Security, Privacy and Safety Risk Assessment for Virtual Reality Learning Environment Applications

Security, Privacy and Safety Risk Assessment for Virtual Reality Learning Environment Applications
复制标题

DOI:
10.1109/ccnc.2019.8651847
复制
发表时间:
2018-11
期刊:
2019 16th IEEE Annual Consumer Communications & Networking Conference (CCNC)
影响因子:
--
通讯作者:
Aniket Gulhane;Akhil Vyas;Reshmi Mitra;Roland Oruche;Gabriela Hoefer;Samaikya Valluripally;P. Calyam;K. A. Hoque
Aniket Gulhane;Akhil Vyas;Reshmi Mitra;Roland Oruche;Gabriela Hoefer;Samaikya Valluripally;P. Calyam;K. A. Hoque
中科院分区:
其他
文献类型:
--
作者:
Aniket Gulhane;Akhil Vyas;Reshmi Mitra;Roland Oruche;Gabriela Hoefer;Samaikya Valluripally;P. Calyam;K. A. Hoque

文献摘要

被引文献

相似文献

基于虚拟现实的社交学习环境(VRLE),如vSocial,在三维沉浸式计算机体验中呈现教学内容,用于培训有学习障碍的青少年。在VR技术中探索攻击漏洞的现有工作有限,因此需要系统框架来量化与安全、隐私和安全(SPS)威胁相对应的风险。SPS威胁可能会对教育用户体验产生不利影响,并阻碍VRLE内容的交付。在本文中,我们提出了一种新的风险评估框架,利用攻击树来计算风险得分为不同的VRLE威胁率和持续时间的威胁作为输入。我们比较了一个精心构造的攻击树与adhoc攻击树的影响,研究管理攻击树的开销之间的权衡,以及发现漏洞时的风险缓解成本。我们使用一个vSocial VRLE测试平台的案例研究,展示我们的框架的有效性,并演示了如何一个合适的攻击树形式主义可以导致一个更安全,隐私保护和安全的VRLE系统。
Social Virtual Reality based Learning Environments (VRLEs) such as vSocial render instructional content in a three-dimensional immersive computer experience for training youth with learning impediments. There are limited prior works that explored attack vulnerability in VR technology, and hence there is a need for systematic frameworks to quantify risks corresponding to security, privacy, and safety (SPS) threats. The SPS threats can adversely impact the educational user experience and hinder delivery of VRLE content. In this paper, we propose a novel risk assessment framework that utilizes attack trees to calculate a risk score for varied VRLE threats with rate and duration of threats as inputs. We compare the impact of a well-constructed attack tree with an adhoc attack tree to study the trade-offs between overheads in managing attack trees, and the cost of risk mitigation when vulnerabilities are identified. We use a vSocial VRLE testbed in a case study to showcase the effectiveness of our framework and demonstrate how a suitable attack tree formalism can result in a more safer, privacy-preserving and secure VRLE system.