<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta>
      <journal-title-group>
        <journal-title>International Workshop on Socio-Technical Perspective in IS development, August</journal-title>
      </journal-title-group>
    </journal-meta>
    <article-meta>
      <title-group>
        <article-title>A Model for the Creation of Biographical Dictionaries</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Marcus Birath</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Johan Ginman</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Joakim Kävrestad</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>University of Skövde</institution>
          ,
          <addr-line>Högskolevägen 1, Skövde</addr-line>
          ,
          <country country="SE">Sweden</country>
        </aff>
      </contrib-group>
      <pub-date>
        <year>2022</year>
      </pub-date>
      <volume>1</volume>
      <fpage>9</fpage>
      <lpage>21</lpage>
      <abstract>
        <p>The use of encryption is increasing, and while that is good for cybersecurity it is a core challenge for digital forensics. Encrypted information cannot be analyzed unless it is first decrypted, which is a complex and time-consuming process. Using a brute force attack to guess the password used for encryption is deemed impractical as even a simple password, being long enough, could take weeks, months, or even years to find. A more feasible approach is to use a dictionary attack where each word in a list is tested. However, a dictionary attack is only successful if the password is in the list, making the process of creating that list a crucial part of decrypting passwords. This research builds on existing literature showing that users commonly use strategies to create passwords, and the aim is to propose a method for creating dictionaries that are grounded in theories of password construction. An initial model was developed using a selective literature review with the purpose of identifying common elements included in biographical passwords, and in what order the elements are used. To improve the model, the study utilized semi-structured interviews with forensic experts from the Swedish police and the Swedish National Forensic Center (NFC). The main contribution of this research is a readily available model for creating dictionaries that can be used by practitioners. The model can also serve as a theoretical contribution that describes how users commonly construct biographical passwords.</p>
      </abstract>
      <kwd-group>
        <kwd>1 passwords</kwd>
        <kwd>biographical dictionary</kwd>
        <kwd>password cracking</kwd>
        <kwd>digital forensics</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>
        While current digital advancements generally are considered beneficial for the society, they also
enable new opportunities for criminals, consequentially creating new challenges for law enforcement
[
        <xref ref-type="bibr" rid="ref1">1</xref>
        ]. The digital world has rapidly become a platform for criminal activities such as selling drugs, child
abuse, or extorsion. Thus digital evidence obviously plays a vital role in crimes conducted in a digital
environment. However, digital evidence also plays an important role in prosecuting all types of crimes
as the general use of personal digital devices has increased and are therefore likely to contain
information of investigative importance (e.g. communication and chat data, position and location data,
affiliations with other suspects, and images). Consequently, digital devices hold evidence that is
important for modern criminal investigations. The process of securing and analyzing data from such
devices is called digital forensics, and the need for digital forensics in criminal investigations is
increasing rapidly [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ].
      </p>
      <p>
        One of the core challenges of digital forensics is encryption, as it is the main method used by
criminals to restrict access to data stored on a digital device [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ][
        <xref ref-type="bibr" rid="ref4">4</xref>
        ]. There are many encryption
techniques available, and today many digital devices (e.g. smartphones or computers) come with
encryption enabled by default which can encrypt a folder, an entire drive of a PC, an application, or a
cloud service automatically or in just a few clicks [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ]. In most cases, these encryption techniques are
used in conjunction with passwords. As the encryption techniques themselves are often robust and
standardized, they cannot be attacked directly, leaving the process of password recovery a necessity for
forensic experts to decrypt data and collect evidence. Many encryption schemes are created to withstand
brute force attacks, and it is, therefore, critical to find other methods in order to collect evidence in a
timely manner [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ]. One such method is to dump the memory and analyze it for passwords or encryption
keys. Memory analysis is a technically advanced technique that requires the device to be acquired in a
powered-on state and that precautions are taken not to alter the volatile data. A more feasible method is
to find the password using a dictionary attack where each password in a list is tested. However, a
dictionary attack is only successful if the password is in the list, making the process of creating that list
a crucial part of decrypting passwords. As users tend to create easy to remember passwords, dictionaries
that contain biographical data such as names, dates, hobbies, and other personal information are
suggested to have a higher possibility of being successful as they relate to common strategies used for
password creation [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ][
        <xref ref-type="bibr" rid="ref5">5</xref>
        ].
      </p>
      <p>Simple dictionary attacks usually include existing lists of previously leaked passwords which are
unlikely to contain a password that is based on a targeted person’s biographical data. To be more
successful, biographical information about the targeted person needs to be collected by forensic experts
and put into a text file which can be used with programs such as JohnTheRipper together with
combination and modification rules to ultimately find the correct password. The success rate is thus
dependent on identifying and collecting the correct biographical information.</p>
      <p>This research aims to create a model to support the creation of dictionaries used when cracking
passwords based on biographical data. The model should aid forensic experts in the acquisition of
biographical data during a forensic investigation and in the composition of a dictionary that is likely to
contain the targeted password and do so in the most time-efficient manner. The explicit focus just
described implies that this research will neither cover the technical details of cracking passwords nor
how to create dictionaries to crack passwords based on other elements than biographical information.</p>
    </sec>
    <sec id="sec-2">
      <title>2. Method</title>
      <p>
        This study has an action-based approach that, according to [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ], is a collaborative method where
systematic action is used to reach a specific goal and improve specific practices. This research includes
collaborative development with professional forensic experts from law enforcement. First, based on
current research, the facts about the creation of biographical passwords were collected. Second, an
initial model was created based on the output from the previous step. Finally, an iterative process began
where the model was revised based on interviews with field experts.
2.1.
      </p>
    </sec>
    <sec id="sec-3">
      <title>Selective Literature Review</title>
      <p>
        To build a foundation for the initial model this study utilized a selective literature review which,
according to [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ], is an excellent way to start action-based qualitative research. This also ensures that the
research is grounded in relevant previous research [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ]. The selective literature review was used to
identify components that commonly make up biographical passwords and in which order they are used.
The study used the databases Sciencedirect, Wiley, and ACM with the following search terms:
 “biographical” AND “password”






“password” AND “personal information”
“password” AND “building”
“biographical” AND “dictionary” AND “password”
“password”
“password” AND “police”
“cracking passwords”
      </p>
      <p>The found articles’ abstracts were analyzed to filter out articles relevant to the research topic; user
strategies for the creation of biographical passwords. Relevant articles were read in their entirety and
analyzed to identify what biographical elements are commonly used and categorize that data
thematically. The articles were also analyzed in order to find patterns as to how common the elements
are and how passwords created with such data are usually structured. Based on the findings, an initial
model was created, which was used as input for the interviews.
2.2.</p>
    </sec>
    <sec id="sec-4">
      <title>Semi-structured Interviews</title>
      <p>To improve the initial model the study utilized semi-structured individual interviews with three
forensic experts from the Swedish police and the Swedish National Forensics Center (NFC). The
experts were purposefully selected as they encounter encryption as part of their daily work. The purpose
of the interviews was to validate and improve the model based on the experience of field experts. It was
deemed that three interviews, independent of each other, would sufficiently cover the potentially
different experiences of forensic practitioners to aid the purpose of this study. The interviews were
conducted in a semi-structured way utilizing open-ended questions. Thus the interviewees were invited
to speak freely about the subject and add their own opinions. The interviews were recorded and
transcribed in their entirety. The transcribed material was then analyzed and categorized using a
thematic approach. The changes consequently led to a revised model, which was, again, presented to
the interviewees. This iterative process continued until the interviewees all considered the model
complete.</p>
    </sec>
    <sec id="sec-5">
      <title>3. Results and Discussion</title>
      <p>This chapter presents the results of the research process. First, the results from the selective literature
review are presented, and then the opinions from the interviewees and how they revised the model are
presented. Finally, the resulting model for creating a dictionary based on biographical data is presented.
3.1.</p>
    </sec>
    <sec id="sec-6">
      <title>Selective Literature Review</title>
      <p>This section presents the results of the literature analysis. First, the components commonly used
when creating passwords based on biographical data are presented. Then, the order in which they are
commonly used is discussed. The publications identified during the search and selection process are
cited throughout this section.</p>
      <p>
        Names of different types are common components of passwords. Of approximately six million
leaked passwords analyzed by [9], more than 25% included names. [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ] analyzed the passwords of 100
participants of different groups (students, IT professionals, and the general population), where 67% of
the students and 42% of the other groups used names in their passwords. [10] present a summary of a
previous study consisting of 1200 participants where 26% of the passwords contained names or
nicknames. In their own study, [10] found that 32% of 218 students’ passwords contained their own, a
pet’s, partner’s, or relative’s name.
      </p>
      <p>The analyzed literature [10][11][12] shows that multiple kinds of geographical and positional data
may be included in passwords. The identified geographical and positional entities are found in Table 1.</p>
      <p>Requirements on password complexity commonly force users to incorporate numbers in their
passwords. Consequently, users also tend to incorporate numbers that have some kind of personal
meaning. [13], [9] and [14] find that birth dates are common when combining letters and numbers as
well as personal identification numbers and phone numbers. It is also common to use a friend’s or
relative’s phone number or birth date [14].</p>
      <p>Almost all words that have some kind of meaning to the user may be used in password creation
[15]. [10] found that almost a third of their analyzed passwords contained entities that can be
categorized as Hobbies &amp; Interests, such as athletic teams, celebrities, fictional characters, and sports.
[16] also mentions favorite foods as potential password elements. Further, [11] suggests that it is
reasonable to include, for example, the entire collection of the Lord of the Rings books if the user has
such an interest. The identified interests and hobbies found are presented in column 3 of Table 1, which
presents and overviews the biographical entities found in the literature.</p>
      <sec id="sec-6-1">
        <title>Names</title>
      </sec>
      <sec id="sec-6-2">
        <title>Geographical Information</title>
      </sec>
      <sec id="sec-6-3">
        <title>Hobbies &amp; Interests</title>
      </sec>
      <sec id="sec-6-4">
        <title>Numbers &amp; Dates</title>
        <sec id="sec-6-4-1">
          <title>Hobbies &amp; Interests</title>
          <p>Athletic teams</p>
          <p>Celebrities</p>
          <p>TV shows
Fictional characters
Other interests and
hobbies</p>
          <p>Foods</p>
        </sec>
        <sec id="sec-6-4-2">
          <title>Numbers &amp; Dates</title>
          <p>Year of birth
Date of birth</p>
          <p>Personal
identification number
Phone numbers</p>
          <p>Related persons’
numbers &amp; dates</p>
        </sec>
      </sec>
      <sec id="sec-6-5">
        <title>Numbers &amp; Dates</title>
        <p>Semi-structured interviews were conducted with the Swedish police and the Swedish National
Forensics Center (NFC) for the purpose of refining the initial model. The results of the analyzed
interviews are presented below.</p>
        <p>Interview 1 was conducted with an IT forensics expert from the Swedish police. The categories and
the biographical components from the initial model are acknowledged and cover what the interview
subject would currently use to generate a dictionary. Improvement suggestions are to include current
and previous workplaces and schools in the category Geographical Information. Regarding the
category order, the interview subject believes it is more common to use interests and hobbies than
geographical information. Thus the category Hobbies &amp; Interests should be tested prior
to Geographical Information. The interview subject also acknowledges the utilization of Numbers &amp;
Dates in conjunction with the other categories as commonplace for password creation.</p>
        <p>Interview 2 was conducted with an IT forensics expert working with the Swedish police. The
interview subject recognizes the current categories and their elements as highly relevant as they have
been a part of almost all biographical passwords cracked or encountered. Suggested refinements are to
include books and historical events in the category Hobbies &amp; Interests. As an example, the title or the
first word of a book is not uncommon. The final suggestion is to include the element “other” in all
categories. This is to encourage the investigator using the model to feel free to include other information
relevant to the category. The most commonly used biographical password is, according to the interview
subject, a person’s name in conjunction with a birth date. Thus the category Names is very common
and should be tested first. In an attempt to distance the password from themselves, users create
passwords based on interests and hobbies more often than geographical information and dates or
numbers, making the Hobbies &amp; Interests category prioritized. The model should also include the
transformation of passwords using leetspeak and special characters. Other opinions expressed by the
interview subject are that many passwords are believed to be cracked using the categories and elements
from the model and that the prioritization would complete the process more efficiently. Finally, the
interview subject underlines the importance and usefulness of the model from a forensic standpoint.</p>
        <p>The third interview was conducted with a person from the Swedish National Forensics Center (NFC)
working with re-creation of passwords, encryption, and digital forensics. Regarding the categories, the
elements nicknames and internet aliases should be added to the category Names. It was also pointed out
to include the mother’s maiden name as it is common for the mother to change name when married,
which makes the maiden name less traceable to the targeted person. Further, the category Numbers &amp;
Dates should be changed to Important Numbers to reflect a more general view of what numbers could
represent and include vehicles’ license plate numbers and postal codes. Geographical
Information should include vacation locations and user origins. If the targeted person originates from
another country, that country and geographical areas in that country are possible elements. Related to
the geographical information, one should also consider other languages that the targeted person may be
familiar with and use the translated versions of gathered information. The category Hobbies &amp;
Interests should be updated with the element paraphilias and vehicles, which could include vehicle
types, brands, and models. Regarding the order, the interview subject suggests that Geographical
Information and Hobbies &amp; Interests should switch places as hobbies and interests are more personal
and thus more likely to be used as a password. It is also recommended to combine all categories with
each other to create as many passwords as possible and then apply modifications such as leetspeak or
special characters. The interview subject explicitly pointed out the importance of having a historical
perspective of all the categories. This means to keep in mind what the elements could have been
historically, for example, a childhood friend or the phone number of the local pizza place where the
targeted person grew up or studied. To not make the user of the model miss valuable information, the
elements should be open and general to be as inclusive as possible. Finally, utilizing a biographical
dictionary to crack passwords is considered very successful as most passwords turn out to be based on
biographical information.</p>
        <p>Based on the information gathered from existing research and the interviews, a revised model is
presented in Figure 2.
Step 1. Collection of elements</p>
        <p>Names
 Own names
 Family members
 Friends
 Partners
 Pets
 Initials
 Nicknames
 Usernames
 Internet aliases
 School credentials
 Other name information
 Other related to the
category</p>
        <p>Hobbies &amp; Interests
 Sports
 Music
 Interests
 Hobbies
 Outdoor activities
 Idols
 TV shows
 Characters
 Fictional characters
 Books
 Vehicles
 History
 Paraphilias
 Foods
 Other related to the
category</p>
        <p>Geographical</p>
        <p>Information
 Addresses
 Cities
 Areas and Places
 Countries
 Resorts
 Origins
 Study places
 Work place information
 Language
 Other related to the
category</p>
        <p>Important Numbers
 Year of birth
 Date of birth
 Personal ID number
 Phone numbers
 Postal codes
 Vehicle registration</p>
        <p>numbers
 Other related to the
category
1. Names
2. Hobbies &amp;</p>
        <p>Interests
3. Geographical</p>
        <p>Information
4. Important
Numbers</p>
      </sec>
      <sec id="sec-6-6">
        <title>Step 2. Combine and merge categories</title>
      </sec>
      <sec id="sec-6-7">
        <title>Step 3. Apply modifications</title>
        <p>Names</p>
        <p>Hobbies &amp; Interests
Geographical Information</p>
        <p>Important Numbers</p>
        <p>Language
Leetspeak
Symbols</p>
        <p>Backwards</p>
        <p>Other modifications</p>
        <p>Apart from the added elements, the final model also reflects structural changes recommended from
the interviews. The final model now includes combining all categories with each other (step 2), which
replaces combining just numbers and dates with all other categories. The interviewees also agreed
that Hobbies &amp; Interests are more common than geographical information, which is now reflected in
the final model. The revised model was sent to the interviewees for assessment and received satisfactory
responses.</p>
      </sec>
    </sec>
    <sec id="sec-7">
      <title>4. Conclusions</title>
      <p>This research reviewed the literature for elements commonly included when creating passwords that
are based on biographical information. Based on current research, an initial model was created, which
was then refined through semi-structured interviews with practitioners from the field. The interviewees
deemed the final model to be useful and likely to be successful as passwords, in many cases, are based
on personal information.</p>
      <p>We present a ready to use model to support the creation of biographical dictionaries used when
cracking passwords. The model is based on previous research and practical knowledge of what elements
are used in biographical passwords and in what order they are most often used. Consequently,
dictionaries resulting from the use of the model will contain likely passwords ordered by probability.
The resulting dictionary will thus contain the most commonly used elements in an order that could
improve efficiency.</p>
      <p>The model suggests that information in four different categories should first be collected, then
combined with each other, and finally modified using various techniques (e.g. leetspeak). In addition
to the three-step process, the model also presents commonly used elements and the order in which they
should be tested based on previous research and the experience of professional practitioners. The list of
biographical elements can thus serve as a guide for what information that should be collected during a
forensic investigation to increase the chance of cracking upcoming passwords. Our model could aid law
enforcement when passwords need to be cracked, consequently collecting evidence in a more efficient
and time-saving manner. This research also highlights common password behavior that may be taken
into consideration by system administrators when creating password policies. The results are, in that
regard, a summary of current research around password behavior.</p>
      <p>To be successful, the user of the model should also consider the languages known to the targeted
person and have a historical perspective, ultimately including both present and past versions of the
elements in multiple languages. It should also be noted that the model is not only useful for cracking
passwords used for encryption but also to crack passwords to gain access to devices, accounts, and
systems in order to collect more evidence, regardless of encryption, where the legislation allows.</p>
      <p>Finally, using the model is likely to result in more cracked passwords and potentially solving crimes.
However, the model is not mutually exclusive to other methods, and we want to highlight the
importance of using other tools and methods as well to be successful in the field of digital forensics.</p>
    </sec>
    <sec id="sec-8">
      <title>5. Future Work</title>
      <p>This study provides the research community with additional insight into password creation. To
validate the effectiveness, a practical evaluation of the model is necessary. This could be achieved using
a collection of cracked passwords that are known to be created using biographical data and see whether
information collected based on the model would generate those passwords. The effectiveness should
also be compared to other methods of cracking passwords, such as using lists of leaked passwords or
brute force attacks. Furthermore, this study was conducted from the perspective of Swedish forensic
experts. Similar studies could be conducted to investigate potential differences in password behavior
between countries and cultures to further improve the model.
6. References
[9] M. AlSabah, G. Oligeri, and R. Riley, Your culture is in your password: An analysis of a
demographically-diverse password dataset, Computers and Security 77 (2018) 427–441.
doi:10.1016/j.cose.2018.03.014.
[10] A. S. Brown, E. Bracken, S. Zoccoli, and K. Douglas, Generating and remembering passwords,</p>
      <p>Applied Cognitive Psychology 18 (2004) 641-651. doi:10.1002/acp.1014
[11] J. Kävrestad, Fundamentals of Digital Forensics – Theory, Methods and Real-life Application,</p>
      <p>Springer, Switzerland.
[12] K. Al-Wehaibi, T. Storer, and W. B. Glisson, Augmenting password recovery with online
profiling, Digital Investigation 8 (2011) 25–33. doi:10.1016/j.diin.2011.05.004.
[13] K. Renaud, R. Otondo, and M. Warkentin, “This is the way ‘I’ create my passwords” … does the
endowment effect deter people from changing the way they create their passwords?, Computers
and Security 82 (2019) 241–260. doi:10.1016/j.cose.2018.12.018
[14] G. B. Duggan, H. Johnson, and B. Grawemeyer, Rational security: Modelling everyday password
use. International Journal of Human Computer Studies 70 (2012) 415–431.
doi:10.1016/j.ijhcs.2012.02.008
[15] R. Alomari, M. V. Martin, S. MacDonald, A. Maraj, R. Liscano, and C. Bellman, Inside out - A
study of users’ perceptions of password memorability and recall, Journal of Information Security
and Applications 47 (2019) 223–234. doi:10.1016/j.jisa.2019.05.009
[16] F. Ghiyamipour, Secure graphical password based on cued click points using fuzzy logic, Security
and Privacy, 4 (2021). doi:10.1002/spy2.140
[17] V. Zimmermann, and N. Gerber, The password is dead, long live the password – A laboratory
study on user perceptions of authentication schemes, International Journal of Human Computer
Studies 133 (2020) 26–44. doi:10.1016/j.ijhcs.2019.08.006</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>A.</given-names>
            <surname>Kanta</surname>
          </string-name>
          ,
          <string-name>
            <surname>I. Coisel</surname>
          </string-name>
          , and
          <string-name>
            <given-names>M.</given-names>
            <surname>Scanlon</surname>
          </string-name>
          ,
          <article-title>A survey exploring open source Intelligence for smarter password cracking</article-title>
          ,
          <source>Forensic Science International: Digital Investigation</source>
          <volume>35</volume>
          (
          <year>2020</year>
          ). doi:
          <volume>10</volume>
          .1016/j.fsidi.
          <year>2020</year>
          .
          <volume>301075</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>S.</given-names>
            <surname>Belshaw</surname>
          </string-name>
          , and
          <string-name>
            <given-names>B.</given-names>
            <surname>Nodeland</surname>
          </string-name>
          ,
          <article-title>Digital evidence experts in the law enforcement community: understanding the use of forensics examiners by police agencies</article-title>
          ,
          <source>Security Journal</source>
          <volume>35</volume>
          (
          <year>2021</year>
          )
          <fpage>248</fpage>
          -
          <lpage>262</lpage>
          . doi:
          <volume>10</volume>
          .1057/s41284-020-00276-w
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <surname>Forensicfocus</surname>
          </string-name>
          .com,
          <source>Current Challenges in Digital Forensics</source>
          ,
          <year>2016</year>
          . URL: https://www.forensicfocus.com/articles/current
          <article-title>-challenges-in-digital-forensics/.</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>R.</given-names>
            <surname>Montasari</surname>
          </string-name>
          , and
          <string-name>
            <given-names>R.</given-names>
            <surname>Hill</surname>
          </string-name>
          ,
          <article-title>Next-Generation Digital Forensics: Challenges and Future Paradigms</article-title>
          ,
          <source>in: 2019 IEEE 12th International Conference on Global Security, Safety and Sustainability (ICGS3)</source>
          ,
          <year>2019</year>
          , pp.
          <fpage>205</fpage>
          -
          <lpage>212</lpage>
          . doi:
          <volume>10</volume>
          .1109/ICGS3.
          <year>2019</year>
          .8688020
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>R.</given-names>
            <surname>Alomari</surname>
          </string-name>
          , and
          <string-name>
            <given-names>J.</given-names>
            <surname>Thorpe</surname>
          </string-name>
          ,
          <article-title>On password behaviours and attitudes in different populations</article-title>
          ,
          <source>Journal of Information Security and Applications</source>
          <volume>45</volume>
          (
          <year>2019</year>
          )
          <fpage>79</fpage>
          -
          <lpage>89</lpage>
          . doi:
          <volume>10</volume>
          .1016/j.jisa.
          <year>2018</year>
          .
          <volume>12</volume>
          .008
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>E. T.</given-names>
            <surname>Stringer</surname>
          </string-name>
          , Action Research, 4th. ed., SAGE Publications, CA, USA,
          <year>2014</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>R.</given-names>
            <surname>Yin</surname>
          </string-name>
          , Qualitative Research from Start to Finish, Guilford Publications,
          <string-name>
            <surname>NY</surname>
          </string-name>
          , USA,
          <year>2011</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>H.</given-names>
            <surname>Snyder</surname>
          </string-name>
          ,
          <article-title>Literature review as a research methodology: An overview and guidelines</article-title>
          ,
          <source>Journal of Business Research</source>
          <volume>104</volume>
          (
          <year>2019</year>
          )
          <fpage>333</fpage>
          -
          <lpage>339</lpage>
          . doi:
          <volume>10</volume>
          .1016/j.jbusres.
          <year>2019</year>
          .
          <volume>07</volume>
          .039
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>