Metaverse Security and Forensics: VR Devices as an Example
摘要
VR devices are a rapidly emerging type of sensory terminal device in the context of the metaverse, with its immersive use effects attracting a large number of users to experience. However, with the continuous development of virtual reality technology, an increasing number of criminal incidents in the virtual world have raised concerns. VR devices are developed based on the Android system but have their unique security mechanisms. Therefore, how to securely extract and preserve data from VR devices is a crucial concern for digital forensic practitioners. This paper first proposes a method for application data extraction and analysis in a non root environment within the VR ecosystem based on the Linux shared user id mechanism. This method utilizes Edge Developer Tools to debug Vuplex 3D Webview, enabling the extraction of internal storage data from embedded web pages within the application. Subsequently, a combination of decompilation and packet capture techniques is used to analyze the data transmission methods and data interaction logic of applications in the VR ecosystem. Finally, based on the experimental results, a comprehensive assessment of the security of VR devices is conducted in the paper. Data extraction from VR devices is an indispensable part of digital forensics in the era of the metaverse. The research on methods for extracting and analyzing application data in the VR ecosystem in this paper provides valuable reference for future forensic work on VR devices.