Attack-Defense Trees with Offensive and Defensive Attributes (with Appendix)

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Copae, Danut-Valentin, Soltani, Reza, Lopuhaä-Zwakenberg, Milan
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909582385741824
author Copae, Danut-Valentin
Soltani, Reza
Lopuhaä-Zwakenberg, Milan
author_facet Copae, Danut-Valentin
Soltani, Reza
Lopuhaä-Zwakenberg, Milan
contents Effective risk management in cybersecurity requires a thorough understanding of the interplay between attacker capabilities and defense strategies. Attack-Defense Trees (ADTs) are a commonly used methodology for representing this interplay; however, previous work in this domain has only focused on analyzing metrics such as cost, damage, or time from the perspective of the attacker. This approach provides an incomplete view of the system, as it neglects to model defender attributes: in real-world scenarios, defenders have finite resources for countermeasures and are similarly constrained. In this paper, we propose a novel framework that incorporates defense metrics into ADTs, and we present efficient algorithms for computing the Pareto front between defense and attack metrics. Our methods encode both attacker and defender metrics as semirings, allowing our methods to be used for many metrics such as cost, damage, and skill. We analyze tree-structured ADTs using a bottom-up approach and general ADTs by translating them into binary decision diagrams. Experiments on randomly generated ADTS demonstrate that both approaches effectively handle ADTs with several hundred nodes.
format Preprint
id arxiv_https___arxiv_org_abs_2504_12748
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Attack-Defense Trees with Offensive and Defensive Attributes (with Appendix)
Copae, Danut-Valentin
Soltani, Reza
Lopuhaä-Zwakenberg, Milan
Cryptography and Security
Computer Science and Game Theory
Effective risk management in cybersecurity requires a thorough understanding of the interplay between attacker capabilities and defense strategies. Attack-Defense Trees (ADTs) are a commonly used methodology for representing this interplay; however, previous work in this domain has only focused on analyzing metrics such as cost, damage, or time from the perspective of the attacker. This approach provides an incomplete view of the system, as it neglects to model defender attributes: in real-world scenarios, defenders have finite resources for countermeasures and are similarly constrained. In this paper, we propose a novel framework that incorporates defense metrics into ADTs, and we present efficient algorithms for computing the Pareto front between defense and attack metrics. Our methods encode both attacker and defender metrics as semirings, allowing our methods to be used for many metrics such as cost, damage, and skill. We analyze tree-structured ADTs using a bottom-up approach and general ADTs by translating them into binary decision diagrams. Experiments on randomly generated ADTS demonstrate that both approaches effectively handle ADTs with several hundred nodes.
title Attack-Defense Trees with Offensive and Defensive Attributes (with Appendix)
topic Cryptography and Security
Computer Science and Game Theory
url https://arxiv.org/abs/2504.12748