How do AND and OR branches in an attack tree change where you spend defensive effort?
answer
- any-one versus all-of
- OR: the cheapest child wins
- AND sums, OR takes the minimum
- one broken conjunct closes the branch
- AND is only as strong as independence
basics
~20 sAn OR node means any one child suffices, so the branch costs whatever the cheapest child costs and hardening only some children buys nothing. An AND node needs every child, so breaking one conjunct closes the whole branch.
solid answer
~50 sUnder an OR node the attacker picks, so cost propagates up as the minimum over the children. Take a supplier payout run with the goal `divert a scheduled payout to an account I control`: alter the stored beneficiary record, or inject a fake supplier into the batch, or intercept the approval. Locking down the beneficiary record just moves a finance-ops clerk one sibling across; at the root nothing improved until the cheapest remaining alternative got expensive. Under an AND node all children are required and cost propagates as a sum, so the defender gets to choose the cheapest conjunct to break. A boiler-setpoint goal that needs reach the control segment AND speak the setpoint protocol AND defeat an independent overpressure interlock is closed by whichever conjunct you can hold most durably. The catch is independence: if one compromise satisfies two conjuncts, you drew an AND but you own OR-strength defence.
go deeper
Be ready to state the difference plainly: OR means any one child is enough, AND means the attacker needs all of them, and OR is the default unless the node is marked.
Explain how a value rolls up: minimum over the children of an OR node, sum across the children of an AND node. Expect to be asked which way round it goes and why the attacker gets the choice.
Demonstrate the defensive read on a real branch: which conjunct of an AND you would fund, why partial coverage of an OR set buys nothing at the root, and how you check that AND conjuncts truly fail separately.
Own the framing that AND nodes are where your separation-of-duties and independent-safety investments live, and that a programme reporting controls deployed rather than the cost of the cheapest remaining path is measuring the wrong thing.
## What the two node types actually assert An attack tree decomposes one attacker goal. Each node is refined into children in one of two ways, and the refinement type is the whole grammar of the tree: - **OR (disjunctive)** — *any one* child achieves the parent. This is the default in most notations; nodes are OR unless marked otherwise. - **AND (conjunctive)** — *all* children are required. It is marked explicitly (an arc drawn across the branches, or the literal word `AND` on the node). An AND asserts nothing about **order**: the children are all necessary, not necessarily sequential. The test when you are unsure which you are drawing: *if the attacker skipped this child, does the parent still happen?* Yes means it is an OR alternative. No means it is an AND conjunct. ## Value propagation Annotate the lower nodes with an attribute — money, elapsed time, skill required, whether privileged access is needed — and roll it up: | attribute | at an OR node | at an AND node | |---|---|---| | cost / time | minimum over children (the attacker chooses) | sum of the children (they pay for all) | | feasible at all? | possible if any child is possible | possible only if every child is possible | | minimum skill needed | the least-skilled child | the most-skilled child | Summing across OR children is the classic arithmetic error: it makes a cheap branch look expensive and buries the path the attacker will actually take. ## Worked AND — a district heating plant ``` GOAL: drive the plant outside its safe operating envelope AND |- reach the plant's control network segment |- speak the setpoint protocol convincingly '- defeat the independent overpressure interlock ``` An adversary with a foothold on the operations network must satisfy all three. That gives the defender a genuine choice, and the interlock is usually the best buy: it is mechanical and independent, so it does not care what the control network believes, and it stays true as the software around it churns. ## Worked OR — a weekly supplier payout run ``` GOAL: divert a scheduled payout to an account I control OR |- alter the stored beneficiary record for a real supplier |- inject a fabricated supplier into the payment batch '- intercept and re-approve the batch at the approval step ``` The adversary here is a clerk in finance ops with legitimate access to the batch. Because it is an OR, the root's difficulty equals the **minimum** across the three. Partial coverage of an OR set produces no improvement at the root until the last cheap sibling is lifted — and an alternative you never listed is a minimum you cannot see, which is why completeness of an OR level matters as much as the controls under it. ## The two defender rules that fall out 1. **Under an OR you are managing a minimum.** Measure your improvement by what the cheapest *remaining* sibling now costs, not by how many siblings you touched. Controls that displace an attacker sideways are not risk reduction. 2. **Under an AND you are managing a conjunction and may pick the weakest link to reinforce.** Prefer the conjunct that is cheapest to hold over years, hardest for the attacker to route around, and independent of the other conjuncts. ## The independence trap An AND is only as strong as the assumption that its conjuncts fail separately. Consider an exam-results system and the goal `change a posted final grade so no one notices`: it needs *change the stored mark* **AND** *suppress or forge the matching audit entry*. That is a real conjunction only while the audit trail is out of reach of whoever can write marks. If one database role can do both, a single compromise satisfies both conjuncts and the AND is decorative. Making the log append-only and separately administered is what restores the conjunction — which is the point of drawing it: an AND node tells you exactly which separation you are relying on. ## Mis-marking cuts both ways Marking AND where the truth is OR flatters your defences, because you are quietly assuming the attacker will do all of the work. Marking OR where the truth is AND overstates risk and spends budget on branches that are already blocked by a conjunct you own. Reviewing the AND/OR marks is one of the highest-value passes over a finished tree.
- You harden two of the four children under an OR node. What has happened to the root's difficulty?Nothing, if either untouched sibling is still the cheapest. An OR node's value is the minimum over its children, so the root only moves when the cheapest remaining alternative gets more expensive. That is why OR levels get reported as a single number - the cost of the easiest path - rather than as a count of controls deployed.
- An AND branch has three conjuncts and you can fund only one control. How do you choose?Pick the conjunct the attacker can least easily route around, that is cheapest to keep true over years, and that is independent of the other two. A control on a conjunct that shares a credential, a host or an administrator with a sibling conjunct buys much less than it looks like, because one compromise satisfies both.
- Does an AND node say the child steps happen in a particular order?No. An AND node asserts only that all children are required. Ordering is a separate property; if a real dependency exists - one step must precede another - you note it explicitly rather than reading it off the left-to-right layout. Assuming order leads defenders to over-value a control on whichever child happens to be drawn first.
An OR node is a building with several unlocked doors: bolting three of four changes nothing for someone who tries the fourth. An AND node is a safe needing two keys held by different people.
saying these in an interview costs you the question
- Treats every node as OR because the diagram never marks AND
- Believes hardening one child of an OR node reduces root risk
- Sums costs across the children of an OR node
- Assumes AND conjuncts fail independently without checking
- Reads an AND node as an ordered sequence of steps