Attack trees decompose goals into possible paths
Start with what the attacker wants and work backwards through every way they could get it.
It produces a structure rather than a list, which makes it obvious when several branches share a single control, and when an expensive mitigation only closes one route out of five. It also handles non-technical branches naturally: bribery and physical access sit in the tree alongside exploits.
More on Threat modelling
- Assets are what attackers want to affectThey came for one thing
- Abuse cases describe intentional misuseIt worked perfectly
- Threat models expire as systems changeThe plan stopped growing
- Mitigations should connect to specific threatsEvery thread ends on a peg
- Threat models include failure without an attackerTwo ways the same mast falls
- Data-flow diagrams reveal hidden crossingsDraw the pipes, find the crossings
