Security Ontology OntoSecRPA for Robotic Process Automation Domain

Robotic process automation (RPA)* based on the use of software robots has proven to be one of the most demanded technologies to emerge in recent years used for automating daily IT routines in many sectors, such as banking and finance. As with any new technology, RPA has a number of potential cyber s...

Full description

Bibliographic Details
Main Authors: Anastasiya Kurylets, Nikolaj Goranin
Format: Article
Language:English
Published: MDPI AG 2023-04-01
Series:Applied Sciences
Subjects:
Online Access:https://www.mdpi.com/2076-3417/13/9/5568
_version_ 1797602972724625408
author Anastasiya Kurylets
Nikolaj Goranin
author_facet Anastasiya Kurylets
Nikolaj Goranin
author_sort Anastasiya Kurylets
collection DOAJ
description Robotic process automation (RPA)* based on the use of software robots has proven to be one of the most demanded technologies to emerge in recent years used for automating daily IT routines in many sectors, such as banking and finance. As with any new technology, RPA has a number of potential cyber security weaknesses, caused either by fundamental logical mistakes in the approach or by cyber-human mistakes made during the implementation, configuration, and operation phases. It is important to have an extensive understanding of the related risks before RPA integration into enterprise IT infrastructure. The main asset operated by RPA is confidential enterprise data. Data leakage and theft are the two main threats. The wide application of RPA technology in information security-sensitive sectors makes the protection of RPA against cyber-attacks an important task. Still, this topic is not yet adequately investigated in the scientific press and existing articles mainly concentrate on stating the RPA security importance and describing some threats. In this article, we present a flexible tool, security-oriented ontology OntoSecRPA*, which systematically describes RPA-specific assets, risks, security, threats, vulnerabilities, and countermeasures. To the best of our knowledge, there are currently no ontologies available that are specific to the RPA domain, and existing security ontologies lack RPA-related features. In the future, the proposed ontology can be updated and used in different ways, for example, as a checklist for risk management tasks in RPA solutions and a source of information for an expert system or a concentrated domain-specific source of information, which indicates its wide practical application. The proposed ontology was formally verified by applying ontology completeness assessment and used for risk assessment in a sample scenario.
first_indexed 2024-03-11T04:24:15Z
format Article
id doaj.art-6d17618b725e4468b88786fc83671079
institution Directory Open Access Journal
issn 2076-3417
language English
last_indexed 2024-03-11T04:24:15Z
publishDate 2023-04-01
publisher MDPI AG
record_format Article
series Applied Sciences
spelling doaj.art-6d17618b725e4468b88786fc836710792023-11-17T22:35:48ZengMDPI AGApplied Sciences2076-34172023-04-01139556810.3390/app13095568Security Ontology OntoSecRPA for Robotic Process Automation DomainAnastasiya Kurylets0Nikolaj Goranin1Faculty of Fundamental Sciences, Department of Information Systems, Vilnius Gediminas Technical University, Sauletekio al. 11, 10223 Vilnius, LithuaniaFaculty of Fundamental Sciences, Department of Information Systems, Vilnius Gediminas Technical University, Sauletekio al. 11, 10223 Vilnius, LithuaniaRobotic process automation (RPA)* based on the use of software robots has proven to be one of the most demanded technologies to emerge in recent years used for automating daily IT routines in many sectors, such as banking and finance. As with any new technology, RPA has a number of potential cyber security weaknesses, caused either by fundamental logical mistakes in the approach or by cyber-human mistakes made during the implementation, configuration, and operation phases. It is important to have an extensive understanding of the related risks before RPA integration into enterprise IT infrastructure. The main asset operated by RPA is confidential enterprise data. Data leakage and theft are the two main threats. The wide application of RPA technology in information security-sensitive sectors makes the protection of RPA against cyber-attacks an important task. Still, this topic is not yet adequately investigated in the scientific press and existing articles mainly concentrate on stating the RPA security importance and describing some threats. In this article, we present a flexible tool, security-oriented ontology OntoSecRPA*, which systematically describes RPA-specific assets, risks, security, threats, vulnerabilities, and countermeasures. To the best of our knowledge, there are currently no ontologies available that are specific to the RPA domain, and existing security ontologies lack RPA-related features. In the future, the proposed ontology can be updated and used in different ways, for example, as a checklist for risk management tasks in RPA solutions and a source of information for an expert system or a concentrated domain-specific source of information, which indicates its wide practical application. The proposed ontology was formally verified by applying ontology completeness assessment and used for risk assessment in a sample scenario.https://www.mdpi.com/2076-3417/13/9/5568security ontologyrisk managementRPAcybersecurity
spellingShingle Anastasiya Kurylets
Nikolaj Goranin
Security Ontology OntoSecRPA for Robotic Process Automation Domain
Applied Sciences
security ontology
risk management
RPA
cybersecurity
title Security Ontology OntoSecRPA for Robotic Process Automation Domain
title_full Security Ontology OntoSecRPA for Robotic Process Automation Domain
title_fullStr Security Ontology OntoSecRPA for Robotic Process Automation Domain
title_full_unstemmed Security Ontology OntoSecRPA for Robotic Process Automation Domain
title_short Security Ontology OntoSecRPA for Robotic Process Automation Domain
title_sort security ontology ontosecrpa for robotic process automation domain
topic security ontology
risk management
RPA
cybersecurity
url https://www.mdpi.com/2076-3417/13/9/5568
work_keys_str_mv AT anastasiyakurylets securityontologyontosecrpaforroboticprocessautomationdomain
AT nikolajgoranin securityontologyontosecrpaforroboticprocessautomationdomain