skip to content

An architect multiplies four layers' bypass costs to size an attack - when is that arithmetic wrong?

level: seniorimportance: should knowfreq 41%

answer

  1. compounding assumes conditional independence
  2. cost of B given A already cleared
  3. correlated add, inherited contribute nothing
  4. group by fact, compound across groups
  5. every cost is relative to an assumed actor

basics

~20 s

Multiplication holds only across independent preconditions. Where controls are satisfied by the same fact, their costs add rather than multiply, and a control that inherits the fact entirely adds nothing — the real total is the cost of obtaining the shared fact.

solid answer

~50 s

The multiply-the-costs model quietly assumes that clearing one layer tells an actor nothing about clearing the next. That assumption is what makes depth compound, and it is exactly what fails in a correlated stack. If control B is satisfied by the same fact as control A, then once A is cleared B is already cleared: it contributes a factor of one, not a factor of a thousand. The honest way to combine is to group the controls by the fact each accepts, treat each group as one layer whose cost is the cost of obtaining that fact plus the largest extra effort inside the group, and only then compound *across* groups. Two more things fall out. Costs are always relative to an assumed actor — an insider's cost for 'holds a legitimate job identity' is zero, so every control conditioned on it is free to them. And a stack can be genuinely deep while looking flat, so the same arithmetic can under-count too.

go deeper

for a junior

Know that adding controls does not automatically make an attack harder, and that two controls satisfied by the same fact do not stack. You are not expected to model the cost yet.

for a middle

Explain conditional cost in plain words: the second layer costs whatever it costs given the first is already cleared, and that is zero when both accept the same fact.

for a senior

Show the replacement procedure — group controls by accepted fact, compound only across groups, and state the result ordinally rather than as an invented product of four numbers.

for a principal

Own the framing for a leadership audience: sizing is relative to an assumed actor, so the same stack has different answers for an outsider and a contributor, and the architecture decision follows from which actor you have accepted.

## The wrong answer this question is aimed at A competent senior engineer, asked how hard a stack is to get through, reaches for multiplication: this layer is worth a thousand, that one a hundred, that one ten, so we are at a million and nobody is doing that. The instinct is sound and the arithmetic is sometimes right. It is right precisely when the layers are independent — and nothing in the box count tells you whether they are. ## Where the multiplication comes from Compounding is a statement about conditional cost. The cost of clearing A and then B is the cost of A, plus the cost of B *given that A has already been cleared*. If knowing you cleared A tells you nothing about B, that conditional cost is the full cost of B, and the combined difficulty is much larger than either alone — the effect people summarise as 'multiplying'. If A and B are conditioned on the same fact, the conditional cost of B given A is **zero**. An actor who obtained the fact to clear A has already obtained everything B asks for. The factor B contributes is one. ## The three regimes - **Independent preconditions.** Cost compounds. This is the case depth was invented for, and it is worth building deliberately. - **Partially correlated.** The second control accepts the same fact but demands a different *procedure* — a different tool, a different route, an extra step. The actor must do more work, but they need nothing new. Costs here **add**, and usually add a little. - **Fully inherited.** The second control is decided entirely by something the first already established. It adds nothing at all to an actor's cost, whatever it cost you to buy and run. The practical review move is to write, beside each control, the single fact it accepts; group by fact; count groups. Within a group, the cost is roughly the cost of the shared fact plus the largest extra effort any member imposes — not the sum of the members' headline numbers. Only across groups does the compounding argument apply. ## Costs belong to an assumed actor A bypass cost is not a property of a control; it is a property of a control *and* the actor you have in mind. 'Holds a valid privileged session' may be genuinely expensive for a remote actor with nothing, and it is exactly zero for the person the session belongs to and for anyone whose standing rights include starting it. So the same stack can be worth a million against one assumed actor and worth nothing against another, without a single control changing. This is why the layer-count question and the actor question have to be answered together, and why a stack of controls all conditioned on 'this is a legitimate job' is a strong architecture against outsiders and an empty one against a contributor who may edit the job. ## The error runs both ways Multiplying correlated layers over-states depth, which is the dangerous direction. But naive counting can also under-state it. Two controls that look nearly identical can rest on different principals — one on a machine identity, one on a human who is not that machine — and those really do compound even though the diagram shows two similar boxes side by side. The fix in both directions is the same: stop reading the boxes and read the preconditions. ## Do not put a false number on it Nobody has trustworthy per-layer bypass costs, and a plausible-looking product of four invented numbers is worse than no number, because it survives into slide decks. The defensible output of this analysis is ordinal, not cardinal: *these four controls are one layer, this stack has two distinct preconditions, and the cheaper of the two is free to anyone with commit rights on the pipeline*. That sentence supports a decision. 'Ten to the sixth' does not. ## Answering it well State the condition under which multiplication is valid, name the failure — correlated layers add, inherited ones contribute nothing — and then give the grouping procedure as your replacement. Finish by pointing out that any such number is relative to an assumed actor, and that for an insider the shared fact is free.

  • Six controls rest on three distinct facts. How would you size the stack?
    As three layers, not six. For each group, the cost is the cost of obtaining that group's fact plus the largest extra effort any member of it imposes; you compound only across the three groups. Then state it ordinally — which of the three facts is cheapest for the actor you are assuming, because that one bounds the whole stack for them.
  • Does this mean correlated controls should be removed?
    No. A correlated control can still limit what an actor can do once inside the shared precondition, catch a misconfiguration, or force a slower and clumsier procedure. What you must not do is count it as a layer when sizing an attack or when justifying that no further work is needed. Remove it only if it costs more to run than the narrowing it buys.
  • Can naive layer counting ever under-state depth?
    Yes. Two boxes that look alike can rest on different principals — one satisfied by a machine identity, the other by a human who cannot be that machine — and those genuinely compound. Counting boxes gets this wrong in both directions, which is why the grouping is done on preconditions rather than on the diagram.

saying these in an interview costs you the question

  • Multiplies per-layer costs without checking independence
  • Quotes a precise combined number nobody can defend
  • Treats bypass cost as a property of the control alone
  • Forgets an insider's cost for the shared fact is zero
  • Assumes any extra control raises the total

context