Endre søk
Link to record
Permanent link

Direct link
Publikasjoner (10 av 14) Visa alla publikasjoner
Xiong, W., Legrand, E., Åberg, O. & Lagerström, R. (2022). Cyber security threat modeling based on the MITRE Enterprise ATT&CK Matrix. Software and Systems Modeling, 21(1), 157-177
Åpne denne publikasjonen i ny fane eller vindu >>Cyber security threat modeling based on the MITRE Enterprise ATT&CK Matrix
2022 (engelsk)Inngår i: Software and Systems Modeling, ISSN 1619-1366, E-ISSN 1619-1374, Vol. 21, nr 1, s. 157-177Artikkel i tidsskrift (Fagfellevurdert) Published
Abstract [en]

Enterprise systems are growing in complexity, and the adoption of cloud and mobile services has greatly increased the attack surface. To proactively address these security issues in enterprise systems, this paper proposes a threat modeling language for enterprise security based on the MITRE Enterprise ATT&CK Matrix. It is designed using the Meta Attack Language framework and focuses on describing system assets, attack steps, defenses, and asset associations. The attack steps in the language represent adversary techniques as listed and described by MITRE. This entity-relationship model describes enterprise IT systems as a whole; by using available tools, the proposed language enables attack simulations on its system model instances. These simulations can be used to investigate security settings and architectural changes that might be implemented to secure the system more effectively. Our proposed language is tested with a number of unit and integration tests. This is visualized in the paper with two real cyber attacks modeled and simulated.

sted, utgiver, år, opplag, sider
Springer, 2022
HSV kategori
Forskningsprogram
Datalogi
Identifikatorer
urn:nbn:se:kth:diva-297591 (URN)10.1007/s10270-021-00898-7 (DOI)000663233900001 ()2-s2.0-85108228568 (Scopus ID)
Forskningsfinansiär
VinnovaSwedish Energy Agency
Merknad

QC 20210621

Tilgjengelig fra: 2021-06-18 Laget: 2021-06-18 Sist oppdatert: 2024-01-17bibliografisk kontrollert
Hacks, S., Katsikeas, S., Rencelj Ling, E., Xiong, W., Pfeiffer, J. & Wortmann, A. (2022). Towards a Systematic Method for Developing Meta Attack Language Instances. In: Enterprise, Business-Process and Information Systems Modeling 23rd International Conference, BPMDS 2022 and 27th International Conference, EMMSAD 2022, Held at CAiSE 2022, Leuven, Belgium, June 6–7, 2022, Proceedings: . Paper presented at 34th International Conference on Advanced Information Systems Engineering CAiSE 2022, Leuven, Belgium, June 6–7, 2022 (pp. 139-154). Springer Nature, 450
Åpne denne publikasjonen i ny fane eller vindu >>Towards a Systematic Method for Developing Meta Attack Language Instances
Vise andre…
2022 (engelsk)Inngår i: Enterprise, Business-Process and Information Systems Modeling 23rd International Conference, BPMDS 2022 and 27th International Conference, EMMSAD 2022, Held at CAiSE 2022, Leuven, Belgium, June 6–7, 2022, Proceedings, Springer Nature , 2022, Vol. 450, s. 139-154Konferansepaper, Publicerat paper (Fagfellevurdert)
Abstract [en]

Successfully developing domain-specific languages (DSLs) demands language engineers to consider their organizational context, which is challenging. Action design research (ADR) provides a conceptual framework to address this challenge. Since ADR’s application to the engineering of DSLs has not yet been examined, we investigate applying it to the development of threat modeling DSLs based on the Meta Attack Language (MAL), a metamodeling language for the specification of domain-specific threat modeling languages. To this end, we conducted a survey with experienced MAL developers on their development activities. We extract guidelines and align these, together with established DSL design guidelines, to the conceptual model of ADR. The research presented, aims to be the first step to investigate whether ADR can be used to systematically engineer DSLs.

sted, utgiver, år, opplag, sider
Springer Nature, 2022
Serie
Lecture Notes in Business Information Processing, ISSN 1865-1348 ; 450
Emneord
Action design research (ADR), Domain specific language (DSL), Language engineering, Digital subscriber lines, Modeling languages, Action design research, Conceptual frameworks, Design research, Domain specific language, Domains specific languages, Metamodeling, Organizational context, Systematic method, Threat modeling, Problem oriented languages
HSV kategori
Identifikatorer
urn:nbn:se:kth:diva-315994 (URN)10.1007/978-3-031-07475-2_10 (DOI)000894110300010 ()2-s2.0-85131307190 (Scopus ID)
Konferanse
34th International Conference on Advanced Information Systems Engineering CAiSE 2022, Leuven, Belgium, June 6–7, 2022
Merknad

QC 20230130

Tilgjengelig fra: 2022-08-05 Laget: 2022-08-05 Sist oppdatert: 2025-02-07bibliografisk kontrollert
Xiong, W., Hacks, S. & Lagerström, R. (2021). A Method for Assigning Probability Distributions in Attack Simulation Languages. Complex Systems Informatics and Modeling Quarterly (26), 55-77, Article ID 151.
Åpne denne publikasjonen i ny fane eller vindu >>A Method for Assigning Probability Distributions in Attack Simulation Languages
2021 (engelsk)Inngår i: Complex Systems Informatics and Modeling Quarterly, E-ISSN 2255-9922, nr 26, s. 55-77, artikkel-id 151Artikkel i tidsskrift (Fagfellevurdert) Published
Abstract [en]

Cyber attacks on IT and OT systems can have severe consequences for individuals and organizations, from water or energy distribution systems to online banking services. To respond to these threats, attack simulations can be used to assess the cyber security of systems to foster a higher degree of resilience against cyber attacks; the steps taken by an attacker to compromise sensitive system assets can be traced, and a time estimate can be computed from the initial step to the compromise of assets of interest.

Previously, the Meta Attack Language (MAL) was introduced as a framework to develop security-oriented domain-specific languages. It allows attack simulations on modeled systems and analyzes weaknesses related to known attacks. To produce more realistic simulation results, probability distributions can be assigned to attack steps and defenses to describe the efforts required for attackers to exploit certain attack steps. However, research on assessing such probability distributions is scarce, and we often rely on security experts to model attackers’ efforts. To address this gap, we propose a method to assign probability distributions to the attack steps and defenses of MAL-based languages. We demonstrate the proposed method by assigning probability distributions to a MAL-based language. Finally, the resulting language is evaluated by modeling and simulating a known cyber attack.

sted, utgiver, år, opplag, sider
Riga Technical University, 2021
Emneord
Attack Simulations; Threat Modeling; Domain-Specific Language; Cyber Security; Information Collection
HSV kategori
Forskningsprogram
Elektro- och systemteknik
Identifikatorer
urn:nbn:se:kth:diva-293920 (URN)10.7250/csimq.2021-26.04 (DOI)2-s2.0-85108209334 (Scopus ID)
Forskningsfinansiär
StandUpVinnova
Merknad

QC 20210527

Tilgjengelig fra: 2021-05-05 Laget: 2021-05-05 Sist oppdatert: 2025-05-08bibliografisk kontrollert
Xiong, W., Hacks, S. & Lagerström, R. (2021). A Method for Quality Assessment of Threat Modeling Languages: The Case of enterpriseLang. In: : . Paper presented at PoEM’21 Forum: 14th IFIP WG 8.1 Working Conference on the Practice of Enterprise Modelling (pp. 49-58). Riga, Latvia, 3045
Åpne denne publikasjonen i ny fane eller vindu >>A Method for Quality Assessment of Threat Modeling Languages: The Case of enterpriseLang
2021 (engelsk)Konferansepaper, Publicerat paper (Fagfellevurdert)
Abstract [en]

Enterprise systems are growing in complexity, and the adoption of cloud and mobile services has greatly increased the attack surface. To proactively address these security issues in enterprise systems, a threat modeling language for enterprise systems called enterpriseLang was proposed. It is a domain-specific language (DSL) designed using the Meta Attack Language (MAL) framework and focuses on describing system assets, attack steps, defenses, and asset associations. The threat models can serve as input for attack simulations to analyze the behavior of attackers within the system. However, whether and to what extent the functionality of these threat modeling languages is achieved has not been addressed. To ensure the correct functionality of threat modeling languages, this paper proposes a method to assess the quality of such languages and illustrates its application using enterpriseLang.

sted, utgiver, år, opplag, sider
Riga, Latvia: , 2021
Emneord
Threat modeling, Attack simulations, Domain-specific language, Design guidelines, Test coverage
HSV kategori
Forskningsprogram
Elektro- och systemteknik
Identifikatorer
urn:nbn:se:kth:diva-299982 (URN)
Konferanse
PoEM’21 Forum: 14th IFIP WG 8.1 Working Conference on the Practice of Enterprise Modelling
Merknad

QC 20210823

Tilgjengelig fra: 2021-08-20 Laget: 2021-08-20 Sist oppdatert: 2022-12-20bibliografisk kontrollert
Xiong, W., Hacks, S. & Lagerström, R. (2021). A Method for Quality Assessment of Threat Modeling Languages: The Case of enterpriseLang. In: CEUR Workshop Proceedings: . Paper presented at 14th IFIP WG 8.1 Working Conference on the Practice of Enterprise Modeling, PoEM-Forum 2021, 24 November 2021 through 26 November 2021 (pp. 49-58). CEUR-WS
Åpne denne publikasjonen i ny fane eller vindu >>A Method for Quality Assessment of Threat Modeling Languages: The Case of enterpriseLang
2021 (engelsk)Inngår i: CEUR Workshop Proceedings, CEUR-WS , 2021, s. 49-58Konferansepaper, Publicerat paper (Fagfellevurdert)
Abstract [en]

Enterprise systems are growing in complexity, and the adoption of cloud and mobile services has greatly increased the attack surface. To proactively address these security issues in enterprise systems, a threat modeling language for enterprise systems called enterpriseLang was proposed. It is a domain-specific language (DSL) designed using the Meta Attack Language (MAL) framework and focuses on describing system assets, attack steps, defenses, and asset associations. The threat models can serve as input for attack simulations to analyze the behavior of attackers within the system. However, whether and to what extent the functionality of these threat modeling languages is achieved has not been addressed. To ensure the correct functionality of threat modeling languages, this paper proposes a method to assess the quality of such languages and illustrates its application using enterpriseLang.

sted, utgiver, år, opplag, sider
CEUR-WS, 2021
Emneord
Attack simulations, Design guidelines, Domain-specific language, Test coverage, Threat modeling, Modeling languages, Attack simulation, Cloud services, Design guideline, Enterprise system, ITS applications, Mobile service, Quality assessment, Security issues, Test-coverage, Problem oriented languages
HSV kategori
Identifikatorer
urn:nbn:se:kth:diva-316065 (URN)2-s2.0-85121720425 (Scopus ID)
Konferanse
14th IFIP WG 8.1 Working Conference on the Practice of Enterprise Modeling, PoEM-Forum 2021, 24 November 2021 through 26 November 2021
Merknad

QC 20220905

Tilgjengelig fra: 2022-09-05 Laget: 2022-09-05 Sist oppdatert: 2022-12-20bibliografisk kontrollert
Xiong, W. (2021). Enhancing IT Systems Cyber Resilience through Threat Modeling: Cyber Security Analysis of Enterprise Systems and Connected Vehicles. (Doctoral dissertation). Stockholm: KTH Royal Institute of Technology
Åpne denne publikasjonen i ny fane eller vindu >>Enhancing IT Systems Cyber Resilience through Threat Modeling: Cyber Security Analysis of Enterprise Systems and Connected Vehicles
2021 (engelsk)Doktoravhandling, med artikler (Annet vitenskapelig)
Abstract [en]

Information technology (IT) systems are growing in complexity and are becoming more and more connected. Such connected systems can increase flexibility and productivity while also introducing security threats. Recent years have witnessed some of the largest, most sophisticated, and most severe cyber attacks on IT systems, which can have severe consequences for individuals and organizations, from water or energy distribution systems to online banking services. Therefore, security is a top priority for IT systems.

To address these security issues proactively, threat modeling can be utilized as follows: to assess the current state of a system, and as a security-by-design tool for developing new systems. Threat models can serve as input for attack simulations, which are used for analyzing the behavior of attackers within the system. The simulation results obtained can help stakeholders to investigate in security settings that can be applied to secure their system more effectively.

This thesis presents work on threat modeling for IT systems. The contributions to the field of threat modeling include a systematic literature review on threat modeling (Paper A). With regard to securing enterprise systems, the contributions include a threat modeling language for security assessment of enterprise systems (Paper B), a method for assigning probability distributions in attack simulation languages to provide more realistic simulation results (Paper C), and a method for quality assessment of threat modeling languages (Paper D). With regard to securing connected vehicles, the contributions include a proof-of-concept of an approach for securing connected vehicles using threat modeling coupled with attack simulations (Paper E), and an empirical study to explore common security vulnerabilities and software weaknesses in vehicles (Paper F).

Abstract [sv]

IT-system växer i komplexitet och blir mer och mer ihopkopplade. Att koppla samman system kan öka flexibiliteten och produktiviteten, samtidigt som det också kan medföra säkerhetsluckor. De senaste åren har vi bevittnat några av de största, mest sofistikerade och allvarligaste cyberattackerna på IT-system. Vilket kan få allvarliga konsekvenser för individer och organisationer, från vatten- och energidistributionssystem till banktjänster. Därför är säkerhet högsta prioritet i IT-system.

För att proaktivt ta itu med dessa säkerhetsfrågor kan hotmodellering användas för att bedöma ett systems nuvarande tillstånd och som ett verktyg för att designa säkra system. Hotmodeller kan även fungera som indata till attacksimuleringar. Dessa används för att analysera angriparnas beteende inom systemet, och simuleringsresultaten kan hjälpa intressenter att undersöka säkerhetsinställningar som kan implementeras för att säkra ett system mer effektivt.

Denna avhandling presenterar arbete med hotmodellering för IT-system. När det gäller hotmodellering generellt inkluderar bidragen en systematisk litteraturöversikt om hotmodellering (Artikel A), en metod för tilldelning av sannolikhetsfördelningar i attacksimuleringsspråk för att ge mer realistiska simuleringsresultat (Artikel C), och en metod för kvalitetsbedömning av hotmodelleringsspråk (Artikel D). När det gäller mer domänspecifika resultat inkluderar bidragen ett hotmodelleringsspråk för säkerhetsbedömning av företagsövergripandesystem (Artikel B), ett koncept-test av ett tillvägagångssätt som använder hotmodellering i kombination med attacksimuleringar för uppkoppladefordon  (Artikel E) och en empirisk studie för att utforska kända sårbarheter och svagheter i programvara för fordon (Artikel F).

sted, utgiver, år, opplag, sider
Stockholm: KTH Royal Institute of Technology, 2021. s. 47
Serie
TRITA-EECS-AVL ; 2021:51
Emneord
Cyber Security, Threat Modeling, Attack Simulations, IT Systems, Security Analysis
HSV kategori
Forskningsprogram
Elektro- och systemteknik
Identifikatorer
urn:nbn:se:kth:diva-300046 (URN)978-91-7873-940-0 (ISBN)
Disputas
2021-09-17, https://kth-se.zoom.us/j/65069300996, F3, Lindstedtsvägen 26, KTH Campus, Stockholm, 09:00 (engelsk)
Opponent
Veileder
Merknad

QC 20210823

Tilgjengelig fra: 2021-08-23 Laget: 2021-08-23 Sist oppdatert: 2022-12-20bibliografisk kontrollert
Xiong, W. & Hacks, S. (2020). Threat Modeling and Attack Simulations for Enterprise and ICS. In: : . Paper presented at CS3STHLM Stockholm 19-22 October 2020,.
Åpne denne publikasjonen i ny fane eller vindu >>Threat Modeling and Attack Simulations for Enterprise and ICS
2020 (engelsk)Konferansepaper, Oral presentation with published abstract (Annet (populærvitenskap, debatt, mm))
Abstract [en]

This work concentrates on the cyber security of enterprise and Industrial Control Systems (ICS).

Enterprise systems are growing in complexity, and the adoption of cloud and mobile services has greatly increased attack surfaces. This all has led to fragmentation on the security front. To improve the security of enterprise systems, threat modeling can be applied to proactively deal with security issues from a holistic point of view, and can also be combined with attack simulations to provide quantitative security measurements, which has not been commonly used while shown efficient in some disciplines.

Hitherto, we have proposed the use of attack simulations based on system architecture models. Our approaches facilitate a model of the system and simulate cyber-attacks in order to identify the greatest weaknesses. This can be imagined as the execution of a great number of parallel virtual penetration tests. Such an attack simulation tool enables the security assessor to focus on the collection of the information about the system required for the simulations.

As the previous approaches rely on a static implementation, we propose the use of MAL (the Meta Attack Language). This framework for domain-specific languages (DSLs) defines which information about a system is required and specifies the generic attack logic. Since MAL is a meta language (i.e. the set of rules that should be used to create a new DSL), no particular domain of interest is represented, but it can be used to create languages targeting certain domains

This work introduces enterpriseLang - a threat modeling language for enterprise security based on the MITRE ATT&CK Matrix, which can assess the cyber security of enterprise systems from a holistic point of view. This compilable language can automatically visualize possible attack paths an adversary may choose, show the most vulnerable asset, and provide possible mitigations for each attack step intended to counter cyber-attacks. The attack steps representing adversary techniques are captured within the ATT&CK Matrix based on real-world observations. These adversary techniques are categorized by tactics, and are organized with security metrics e.g. platform, permissions required, and mitigations that provide information for threat modeling. The proposed threat modeling language is tested through modeling real-world attack scenarios, thus can be used to forecast attacks on enterprise systems. The language can also be re-used by people with less security expertise to automatically assess the security of their specific-enterprise systems.

This core IT related threat modeling language is complemented by our IcsLang that allows to create and simulate OT specific environments. Similarly to enterpriseLang, this language is based on the ICS MITRE ATT&CK Matrix and enriched by real-world observations collected from industry partners in an EU project (EnergyShield). Based on the characteristics of MAL, we will motivate why certain types of attacks are included in our artifact and others not. Mainly, this is based on assumptions, made in the design of MAL and creating a trade-off between level of detail and usability.

To demonstrate the applicability and the integration between the two languages, we present energy domain architecture and simulate well known attacks like the Ukrainian scenario.

HSV kategori
Identifikatorer
urn:nbn:se:kth:diva-284445 (URN)
Konferanse
CS3STHLM Stockholm 19-22 October 2020,
Merknad

QC 20201026

Tilgjengelig fra: 2020-10-22 Laget: 2020-10-22 Sist oppdatert: 2022-12-20bibliografisk kontrollert
Lagerström, R., Xiong, W. & Ekstedt, M. (2020). Threat modeling and attack simulations of smart cities: A literature review and explorative study. In: ICISSP 2020 - Proceedings of the 6th International Conference on Information Systems Security and Privacy: . Paper presented at 6th International Conference on Information Systems Security and Privacy, ICISSP 2020, 25-27 February 2020 (pp. 369-376). SciTePress
Åpne denne publikasjonen i ny fane eller vindu >>Threat modeling and attack simulations of smart cities: A literature review and explorative study
2020 (engelsk)Inngår i: ICISSP 2020 - Proceedings of the 6th International Conference on Information Systems Security and Privacy, SciTePress , 2020, s. 369-376Konferansepaper, Publicerat paper (Fagfellevurdert)
Abstract [en]

Digitization has made enterprises and inter-enterprise organizations (e.g. smart cities) increasingly vulnerable to cyber attacks. Malicious actors compromising computers can have potential damage and disruptions. To mitigate cyber threats, the first thing is to identify vulnerabilities, which is difficult as it requires (i) a detailed understanding of the inter-enterprise architecture, and (ii) significant security expertise. Threat modeling supports (i) by documenting the design of the system architecture, and attack simulation supports (ii) by automating the identification of vulnerabilities. This paper presents a systematic literature review and provides a research outlook for threat modeling and attack simulations of smart cities. The results show that little research has been done in this area, and promising approaches are being developed. 

sted, utgiver, år, opplag, sider
SciTePress, 2020
Emneord
Attack graph, Cloud, Internet-of-Things, Smart city, Systematic literature review, Threat modeling, Information systems, Information use, Network security, Cyber threats, Cyber-attacks, Inter-Enterprise, Literature reviews, System architectures
HSV kategori
Identifikatorer
urn:nbn:se:kth:diva-274237 (URN)10.5220/0008921903690376 (DOI)000570766300037 ()2-s2.0-85083033763 (Scopus ID)
Konferanse
6th International Conference on Information Systems Security and Privacy, ICISSP 2020, 25-27 February 2020
Merknad

Duplicate in Scopus 2-s2.0-85176332029

QC 20200713

Tilgjengelig fra: 2020-07-13 Laget: 2020-07-13 Sist oppdatert: 2023-11-23bibliografisk kontrollert
Xiong, W., Güsever, M., Kaya, K. M. & Lagerström, R. (2019). A Study of Security Vulnerabilities and Software Weaknesses in Vehicles. In: Nordic Conference on Secure IT Systems: . Paper presented at 24th Nordic Conference on Secure IT Systems, NordSec 2019 (pp. 204-218). Aalborg, Denmark: Springer, 11875
Åpne denne publikasjonen i ny fane eller vindu >>A Study of Security Vulnerabilities and Software Weaknesses in Vehicles
2019 (engelsk)Inngår i: Nordic Conference on Secure IT Systems, Aalborg, Denmark: Springer, 2019, Vol. 11875, s. 204-218Konferansepaper, Publicerat paper (Fagfellevurdert)
Abstract [en]

In this paper, we conduct an empirical study with the purpose of identifying common security vulnerabilities discovered in vehicles. The vulnerability information is gathered for 60 vehicle OEMs (Original Equipment Manufacturers) and common vehicle components from the National Vulnerability Database (NVD). Each vulnerability (CVE) is analyzed with respect to its software weakness type (CWE) and severity score (CVSS). 44 unique CVEs were found in NVD and analyzed. The analysis results show that about 50% of the vulnerabilities fall into the medium severity category, and the three most common software weaknesses reported are protection mechanism failure, buffer errors, and information disclosure.

sted, utgiver, år, opplag, sider
Aalborg, Denmark: Springer, 2019
HSV kategori
Forskningsprogram
Datalogi
Identifikatorer
urn:nbn:se:kth:diva-264014 (URN)10.1007/978-3-030-35055-0_13 (DOI)000611477300013 ()2-s2.0-85076301277 (Scopus ID)
Konferanse
24th Nordic Conference on Secure IT Systems, NordSec 2019
Merknad

QC 20200722

Tilgjengelig fra: 2019-11-20 Laget: 2019-11-20 Sist oppdatert: 2022-06-26bibliografisk kontrollert
Xiong, W., Carlsson, P. & Lagerström, R. (2019). Re-using Enterprise Architecture Repositories for Agile Threat Modeling. In: 2019 IEEE 23rd International Enterprise Distributed Object Computing Workshop (EDOCW): . Paper presented at IEEE 23rd International Enterprise Distributed Object Computing Workshop, 28-31 Oct. 2019, Paris, France. Paris, France: Institute of Electrical and Electronics Engineers (IEEE)
Åpne denne publikasjonen i ny fane eller vindu >>Re-using Enterprise Architecture Repositories for Agile Threat Modeling
2019 (engelsk)Inngår i: 2019 IEEE 23rd International Enterprise Distributed Object Computing Workshop (EDOCW), Paris, France: Institute of Electrical and Electronics Engineers (IEEE), 2019Konferansepaper, Publicerat paper (Fagfellevurdert)
Abstract [en]

Digitization has increased exposure and opened up for more cyber threats and attacks. To proactively handle this issue, enterprise modeling needs to include threat management during the design phase that considers antagonists, attack vectors, and damage domains. Agile methods are commonly adopted to efficiently develop and manage software and systems. This paper proposes to use an enterprise architecture repository to analyze not only shipped components but the overall architecture, to improve the traditional designs represented by legacy systems in the situated IT-landscape. It shows how the hidden structure method (with Design Structure Matrices) can be used to evaluate the enterprise architecture, and how it can contribute to agile development. Our case study uses an architectural descriptive language called ArchiMate for architecture modeling and shows how to predict the ripple effect in a damaging domain if an attacker's malicious components are operating within the network.

sted, utgiver, år, opplag, sider
Paris, France: Institute of Electrical and Electronics Engineers (IEEE), 2019
HSV kategori
Forskningsprogram
Datalogi
Identifikatorer
urn:nbn:se:kth:diva-264018 (URN)10.1109/EDOCW.2019.00031 (DOI)000520469200017 ()2-s2.0-85075973320 (Scopus ID)
Konferanse
IEEE 23rd International Enterprise Distributed Object Computing Workshop, 28-31 Oct. 2019, Paris, France
Merknad

QC 20191126

Part of ISBN 978-1-7281-4598-3

Tilgjengelig fra: 2019-11-20 Laget: 2019-11-20 Sist oppdatert: 2024-10-23bibliografisk kontrollert
Organisasjoner
Identifikatorer
ORCID-id: ORCID iD iconorcid.org/0000-0003-0434-4436