INFS 767, Fall 2003, Examination 1

Posted: 10/10/2003, Due in class: 10/23/03

Prof. Ravi Sandhu

 

This is a take-home, open-book and open-time examination.  You are required to solve it on your own using whatever material you like.  Please sign and submit the following honor code statement with your solution:

 

I have not taken any help on this examination from anyone and not provided any help to anyone.  The solution has been entirely worked out by me and represents my individual effort.

 

Please submit a typed solution with the signed honor code statement.  Keep a copy for your records and reference.  The process for grading the examination will be discussed later.  Any clarification questions regarding the examination should be emailed to sandhu@gmu.edu.  Clarifications will be posted on this page as needed.

 

ANSWER ALL 3 QUESTIONS.  ALL QUESTIONS HAVE EQUAL WEIGHT.

 

  1. Consider the RBAC96 model defined in

·        Ravi Sandhu, Edward Coyne, Hal Feinstein and Charles Youman, Role-Based Access Control Models, IEEE Computer, Volume 29, Number 2, February 1996

and the proposed NIST standard model defined in

·        David F. Ferraiolo, Ravi Sandhu, Serban Gavrila, D. Richard Kuhn and Ramaswamy Chandramouli, Proposed NIST Standard for Role-Based Access Control, ACM Transactions on Information and Systems Security (TISSEC), Volume 4, Number 3, August 2001.

a)      Give a comparison of the two models (maximum length 1 page).  Do not repeat a description of the 2 models.  That is already available in the papers.  Focus on identifying significant similarities and differences and important pros and cons.

b)      Discuss whether or not the proposed NIST standard would be useful if widely adopted by the security industry (maximum length 1/2 page)

 

  1. Separation of duties is traditionally concerned with the regular roles in the organization.  Consider application of separation of duties to administrative roles. 

a)      Discuss what kinds of separation of duties may be useful in the context of administrative roles (maximum length 1/2 page).

b)      Discuss how RCL2000 may be extended to cover administrative roles (maximum length 1/2 page).

 

  1. Consider the criticism of ARBAC97 and suggested improvements in

·        Sejong Oh, Ravi S. Sandhu, A Model for Role Administration Using Organization Structure, SACMAT 2002.

Give a review of this paper and an assessment of suggested modifications to ARBAC97 (maximum length 1 page).  

 

 

History:

10/10/03: Examination 1 posted.  No clarifications so far.