skip to content

In an attack tree, why does propagating cost and time separately give an unreal path?

level: principalimportance: nice to knowfreq 27%

answer

  1. different branches win different columns
  2. the argmin is per attribute
  3. the root stops naming one attack
  4. carry the path, not just the number

basics

~20 s

Each attribute's minimum can land on a different OR branch, so the root reports one branch's money beside another branch's hours. That combination is not an attack anyone can run. Propagate whole annotated paths, not independent columns of numbers.

solid answer

~50 s

The min/sum machinery is defined per attribute, so running it over several attributes at once quietly loses the link between a value and the branch it came from. On a hospital medication-order integrity tree, forging prescriber credentials costs real money but takes minutes, while walking a ward as agency staff and altering an order at an unattended workstation costs almost nothing but demands hours of unobserved physical presence. Minimise in currency and you select the ward branch; minimise in hours and you select the forgery branch. Propagate both independently and the root reads “cheap and fast”, describing an attack that exists in no branch. Fix it by propagating the whole annotation tuple **with the path identity attached**, so the root names a real branch; by treating required privilege or physical access as feasibility gates that prune branches per adversary profile before any minimisation; and by combining attributes only with weights you state out loud.

go deeper

for a junior

Know that the sum-and-minimum rules apply to one attribute at a time. If a tree is annotated with both money and time, do not assume the cheapest branch is also the fastest.

for a middle

Explain with a concrete pair of branches why minimising each column independently yields a profile matching no branch, and know that required access and skill behave as conditions rather than costs.

for a senior

Show the remedy in practice: carry the winning child's identity with its numbers so the root names a path, prune branches per adversary profile before minimising, and refuse to hand a review a figure assembled from incompatible branches.

for a principal

Own the convention your organisation uses. Decide whether trees report one root per adversary profile or a weighted single figure, insist the weights be visible, and be ready to argue why a defensible named path beats a tidy composite score in front of a sceptical review.

## The failure Cheapest-path propagation is defined for **one** attribute at a time: sum it at AND, minimise it at OR. Nothing in that definition says the winning child at an OR node is the same child for every attribute. Run the machinery independently over money, hours, skill and detectability, and each column's minimum can be contributed by a different branch. The root then holds a **synthetic profile** — the cheapest money, the shortest time, the lowest skill — that corresponds to no path in the tree and to no attack a human could execute. ## Worked case: medication-order integrity A hospital, asset patient safety, goal "cause a patient to receive an order they were not prescribed". Two branches under one OR: | Branch | Money | Hands-on time | Access required | | --- | --- | --- | --- | | Forge prescriber credentials and submit remotely | substantial | minutes | none physical | | Enter as agency staff, alter an order at an unattended ward workstation | near zero | hours of unobserved presence | on-ward physical | The adversary of the second branch is a visitor or agency staffer; of the first, a remote actor with money. Minimising per column produces "near-zero money, minutes of time, no physical access" — better than either real option on every axis, and available to nobody. Presented to a clinical safety review, that root is worse than no number, because it invites controls aimed at an attacker who does not exist. ## Why it happens so easily - **The operators are seductive.** Summing four columns through an AND and minimising four columns through an OR is one loop over an array; nothing errors. - **Units are incommensurable.** Hours and currency have no exchange rate until someone declares one, and a declared rate is a modelling assumption that deserves to be visible. - **Some attributes are not costs at all.** Required privilege level or physical access are *gates*: you either have them or you do not. Minimising a gate as if it were a quantity is meaningless. - **Some attributes compose differently.** Detection probability does not sum. For two independent steps of an AND node each carrying a 0.2 chance of being noticed, the chance of being noticed overall is 1 − (0.8 × 0.8) = 0.36, not 0.4. And the attacker minimises detection at OR, which may select a different branch again. - **Ordinal annotations do not add.** If a leaf is labelled "medium" rather than given a number, the sum at an AND node has no defined result, and the comparison at an OR node only supports an ordering, not arithmetic. ## Four ways to keep the root real 1. **Propagate paths, not numbers.** Carry the whole annotation tuple together with the identity of the child that won. At an OR node you choose one child *by a stated criterion* and inherit all of its attributes, including the unflattering ones. The root then names a branch and reports that branch's full profile, which is checkable by a reviewer who knows the system. 2. **Gate first, minimise second.** Fix an adversary profile — anonymous remote actor, on-site agency staffer, bribeable operator, compromised vendor — and prune every branch whose access or skill requirement the profile cannot meet. Only then minimise on a single attribute. This turns "skill" and "required access" from fake costs into what they actually are: feasibility conditions. 3. **Answer per profile, not per tree.** One tree, several roots. The on-ward profile's cheapest path is the workstation branch; the remote profile's is the credential branch. Two honest answers beat one averaged fiction, and the difference between them is often the most useful output of the exercise. 4. **Scalarise only with declared weights.** If a single figure is genuinely required, combine attributes with an explicit weighting — an hour of unobserved presence valued at some stated rate — and print the weights beside the result. The number then survives challenge, because the arguable part is on the page instead of buried in a spreadsheet. ## What a strong answer sounds like Say plainly that the arithmetic is valid per attribute and invalid across attributes; give a concrete pair of branches where the argmin differs by column; and land on the remedy — keep the path attached to the numbers, treat access and skill as gates, and answer once per adversary profile. Candidates who instead propose normalising every attribute to a 1–5 scale and adding them up have reproduced the original defect with more decimal places: the sum is still combining branches nobody can combine, and now the weighting is implicit at 1:1 rather than argued.

  • How do you keep the propagated answer a real path rather than a synthetic profile?
    Propagate the whole annotation tuple together with the identity of the winning child. At an OR node, choose one branch by a criterion you have stated, then inherit all of that branch's attributes — including the ones that make it look worse. The root then reports a named path with a complete profile, which a reviewer who knows the system can check or contest.
  • Does detectability propagate the same way as cost?
    No. Cost accumulates additively through an AND, but the chance of being noticed across independent steps composes as one minus the product of the per-step survival chances — two 0.2 steps give 0.36, not 0.4. At an OR node the attacker minimises detection, which may pick a different branch than cost minimisation does. Treat it as its own algebra rather than another column in the same loop.
  • Why is required privilege level a poor thing to minimise up the tree?
    Because it is not a quantity the attacker spends, it is a condition they either satisfy or do not. Minimising it produces a root claiming an attack needs little privilege when the branch that supplied the number is unavailable to your adversary. Use it as a filter: fix a profile, prune branches it cannot reach, and minimise cost or time over what remains.
  • What is wrong with normalising every attribute to a 1-5 scale and adding them?
    It hides the same defect behind arithmetic. Adding normalised columns imposes an implicit 1:1 exchange rate between hours, money and skill that nobody argued for, and it still permits the total to be assembled from attributes contributed by different branches unless the path identity is carried through. If a single figure is required, use declared weights and print them beside the result.

Picking the cheapest flight and the shortest flight out of the same timetable does not give you a flight that is both cheap and short. It gives you two flights and a fantasy.

saying these in an interview costs you the question

  • Taking a per-column minimum and calling the result a path
  • Adding hours and currency into one figure without stated weights
  • Summing low, medium and high labels at an AND node
  • Assuming every adversary profile can execute every leaf
  • Propagating detection probability by adding it through an AND
  • Normalising all attributes to one scale and calling it rigour

context