How Can We Prepare for Metaverse Cyber Threats?

173 views
•
October 13, 2023
by
RSAC Cybersecurity
YouTube video player
How Can We Prepare for Metaverse Cyber Threats?

TL;DR

Preparing for metaverse cyber threats starts with defining the metaverse broadly enough to include augmented, virtual, and mixed reality, digital twins, phones, headsets, and online environments. Security planning must address familiar attacks, XR-specific vulnerabilities, sensitive sensor data, application providers, critical infrastructure dependencies, and hardware supply chains before adoption expands further.

Transcript

Hello, everyone, and thank you so much for joining us for this special edition of our RSAC 365 livestream. Thank you for tuning in. I'm your host, Casey Zerkas, with the RSA Conference team, and today I am talking with Michael Garcia, who was a recipient of the inaugural #ShareTheMic in Cyber fellowship grant. Michael, please take a moment to tell ... Read More

Key Insights

  • A useful metaverse definition is essential because cybersecurity challenges and solutions cannot be evaluated consistently without agreement about the technologies inside the concept. The paper separates commercialization language from technical capabilities to identify relevant systems and attack vectors.
  • The metaverse is broader than immersive virtual reality headsets. It can include augmented, virtual, and mixed reality, phone applications that place digital objects into physical rooms, online environments, and digital representations of people, facilities, or cities.
  • Digital twins are digital representations of entities ranging from individuals to water plants and cities. They can help operators identify efficiencies and potential physical or cybersecurity weaknesses, but their operational detail may also create valuable targets for attackers.
  • Critical infrastructure exposure is significant because metaverse technologies could be used across nearly all 16 United States critical infrastructure sectors. A successful attack could therefore affect systems tied to national security, the economy, public health, or public safety.
  • Extended reality is already used in consequential environments. An Australian water utility has used a digital schematic since 2017, Seoul created a digital environment for government services, and military systems have incorporated augmented reality capabilities for decades.
  • XR headsets can collect unusually sensitive information because they respond to voice and physical movement. Researchers identified vulnerabilities that could enable retinal tracking, room mapping, and audio capture through hardware, software, or applications supplied for use with a headset.
  • Application security is part of headset security because an attack can originate through software provided for an XR device rather than through the headset itself. Security assessments must therefore examine the broader ecosystem instead of treating the physical device as the only risk.
  • Supply chain resilience is a metaverse cybersecurity concern because headsets depend on semiconductors also used in cars, computers, and other connected devices. China’s stated interest in dominating near-eye display supply could also create manufacturing dependencies for United States producers.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: What technologies are included in the metaverse?

The metaverse can include augmented reality, virtual reality, mixed reality, extended reality devices, digital twins, online environments, and phone-based applications that overlay digital objects onto physical surroundings. It is not limited to immersive headsets or video games. Even using a phone to visualize a sofa inside a living room can represent a metaverse-related capability.

Q: Why must cybersecurity planners define the metaverse first?

Cybersecurity planners need a working definition because they cannot consistently identify challenges, attack vectors, or solutions without agreeing on what the metaverse includes. Distinguishing technical capabilities from commercialization also helps establish which technologies fall within the concept. That foundation makes it possible to examine relevant hardware, software, applications, digital environments, and operational uses systematically.

Q: How could critical infrastructure use metaverse technologies?

Critical infrastructure organizations could use extended reality and digital twins to represent facilities, inspect operations, identify efficiencies, and find potential physical or cybersecurity weaknesses. An Australian water utility, for example, has used a digital schematic since 2017. Because these tools may contain sensitive operational details, compromised devices or applications could expose more than ordinary consumer information.

Q: What is a digital twin in the metaverse?

A digital twin is a digital representation of a person, facility, water plant, city, or another real-world entity. It can support analysis of efficiencies and security weaknesses or provide access to services. Seoul invested millions of dollars in a digital Seoul that users can access by phone, headset, or online to obtain government services such as certificates.

Q: What privacy data can a compromised XR headset reveal?

A compromised XR headset or its supporting software could expose retinal movements, audio, and a map of the room where the user operates the device. These risks arise because headsets may continuously process voice and physical movement to support interaction. Researchers from LSU, Rutgers, and other institutions identified vulnerabilities involving hardware, software, and applications provided for headsets.

Q: Why are metaverse attacks dangerous for critical infrastructure?

Metaverse attacks become especially dangerous when XR systems contain digital schematics or provide access to operational environments. Capturing audio or mapping an ordinary room is already a privacy concern, but obtaining details about an airport, water utility, or another critical facility could have broader consequences. Disruption could affect national security, the economy, public health, or public safety.

Q: How does the metaverse create supply chain risks?

Metaverse devices depend on components that already support cars, computers, and other connected products, including semiconductors used in headsets. The paper also highlights China’s five-year metaverse plan and its goal of becoming the dominant supplier of near-eye displays. Concentrated control over such components could constrain supplies needed by United States manufacturers and create strategic dependencies.

Q: How should organizations prepare for metaverse cyber threats?

Organizations should begin by identifying which extended reality technologies, digital twins, devices, applications, and data flows they use. Their assessments should cover established attack methods as well as XR-specific risks such as retinal tracking, room mapping, and audio capture. They should also evaluate application providers, sensitive operational schematics, semiconductor dependencies, and near-eye display supply chains.

Summary & Key Takeaways

  • The metaverse lacks a universally accepted definition, which complicates cybersecurity analysis and policy. Garcia treats it as a broad collection of extended reality technologies rather than a headset-only environment. This framing includes everyday phone-based augmented reality, immersive virtual reality, mixed reality, digital twins, and online access to digitally represented services.

  • Extended reality already supports significant real-world functions. Examples include an Australian water utility using a digital schematic, Seoul providing government services through a digital environment, and military augmented reality applications. These cases demonstrate that compromised metaverse technologies could affect operational systems, sensitive facilities, public services, and national readiness.

  • Potential threats include compromised microphones, retinal tracking, room mapping, captured audio, vulnerable applications, and manipulated software. The risk extends beyond individual privacy when XR devices access critical infrastructure schematics or operational environments. Semiconductor dependencies and control over near-eye display manufacturing also introduce supply chain concerns that require deeper investigation.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚