Skip to main content
Guidance

Risk management

How to understand and manage the cyber security risks for your organisation.

Page 13 of 15

Using attack trees to understand cyber security risk

How conceptual 'attack tree' diagrams can help you to represent and understand cyber security risk.






This step should then be repeated for each new node created, until there are no further steps in the process. The final nodes (that is, nodes with no steps beneath them) are known as leaf nodes.

When building an attack tree, there's no need to worry about aesthetics (that is, whether or not it looks like a tree). There's no need to have the same number of branches from each node, or for all paths from leaf nodes to the root node to be the same length. In fact, your tree will most likely be asymmetrical since attacks may have different numbers of steps, or require more or less detail.

Below is an example of how to build an attack tree based on a JavaScript example by Gergely Nemeth.

Example attack tree

Threat modelling for Node.

You should document each step of the attack tree build to capture the justification and evidence base used for making key decisions. It will also act as an audit trail, providing a rationale for decisions made based on the assessment.

If a larger attack tree is being built over a long period, the tree should be reviewed by a subject-matter expert to ensure that any assumptions made when the tree was originally built are still relevant. Nodes should be updated, as appropriate.

Building attack trees: a summary

  • Identify the core issue.
  • Create the root node for the core issue.
  • Identify the steps by which the attacker can achieve the core issue.
  • Add these steps as nodes beneath the core issue.
  • Repeat the process for each of the nodes you've just added.
  • The tree is complete when each branch of the tree ends in a leaf node (that is, nodes with no steps beneath them).



Published

Reviewed

Version

2.0