
@Article{cmes.2026.085454,
AUTHOR = {Chia-Nan Wang, Tsei-Hsuan Chen, Syuan-Yun Wang, Chung-Nan Cheng},
TITLE = {Intelligent Risk Prioritization for Phishing Mitigation: A Human-Factor-Aware Framework for Healthcare SOCs},
JOURNAL = {Computer Modeling in Engineering \& Sciences},
VOLUME = {},
YEAR = {},
NUMBER = {},
PAGES = {{pages}},
URL = {http://www.techscience.com/CMES/online/detail/28107},
ISSN = {1526-1506},
ABSTRACT = {In email-centric healthcare environments, social engineering attacks increasingly exploit human psychology, organizational trust relationships, and persuasive communication strategies to bypass conventional cybersecurity defenses. While existing email security controls are effective at blocking many malicious messages, they remain vulnerable to whitelist-failure scenarios in which compromised or seemingly legitimate communications evade detection and reach end users. Under limited analyst capacity and increasing alert volumes, the operational challenge is no longer solely identifying phishing emails but determining which socially engineered communications should be reviewed first. To address this problem, this study proposes a governance-oriented human-factor risk prioritization framework that operates as a post-detection decision-support layer rather than a traditional phishing-filtering mechanism. The proposed P×F framework integrates persuasion tactics (P) and persona-based message-framing factors (F) to model social engineering influence patterns and transform psychological manipulation cues into interpretable risk representations for Top-K (top-ranked K alerts) alert prioritization. Using Bayesian smoothing and Logistic Regression, the framework converts semantic indicators into auditable risk scores that support analyst attention allocation under constrained Security Operations Center (SOC) resources. The framework was evaluated using Enron and Nazario email corpora, Large Language Model (LLM)-generated phishing scenarios, and a real-world Hospital A proof-of-concept dataset. Experimental results achieved mean Receiver Operating Characteristic Area Under the Curve (ROC-AUC) values of 0.9829 under subject-only conditions and 0.9871 using full-text content, while maintaining robust performance under distribution shift with performance degradation below 0.06 AUC. In operational evaluation, the Top-100 prioritization mechanism achieved 0.95 precision across 10,463 real SOC emails. Compared with Bidirectional Encoder Representations from Transformers (BERT), which exhibited recall collapse (0.03) under limited-context conditions, the proposed framework demonstrated greater stability, interpretability, and operational suitability for alert triage. Unlike conventional phishing detection approaches that primarily emphasize content classification, the proposed framework models psychological manipulation mechanisms derived from persuasion theory and human-factor literature. It operationalizes these mechanisms as interpretable P×F human-factor indicators and validates the resulting governance-oriented risk prioritization framework using real hospital phishing emails.},
DOI = {10.32604/cmes.2026.085454}
}



