regions. Two readings are possible. One is that the practice of empirically establishing attribution is comparatively weak. The other is that, the threatening actor being more or less fixed as China, there is little need to demonstrate attribution afresh in each report; in fact 40 of the 47 reports (85%) name China as the interfering actor, and 28 name China alone. The second reading is an inference with a certain plausibility. Yet proceeding with an investigation while taking the actor as given risks overlooking activity by other actors such as Russia and North Korea, and newly emerging actors. The habit of not writing attribution ultimately remains a weakness in the investigative apparatus.
The same data show that conducting web investigation does not automatically raise precision. Three web network investigations by South Korean government-affiliated institutions, announcing the takedown of fake sites, score 3.83 for threat level against 1.67 for attribution, a gap reaching −2.17. They list the sites taken down and publish the counts, but the empirical description of who operated them and where the money came from is thin. Access to the method is not enough; precision rises only when norms and practice for empirically establishing and describing attribution accompany it.
Two confounders in these results should finally be stated explicitly. The first is an institutional effect: those carrying out web network investigations are already concentrated among technically strong institutions, so the high scores reflect in part the capability of the implementing institution rather than the method. The second is an object effect: web-network operations contain from the outset such elements as impersonation of news organizations and contracting routed through sanctioned companies, so the items of "Confirmation of Threat-Level Exceedance," which ask about illegality and concealment, tend to score high. The classification decision adopted here, counting the exposure of coordinated account networks on social media as SNS investigation, also affects the size of the contrast between categories. What is shown here is therefore not proof of a causal relationship in which conducting web investigation necessarily raises precision, but a correlation suggesting its effectiveness. Even with that reservation, the proportion of reports in which attribution catches up with the threat differs clearly between categories.
4. Outlook: The Expansion of Web Investigation Through AI
The chief reason web network investigation has been concentrated in a few Western institutions is the height of the barrier to entry. Three things are needed at once: analysts trained in digital forensics and OSINT, staff able to sustain the work of cross-referencing traces, and an apparatus for monitoring large numbers of sites continuously. Publication adds a further burden, since the technical grounds must be written up so that third parties can replicate them. Few organizations possess all of this.
These conditions are changing. Matching leads such as registration records, certificates and advertising identifiers, identifying site networks by common fingerprints, and monitoring large numbers of sites are all repetitions of routine judgment, requiring volume of work rather than high-level insight. Tasks that once demanded a specialist team are becoming easier for small numbers of people to execute with AI support. Kasouken itself uses large language models to investigate and continuously monitor influence operation networks. The development and implementation of AI-assisted web investigation methods will likely increase. This is an inference from current technological trends, not an established fact. The design questions of which leads to weight, and what degree of correspondence justifies concluding common operation, meanwhile remain with the analyst.
Three areas hold promise. The first is continuous monitoring: watching the addition and removal of domains and changes in the composition of site networks, and recording the moment of change, is burdensome by hand and suited to machine support. The second is prediction, since influence operations invariably pass through a stage of infrastructure preparation such as bulk domain acquisition and site construction, and catching that stage means grasping warning signs before an operation unfolds. The third is prevention: identifying in advance the site networks likely to be mobilized ahead of elections and other critical dates, and linking that to countermeasures. Exposure conventionally follows execution, but a network mapped at the infrastructure stage leaves room to choose the timing of publication. None of this is easily achieved in SNS-focused investigation, where deletion readily severs observation; it is specific to web investigation, where traces accumulate.
Caution is nonetheless required. Even as AI advances the instrumentation of investigation, the structure of relying on tools does not change, and the traps described in Section 2, case-by-case work and the loss of the overall picture, persist in the same form when the object shifts from social media to the web. If anything, as the volume processed grows, it may become harder to notice what is being missed outside the range the tools handle. That is precisely why publishing the methodology, which leads were cross-referenced and how, and presenting results in a form third parties can verify, matters.
5. Challenges for Japan
The same data show the situation in Japan. Of the 50 reports from Japanese institutions, 44 (88%) fall into non-empirical categories such as policy recommendations, opinion surveys and white papers. The absence of empirical work is itself the largest problem. Those involving actual investigation comprise five investigations targeting posts on social media, including analysis on X (formerly Twitter) of disinformation surrounding rescue requests during the Noto Peninsula earthquake and analysis of cognitive warfare directed at Taiwan on TikTok. Web investigation amounts to just one report, an explanatory piece on Chinese-linked fake news site networks by the Sasakawa Peace Foundation's International Information Network Analysis (IINA).
The five SNS investigations by Japanese institutions average 2.70 for threat level and 2.60 for attribution, below both the 373 by Western institutions (3.46 and 2.96) and the nine by South Korean and Taiwanese institutions (3.94 and 2.94). Given a base of five reports, one should be cautious about arguing from the standard itself; what can be confirmed here is less the difference in means than the small number of empirical investigations. Against 71 web network investigations accumulated by Western institutions, Japanese institutions have produced one.
The implication is plain. Because comprehensive investigation including web network investigation does not exist, Japan cannot map for itself the overall picture of influence operations targeting it. Each time an individual case draws attention, only that case is observed. How large a network is operated in Japanese overall, who runs it and where the money comes from cannot be learned from domestic investigation. The result is continued dependence on the reports of Western investigative institutions, while areas outside Western interest, such as fake site networks specific to the Japanese-language sphere, remain blank. Priorities for response cannot be set for objects that have not been mapped.
The direction to take is suggested by the South Korean and Taiwanese case. Where empirical investigation is carried out, the standard of description can match that of Western institutions, which is precisely what those nine SNS investigations demonstrated. What is lacking is not capability but the mix of investigation types and the number of empirical investigations. For Japan too, the first step is to increase the absolute number of investigations involving empirical work and to build web network investigation into them. Continuous monitoring is the easiest place to start, beginning with the continuous recording of registration records and site-building system fingerprints for suspicious groups of sites operating in Japanese; the accumulation of records is itself the basis for later identifying networks. At the same time, the weakness shown by the publications of South Korean government-affiliated institutions, which stopped at listing sites without empirically establishing the operating body and the funding source, must not be repeated.
6. Conclusion
The evaluation data for 827 reports show the following. Investigations whose principal object is websites and the networks they form set the highest standard in describing the threat level, stand almost level with the composite type in inferring the threatening actor, and hold the largest share of reports in which attribution catches up with the threat description. The institutions conducting this work have been confined almost entirely to a small number of Western organizations, but the conditions of entry are changing with the use of AI, and expansion can be expected. Expanding web network investigation of influence operations can be a realistic means of filling the weakness in attribution that this field has long carried.
Two reservations apply. The first is that this result is a correlation, not proof of causation; the confounders of institutional bias and the nature of the object of investigation have not been removed. The second is that method alone is not enough: as the publication on fake site takedowns by South Korean government-affiliated institutions showed, conducting web investigation without accompanying norms and practice for empirically establishing and describing the operating body and the funding source can widen the gap instead. It is also necessary to remain aware that the traps generated by dependence on tools, case-by-case work and the loss of the overall picture, persist when the object shifts to the web.
For Japan the recommendations are clear. First, increase the absolute number of investigations involving empirical work. Second, build web network investigation of influence operations into them. Third, begin with the continuous monitoring that is easiest to start, and accumulate records. A country unable to draw for itself the overall picture of the influence operations targeting it lacks the precondition for response. As long as the search continues under the streetlight, the key will not be found.







