Security Ontology OntoSecRPA for Robotic Process Automation Domain

被引:1
|
作者
Kurylets, Anastasiya [1 ]
Goranin, Nikolaj [1 ]
机构
[1] Vilnius Gediminas Tech Univ, Fac Fundamental Sci, Dept Informat Syst, Sauletekio Al 11, LT-10223 Vilnius, Lithuania
来源
APPLIED SCIENCES-BASEL | 2023年 / 13卷 / 09期
关键词
security ontology; risk management; RPA; cybersecurity;
D O I
10.3390/app13095568
中图分类号
O6 [化学];
学科分类号
0703 ;
摘要
Robotic process automation (RPA)* based on the use of software robots has proven to be one of the most demanded technologies to emerge in recent years used for automating daily IT routines in many sectors, such as banking and finance. As with any new technology, RPA has a number of potential cyber security weaknesses, caused either by fundamental logical mistakes in the approach or by cyber-human mistakes made during the implementation, configuration, and operation phases. It is important to have an extensive understanding of the related risks before RPA integration into enterprise IT infrastructure. The main asset operated by RPA is confidential enterprise data. Data leakage and theft are the two main threats. The wide application of RPA technology in information security-sensitive sectors makes the protection of RPA against cyber-attacks an important task. Still, this topic is not yet adequately investigated in the scientific press and existing articles mainly concentrate on stating the RPA security importance and describing some threats. In this article, we present a flexible tool, security-oriented ontology OntoSecRPA*, which systematically describes RPA-specific assets, risks, security, threats, vulnerabilities, and countermeasures. To the best of our knowledge, there are currently no ontologies available that are specific to the RPA domain, and existing security ontologies lack RPA-related features. In the future, the proposed ontology can be updated and used in different ways, for example, as a checklist for risk management tasks in RPA solutions and a source of information for an expert system or a concentrated domain-specific source of information, which indicates its wide practical application. The proposed ontology was formally verified by applying ontology completeness assessment and used for risk assessment in a sample scenario.
引用
收藏
页数:23
相关论文
共 50 条
  • [1] Ontology-Supported Modeling of Bots in Robotic Process Automation
    Voelker, Maximilian
    Weske, Mathias
    [J]. CONCEPTUAL MODELING (ER 2022), 2022, 13607 : 239 - 254
  • [2] Robotic Process Automation
    Scheppler B.
    Weber C.
    [J]. Informatik-Spektrum, 2020, 43 (02): : 152 - 156
  • [3] Robotic Process Automation
    van der Aalst, Wil M. P.
    Bichler, Martin
    Heinzl, Armin
    [J]. BUSINESS & INFORMATION SYSTEMS ENGINEERING, 2018, 60 (04): : 269 - 272
  • [4] Robotic process automation
    Hofmann, Peter
    Samp, Caroline
    Urbach, Nils
    [J]. ELECTRONIC MARKETS, 2020, 30 (01) : 99 - 106
  • [5] Robotic Process Automation
    Wil M. P. van der Aalst
    Martin Bichler
    Armin Heinzl
    [J]. Business & Information Systems Engineering, 2018, 60 : 269 - 272
  • [6] Robotic process automation
    Peter Hofmann
    Caroline Samp
    Nils Urbach
    [J]. Electronic Markets, 2020, 30 : 99 - 106
  • [7] Robotic Process Automation in Cyber Security Operations: Optimizing Workflows with AI-Driven Automation
    Dhabliya, Dharmesh
    Ghule, Gauri
    Khubalkar, Deepti
    Moje, Ravindra K.
    Kshirsagar, Pranali S.
    Bendale, Shailesh P.
    [J]. JOURNAL OF ELECTRICAL SYSTEMS, 2023, 19 (03) : 96 - 105
  • [8] On ontology mapping in factory automation domain
    Popescu, Corina
    Lastra, Jose L. Martinez
    [J]. ETFA 2007: 12TH IEEE INTERNATIONAL CONFERENCE ON EMERGING TECHNOLOGIES AND FACTORY AUTOMATION, VOLS 1-3, 2007, : 288 - 292
  • [9] Robotic Process Automation for Auditing
    Moffitt, Kevin C.
    Rozario, Andrea M.
    Vasarhelyi, Miklos A.
    [J]. JOURNAL OF EMERGING TECHNOLOGIES IN ACCOUNTING, 2018, 15 (01) : 1 - 10
  • [10] Robotic Process Automation (RPA)
    Kobayasi, Yosiyuki
    [J]. Kyokai Joho Imeji Zasshi/Journal of the Institute of Image Information and Television Engineers, 2019, 73 (02): : 335 - 337