Why is an attack tree's cheapest path often not the attack you should expect?
answer
- a bound, not a forecast
- attackers optimise return, not unit price
- one-off versus repeatable at volume
- the figure omits exposure and held capability
basics
~20 sCheapest-path propagation assumes an attacker minimising your cost estimate for one attempt. Real adversaries optimise repeatability, exposure risk and capability they already own, so the attack you actually see is often a costlier branch run at volume.
solid answer
~50 sMinimum-at-OR gives the cheapest complete path, which is a **lower bound on attacker effort** — not a forecast. Take a refund-redirect tree for a tax-filing portal. The cheapest branch might be paying one contact-centre agent to change the bank details on a single account: a few thousand, one refund, done. The branch you will actually be hit by is credential phishing of taxpayers — a higher setup cost, but a per-victim cost near zero, infinitely repeatable, no accomplice who can identify you, and no physical presence. The cost figure ignores scale, the attacker's appetite for exposure, and what capability they already possess. I report both readings: the cheapest path tells me how strong my guarantee actually is, and the likeliest path tells me what to instrument and staff for. They usually point at different controls, and pretending one number covers both is where trees get discredited.
go deeper
Know that the number propagated to the root of an attack tree is the least an attacker could spend, not the attack most likely to be attempted. Do not describe the cheapest path as a prediction.
Explain what the cost annotation omits: setup versus per-attempt cost, exposure risk, and capability the attacker already owns. Be able to give one example where the cheapest branch and the expected branch differ.
Demonstrate that you would report a named path with its runner-up rather than a bare number, and that you run the tree per adversary profile. Interviewers want to hear you separate the bound you can defend from the forecast you cannot.
Own the tension between a defensible bound and an actionable forecast in your programme. Decide what design reviews are told, how repeatability is recorded, and how to stop a single root figure from becoming a budget argument it cannot support.
## Two different questions, one tree Propagating a cost attribute upward — summing at AND, minimising at OR — answers exactly one question: *what is the least an attacker could spend to reach the goal?* That is the **cheapest path**. It is a bound. Interviewers press on this because candidates routinely present the bound as a prediction, and the prediction is usually wrong. The **likeliest path** is a different quantity: which route a real adversary, with real constraints, would actually run. Cost is one input to that decision and rarely the dominant one. ## The refund-redirect case A national tax-filing portal; goal, "have a refund paid into an account I control". Three OR branches, three different attacker positions: | Branch | Attacker position | Cost shape | | --- | --- | --- | | Phish taxpayer portal credentials | anonymous, remote | notable setup, near-zero per victim | | Compromise the tax-preparer software vendor | supply chain | very high, but enormous reach | | Pay a contact-centre agent to change bank details | bribed insider | low, per account, needs a contact | Minimum-at-OR selects the bribe. And yet the bribe is a poor business: it consumes a human accomplice who can name you, it does not repeat without recruiting again, and it converts a remote crime into one with a witness. The phishing branch has a worse *unit price on the tree* and a far better *expected return* to the attacker, because the tree prices one execution and the attacker is planning thousands. ## What the cost number leaves out - **Marginal versus fixed cost.** The tree usually records a single-execution cost. An attacker with a repeatable branch amortises setup across every victim; a branch that must be re-bought per target does not scale at all. - **Risk of exposure.** Bribery, physical presence and coercion carry consequences the money figure does not represent. Many adversaries will pay considerably more to stay remote and deniable. - **Capability already held.** A crew that already runs phishing infrastructure prices that branch at nearly nothing and prices an unfamiliar branch at the cost of learning it. Cost is attacker-relative; your tree is annotated with your estimate of a generic attacker. - **Motive and target selection.** A branch that reaches one account is not comparable to one that reaches every account, yet cost propagation treats reaching the goal once as reaching the goal. - **Your enumeration.** Any branch you never drew is implicitly priced at infinity. The cheapest path is the cheapest path *in your model*. ## Buy versus build resets the answer A mobile game's in-app currency ledger, adversary an authenticated player, asset the virtual economy and the revenue behind it. One branch is "discover a flaw in the currency-grant endpoint" — expensive, needs skill. A sibling OR branch is "buy a working exploit from a resale market" — priced at whatever the market asks, and completely independent of how hard the discovery was. Adding that branch can collapse the root without anyone finding anything new. Trees that model only capability development and never purchase systematically overstate their bound. ## How to keep both readings honest 1. **Report a path, not a number.** "Cheapest complete path: bribe a contact-centre agent, roughly 2,000 per account" is checkable; "root = 2,000" is not. 2. **Report the runner-up.** Because OR takes a minimum, the root moves only to the second-cheapest branch when the first is closed. Showing both prevents a design review from over-valuing a single fix. 3. **Name the adversary profile.** Run the tree once per profile — anonymous remote actor, bribeable insider, compromised vendor — and let each profile's cheapest path be its own answer. A single root number silently averages over incompatible adversaries. 4. **Keep repeatability as an explicit annotation.** Per-attempt versus one-off is the single attribute that most often flips cheapest and likeliest, and it costs nothing to record. 5. **Do not manufacture probabilities.** "Likeliest" here means *best fit to a named adversary profile*, argued from repeatability, exposure and held capability — not a percentage invented to look rigorous. ## Why still cost the tree Because the bound is the falsifiable part. The cheapest path is where an embarrassing branch surfaces — the one nobody meant to leave open, that no threat-intelligence narrative would have predicted, and that costs three orders of magnitude less than the design's headline defences. A likelihood story is arguable; a cheap complete path is demonstrable, and it is the reason attack trees survive contact with sceptical engineers.
- What can reset the cheapest path without anyone discovering a new weakness?Purchase. On a mobile game's in-app currency tree, "buy a working exploit on a resale market" is a legitimate OR sibling of "find the flaw yourself", and it is priced at whatever the market asks. Adding it caps the root at the market rate no matter how expensive discovery was. A tree that models only capability development, never acquisition, reports a bound it cannot defend.
- How would you present both readings to a design review without confusing them?Two lines. First the cheapest complete path, named end to end with its cost and its runner-up, framed as the bound on our guarantee. Second, the path our named adversary profile would actually pick, with the reasoning — repeatability, exposure, capability they already hold — stated as assumptions rather than probabilities. Different controls usually follow from each, and the review needs to fund both deliberately.
- If cost is attacker-relative, whose estimates belong on the leaves?A named profile's. Annotating for a generic attacker produces numbers nobody holds, so I fix the profile first — anonymous remote actor, bribeable insider, compromised vendor — and cost the leaves as that profile experiences them. The same tree then yields several cheapest paths, which is more useful than one averaged figure, and it makes the assumptions visible enough to be argued with.
The cheapest way into a building might be bribing the night guard once. The way people actually get in is the fire door that has been propped open for years, because it works every night and nobody has to be paid.
saying these in an interview costs you the question
- Reporting the root value as what will happen
- Assuming attackers know only the branches you drew
- Ignoring that cheap-per-attempt beats cheap-once
- Treating your cost estimates as the attacker's
- Deleting expensive branches from the tree as irrelevant
- Inventing probabilities to make likelihood look rigorous