Rutgers The State University of New Jersey
Rutgers Business School, Newark and New Brunswick
Information Systems Security
26:198:643
Spring 2010
Mondays 2:30 - 5:20pm, 1 Washington Park, Room 528
Official University/Campus
closings due to inclement weather:
Call 973-353-1766 or 732-932-1766, Newark Campus Information
Course Description:
Recent years have witnessed widespread use of computers and their
interconnecting networks. This demands additional computer
security measures to protect the information and relevant
systems. This course prepares the students to meet the new
challenges in the world of increasing threats to computer
security by providing them with an understanding of the various
threats and countermeasures. Specifically, students will learn
the theoretical advancements in information security,
state-of-the-art techniques, standards and best practices.
In particular, the
topics covered in this course include: Study of security
policies, models and mechanisms for secrecy, integrity and
availability; Operating system models and mechanisms for
mandatory and discretionary controls; Data models, concepts and
mechanisms for database security. Basic cryptology and its
applications; Security in computer networks and distributed
systems; Identity threat; Control and prevention of viruses and
other rogue programs.
Text Book:
- Matthew Bishop,
Introduction to Computer Security, Addison-Wesley
2004
Reference Books:
- Charlie Kaufman, Radia Perlman and Mike Speciner,
``Network Security: Private Communication in a Public World,''
Prentice-Hall, 1995.
- Silvana Castano, Mariagrazia Fugini, Giancarlo Martella, and
Pierangela Samarati, ``Database Security,'' Addison-Wesley,
Reading, MA, 1994.
- Plus selected readings
Other sources:
- The
DBLP Bibiliography An Excellent source for the Research
materials in the Database area
- Google Scholar
Related Journals and Conferences:
-
ACM Conference on Computer and Communications Security (CCS)
- IEEE Symposium on Security and Privacy (S&P)
- ACM Symposium on Access
Control Models and Technologies (SACMAT)
- IFIP WG11.3
Working Conference on Data and Application Security (DBSEC)
- Annual Computer Security Applications Conference (ACSAC)
-
Computer Security Foundations Workshop
- ACM Transactions on
Information Systems Security (TISSEC)
- IEEE Transactions on Dependable and Secure Systems (TDSC)
- Journal of Computer
Security
- Computers and Security
Expected Work:
Research Paper and Presentation 50%
Mid term Examination 25%
Final Examination 25%
Tentative Schedule:
Jan 25
Basic Security Concepts, Introduction to Cryptography,
Secret Key and Public Key
Cryptography
Feb 1
Introduction to Cryptography, Secret Key and Public Key
Cryptography (continued)
Feb 8
Digital Signatures and Certificates
Feb 15, 22
Internet Security
Mar 1, 8
Securiy Models
- Chapters 2,3,4
- Lecture Notes 1
- Lecture Notes 2
- "M.A. Harrison, W.L. Ruzzo, and J.D. Ullman: Protection in
Operating Systems. CACM, August 1976.
- Access
Control: Principles and Practice, Ravi Sandhu &
P. Samarati, IEEE Communications, Volume 32, Number 9 /September 1994
-
Lattice-Based Access Control Models,Ravi Sandhu, IEEE
Computer, Volume 26, Number 11 (Cover Article) November 1993
- "D.F.C. Brewer and M.J. Nash: "The Chinese Wall Security
Policy", in IEEE Symposium on Security and Privacy '1989
-
Role-Based Access Control Models,
"R.S. Sandhu, E.J. Coyne, H.L. Feinstein, and
C.E. Youman.
IEEE Computer,
29(2):38--47, February 1996.
- "D. Ferraiolo, R. Sandhu, S. Gavrila, D. Kuhn, and
R. Chandramouli. Proposed NIST standard for role-based access
control. ACM Transactions on Information Systems Security,
2001.
Mar 22
- Database Security
- Chapters 14,15
- Lecture Notes
- Database Security -- Concepts,
Approaches, and Challenges
Elisa Bertino and Ravi Sandhu,
IEEE Transactions on Dependable and Secure Computing,
Vol. 2, NO. 1, January-March 2005
- A chapter from
"Multilevel
secure transaction processing," Kluwer Academic Publishers, by
V.Atluri, S. Jajodia and B. George
Mar 29
Apr 5
- The Role Mining Problem, Guest Lecture by Haibing
Lu
- Lecture Notes
Apr 12
- Security and Privacy in Spatial and Mobile Data, Guest
Lecture by Heechang Shin
Note: The class will be held in Room 1027, and starts at 11:00am
- Lecture Notes
- Research Paper Due ( Email your
paper to me at the following address: atluri at rutgers dot edu )
Apr 19
- Research Paper Presentations: Each student will have 40
minutes to present
- Hussein Issa
- David Chan
- Roman Chychyla
- Yong Ge
Apr 26
- Research Paper Presentations: Each student will have 40
minutes to present
- Nazia Badar
- Zhongmou Li
- Qi Liu
- David Lorenzi
May 3
- Research Paper Presentations: Each student will have 40
minutes to present
- Ishita Chokshi
- Zheng Wei
- Raymond Wong
May 10
Topics for the Research paper include:
- Best Source: The session topics in the conferences listed above
- Authorization Models for New Application domains
- Role-based Access Control
- Inference Control
- Security in Electronic Commerce
- Security in WWW
- Security for Mobile Systems
- Intrusion Detection
- Security for Web services
- Biometrics
- Privacy
- Privacy preseving data sharing and mining
- Security of Statistical Databases
- Viruses
- Computer Ethics
- Spam and Phishing
- Identity theft
- .....
|