skip to content

How do you fix an attack tree level where one sibling is a broad sub-goal and the next is a single keystroke?

level: seniorimportance: nice to knowfreq 31%

answer

  1. siblings answer the same question
  2. one step of how per level
  3. a sub-goal is a state, an action is an act
  4. demote the specific, promote the vague
  5. lopsided branches track attention, not risk

basics

~20 s

Rewrite the level so every sibling sits at the same grain, each naming a state the attacker still has to reach. Demote the over-specific child under the sub-goal it serves; promote anything vaguer than its neighbours.

solid answer

~50 s

Children of one node should all answer "how, one step?" and each should name a state the attacker wants next, not an action they type. Take a ticket-inspection handheld with the root `travel without a valid fare being recorded`. A well-levelled OR beneath it reads: never be inspected; present something the handheld accepts; be inspected but have the record fail to stick. A sibling like `hold up a screenshot of yesterday's ticket` is three levels too low and belongs under the second one. Fix it by demoting the specific child and promoting anything vaguer than its neighbours. Consistent levels matter because siblings only become comparable - by cost, by skill, by how you would detect them - when they sit at the same grain, and because a coarse unexpanded sibling can quietly hide the cheapest attack in the tree.

go deeper

for a junior

Know that the children of one attack-tree node should be roughly equal in scope, and that a specific action sitting beside a broad goal is a sign the level needs fixing.

for a middle

Explain the state-versus-act test for a sub-goal and be able to demote a too-specific child under the sub-goal it serves, then name that sub-goal's other children.

for a senior

Produce a well-levelled first refinement live, defend why those siblings are peers, and explain why a shallow branch is not evidence of low risk.

for a principal

Own levelling as a review standard for the team's trees, since inconsistent grain is what makes branch ratings and cross-tree comparison unusable at portfolio scale.

## The rule Every child of a node answers the same question about that node — *how, in one step?* — and the children should all sit at the same distance from the parent. A **sub-goal** names a state or capability the attacker still has to reach; when a node names a specific act the attacker performs, it has left the sub-goal levels and become an action. ## The worked case A rail operator's ticket-inspection handheld. Root: `travel without a valid fare being recorded`, adversary an anonymous member of the public, assets revenue and audit truth. A consistently levelled first refinement: ``` GOAL: travel without a valid fare being recorded OR |- never be inspected at all |- be inspected and present something the device accepts '- be inspected, be caught, and have the record not stick ``` Three siblings, one grain, each a state the attacker wants, none naming a technique. Now the malformed version: ``` OR |- never be inspected at all |- hold up a screenshot of yesterday's ticket '- be inspected, be caught, and have the record not stick ``` The middle child is an action, and it is a *specific case* of a sub-goal that is now missing from the level. The tree no longer says that presenting an accepted credential is a route at all; it says one particular trick is. ## The three symptoms 1. **A lopsided tree.** One branch is expanded to great depth because it was the branch someone had already found; its siblings are one line each. Depth in a tree tracks attention, not risk, and a reader mistakes the two. 2. **Siblings you cannot compare.** Rating a branch — what it costs, what skill it needs, whether you would see it — only means something across nodes at the same grain. A sub-goal and a keystroke put side by side produce a comparison that is arithmetically fine and semantically meaningless. 3. **Hidden alternatives.** When a specific action stands in for the sub-goal it belongs to, the sub-goal's *other* children never get written down. This is the expensive symptom: the cheapest attack in the tree is often the one that lives under a coarse or misplaced sibling nobody expanded. ## How to fix a level - **Demote.** Ask what sub-goal the over-specific child serves. Insert that sub-goal as the sibling, and hang the specific child beneath it. Then look for the specific child's own siblings — they are usually easy to write once the parent is named, and they are the value you just recovered. - **Promote.** A child that is really the same idea as its parent, or that is broader than its neighbours, gets merged upward or split into peers that match the grain. - **Read the level aloud** as a sentence: "to achieve the parent, the attacker may X, or Y, or Z" for an OR, "must X and Y and Z" for an AND. Grammatical awkwardness at one child is a reliable smell. - **Test each child for state-versus-act.** If it describes something the attacker *is* or *has* afterwards, it is a sub-goal. If it describes a thing they *do*, you are lower than the level intends. - **Probe the OR set for completeness.** Add an explicit `some other way to <parent>` child while you work. If it feels plausible, the level is incomplete and you have an honest placeholder rather than a false sense of coverage; remove it when the level is argued. Separately from level consistency, how far *down* to keep going before stopping is its own question, decided by what you plan to do with the tree — do not conflate a levelling defect with a depth decision. ## Why an interviewer cares Levelling is where a candidate who has actually built trees separates from one who has only read about them. Anyone can name AND and OR. Producing a first refinement whose three or four siblings are genuinely peers, cover the space, and each still name something the attacker wants — on a whiteboard, live — is a skill you only get by doing it and having someone push back on it.

  • How do you check that an OR level is anywhere near complete?
    Add a temporary `some other way to reach the parent` child while you work. If it still feels plausible once the named siblings are listed, the level is incomplete and you have an explicit admission of that rather than a false sense of coverage. Fresh eyes help too: completeness at a level is the one thing the person who drew it is worst at judging.
  • What breaks later if you leave the levels inconsistent?
    Every downstream use of the tree. Comparing branches by cost or skill only means something between peers, so ratings across mismatched grains are noise; effort follows depth rather than risk; and the cheapest path frequently sits under the coarse sibling nobody expanded, so the tree quietly under-reports the attack you most need to see.

saying these in an interview costs you the question

  • Expands only the branch that was discovered first
  • Puts a broad objective and a single command side by side as siblings
  • Reads a shallow branch as a low-risk branch
  • Adds a level for every step of a procedure
  • Assumes the drawn set of OR children is exhaustive

context