Please use this identifier to cite or link to this item: http://hdl.handle.net/11189/10164
DC FieldValueLanguage
dc.contributor.authorBokolo, Zilungileen_US
dc.contributor.authorDaramola, Olawandeen_US
dc.date.accessioned2025-10-14T07:52:16Z-
dc.date.available2025-10-14T07:52:16Z-
dc.date.issued2024-
dc.identifier.citationBokolo, Z. & Daramola, O. 2024. Elicitation of security threats and vulnerabilities in Insurance chatbots using STRIDE. Scientific Reports, 14: 1-25. [https://doi.org/10.1038/s41598-024-68791-z]en_US
dc.identifier.issn2045-2322 (Online)-
dc.identifier.urihttp://hdl.handle.net/11189/10164-
dc.description.abstractAlthough chatbots are used a lot for customer relationship management (CRM), there needs to be more data security and privacy control strategies in chatbots, which has become a security concern for financial services institutions. Chatbots gain access to large amounts of vital company information and clients’ personal information, which makes them a target of security attacks. The loss of data stored in chatbots can cause major harm to companies and customers. In this study, STRIDE (viz. Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, Elevation of privilege) modelling was applied to identify the data security vulnerabilities and threats that pertain to chatbots used in the insurance industry. To do this, we conducted a case study of a South African insurance organisation. The adopted methodology involved data collection from stakeholders in the insurance organisation to identify chatbot use cases and understand chatbot operations. After that, we conducted a STRIDE-based analysis of the chatbot use cases to elicit security threats and vulnerabilities in the insurance chatbots in the organisation. The results reveal that security vulnerabilities associated with Spoofing, Denial of Service, and Elevation of privilege are more relevant to insurance chatbots. The most security threats stem from Tampering, Elevation of privilege, and Spoofing. The study extends the discussion on chatbot security. It fosters an understanding of security threats and vulnerabilities that pertain to insurance chatbots, which is beneficial for security researchers and practitioners working on the security of chatbots and the insurance industry.en_US
dc.language.isoenen_US
dc.publisherNature Portfolioen_US
dc.relation.ispartofScientific Reportsen_US
dc.subjectData securityen_US
dc.subjectChatbotsen_US
dc.subjectChatbot securityen_US
dc.subjectSTRIDEen_US
dc.subjectThreat modellingen_US
dc.subjectInsuranceen_US
dc.subjectCustomer relationship managementen_US
dc.subjectArtificial Intelligenceen_US
dc.titleElicitation of security threats and vulnerabilities in Insurance chatbots using STRIDEen_US
dc.identifier.doihttps://doi.org/10.1038/s41598-024-68791-z-
dc.typeArticleen_US
Appears in Collections:FID - Journal Articles (DHET subsidised)
Files in This Item:
File Description SizeFormat 
Elicitation_of_security_threats.pdf4.51 MBAdobe PDFView/Open
Show simple item record

Page view(s)

102
Last Week
4
Last month
11
checked on Aug 13, 2026

Download(s)

72
checked on Aug 13, 2026

Google ScholarTM

Check

Altmetric


Items in Digital Knowledge are protected by copyright, with all rights reserved, unless otherwise indicated.