Risk management
How to understand and manage the cyber security risks for your organisation.
Pages
Page 13 of 15
Using attack trees to understand cyber security risk

How conceptual 'attack tree' diagrams can help you to represent and understand cyber security risk.
Introduction
This section introduces attack trees as a method for representing and understanding cyber security risk. Attack trees aim to build a structured and logical image of the cyber security risk to a system from the perspective of possible successful attacks.
What are attack trees ?
Attack trees are conceptual diagrams that show the variety of ways in which something can go wrong, and the reason why they might go wrong. The approach uses a visual representation of interconnected issues, that lead to a single major fault, and as such they are an effective way of performing root cause analysis. They are an adaption of the fault tree method used in safety analysis, an example of which is shown below.
In applying the same logic to cyber security, you can investigate the different ways that a system might be attacked, or how an attacker might achieve a specific objective.
Attack trees use a hierarchical representation of the steps needed for a successful attack. Each of the steps gives a requirement for completion for the step linked above it, where a successful attack is a complete set of requirements from the nodes at the bottom of the tree to those at the top. Each path in the tree should be unique, and there should be no loops in the design.

Why use an attack tree ?
Attack trees can provide another way of understanding cyber security risk by providing a visualisation of the problem. By diagrammatically representing a core concern and the components that lead to the attack, you can:
- Develop an understanding of how something can be at risk, noting not just the breadth of attack methods, but the number and ease of steps that are required.
- Develop a useful discussion tool. The simple design of a tree encourages discussions, critiques, and quick understanding of the attack methods used.
Visualising cyber security risk in this way gives a clear understanding of where the risk comes from, allowing you to identify security weaknesses and develop mitigations for them.
Attack trees can also be used effectively in agile environments, where the tree can be built alongside iterative development. Taking this approach means that cyber security risks are considered as they are discovered, and appropriate countermeasures can be introduced.
How to build attack trees
An attack tree is built from two components, nodes and branches.
Nodes can be representative of any aspect of an attack. This is usually an action from an attacker ('steal password') or a state that the system reaches as a result of an action ('get access to password manager').
Branches represent the dependencies between the nodes, identifying a causal link between the completion of those nodes that are lower in the tree with those above them. In most attack trees, no contextual information is given to a branch in a tree when represented diagrammatically. Any context is held implicitly between the two nodes.
To start building an attack tree, the first thing to consider is the objective of an attacker, or your overarching security concerns. These concerns should be sufficiently broad to acknowledge that attackers will usually be able to take multiple approaches to achieve their objective. This could range from broad concerns such as 'Can authentication of employees be bypassed?' to narrower questions like 'How vulnerable is my firewall configuration?' Once identified, this is placed at the top of the tree (also known as the root node).

Bypass Authentication
The next step is to identify as many ways by which that end goal or core concern can be realised. This can be defined in a variety of different ways, but is frequently represented as a set of technical capabilities required by the attacker. You can also consider the targets (different end points at which the objectives can be achieved) or vectors (the means by which the objectives can be achieved).
This step should then be repeated for each new node created, until there are no further steps in the process. The final nodes (that is, nodes with no steps beneath them) are known as leaf nodes.
When building an attack tree, there's no need to worry about aesthetics (that is, whether or not it looks like a tree). There's no need to have the same number of branches from each node, or for all paths from leaf nodes to the root node to be the same length. In fact, your tree will most likely be asymmetrical since attacks may have different numbers of steps, or require more or less detail.
Below is an example of how to build an attack tree based on a JavaScript example by Gergely Nemeth.
You should document each step of the attack tree build to capture the justification and evidence base used for making key decisions. It will also act as an audit trail, providing a rationale for decisions made based on the assessment.
If a larger attack tree is being built over a long period, the tree should be reviewed by a subject-matter expert to ensure that any assumptions made when the tree was originally built are still relevant. Nodes should be updated, as appropriate.
Building attack trees: a summary
- Identify the core issue.
- Create the root node for the core issue.
- Identify the steps by which the attacker can achieve the core issue.
- Add these steps as nodes beneath the core issue.
- Repeat the process for each of the nodes you've just added.
- The tree is complete when each branch of the tree ends in a leaf node (that is, nodes with no steps beneath them).
How do you work with attack trees ?
While the above process defines how a tree can be constructed conceptually, it doesn’t capture where the cyber security risk lies within the system. At this stage, the diagram only represents the different stages of an attack that come together to achieve a desired end goal. The next stage is to evaluate the tree. This is a process where the representation of the problem is turned into an assessment of the associated cyber security risk.
There are a variety of methods that can be used to evaluate an attack tree to understand the risk it shows. Regardless of the approach, contextual information needs to be added to each node of the tree so that you can understand the severity of the cyber security risk that it represents. Note that there is no 'best' methodology to assess the cyber security risk posed by nodes for attack trees; the most appropriate method will be one that is consistent with other aspects of your risk reporting. These assessments may be generated by conducting red team exercises aimed at identifying the most likely pathways to a compromise. Equally, experts may quantitatively estimate defensible values for the cyber security risk posed by each tree node based on their experiences and expertise.
Part of this analysis should be to break the threats down into overarching negative outcomes. Under each of these, specific outcomes can be listed, and the impact assessed. Outcomes may or may not be intentional. For example, it may be caused through intentional cyber attack, or through the unintentional failure to renew a software licence. The outcome is the same either way.
Another activity is to examine exploitation methods; these are ‘how’ an outcome is achieved. An exploitation method provides a means to gain access or capability within the system under review and may be used to achieve multiple outcomes. This process can be repeated to define a comprehensive set of attack vectors.
It may also be possible to use quantitative methods to apply 'scores' to nodes within your tree, but only where this information can be shown to be reliable and meaningful. For example, you may wish to assign a financial cost to each node. Or you could assess the ease with which a node could be exploited. What's important is that the cost or complexity should always be considered from the attacker's point of view.
Once you have assessed the cyber security risk posed by each node of the tree, each branch of the tree needs to be evaluated based on these assessments. This involves tracing a branch of the tree, and inputting the accumulated assessments into your chosen cyber security risk management framework, to get an assessment that represents the total risk of that attack.
The next step is to apply mitigations to each node in the tree. This may require you to prioritise the branches in the tree that you feel are most dangerous (that is, those that might result in most damage or provide the path of least effort or most reward for and attacker). Mitigations should be designed to reduce the cyber security risk associated with attacks that pass through that point. Ideally, the mitigation should be added to the tree at the point in an attack where it specifically reduces the risk. Implementing mitigation will usually modify your assessment for that node. This will allow you to evaluate the cost of each particular type of attack, and use the revised perspective to make security decisions.
Attack trees should only be used to influence decisions which relate to the core question or concern captured in the tree's root node. For example, an unpatched endpoint connected to the internet would represent a significant vulnerability within a system. The same unpatched endpoint might be assessed to be an insignificant vulnerability, if it were operating as a standalone machine. Context matters, and so it may not be correct to copy and paste mitigations between different nodes or trees.
A practical example of the use of attack trees
You may find it useful to review how the NCSC used attack trees to identify cyber security risks in our security analysis for the UK telecoms sector. This involved identifying higher level impacts or outcomes, and linking these to lower level methods or exploitation routes that could contribute to such events occurring.
Further reading
Further useful reading on attack trees can be seen in work by Bruce Schneier.


