{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,10]],"date-time":"2026-06-10T16:01:08Z","timestamp":1781107268826,"version":"3.54.1"},"reference-count":34,"publisher":"IGI Global Scientific Publishing","issue":"2","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2012,4]]},"abstract":"<jats:p>Attack\u2013defense trees can be used as part of threat and risk analysis for system development and maintenance. They are an extension of attack trees with defense measures. Moreover, tree nodes can be decorated with attributes, such as probability, impact, and penalty, to increase the expressiveness of the model. Attribute values are typically assigned based on cognitive estimations and historically recorded events. This paper presents a practical case study with attack\u2013defense trees. First, the authors create an attack\u2013defense tree for an RFID-based goods management system for a warehouse. Then, they explore how to use a rich set of attributes for attack and defense nodes and assign and aggregate values to obtain condensed information, such as performance indicators or other key security figures. The authors discuss different modeling choices and tradeoffs. The case study led them to define concrete guidelines that can be used by software developers, security analysts, and system owners when performing similar assessments.<\/jats:p>","DOI":"10.4018\/jsse.2012040101","type":"journal-article","created":{"date-parts":[[2012,5,16]],"date-time":"2012-05-16T09:58:38Z","timestamp":1337162318000},"page":"1-35","source":"Crossref","is-referenced-by-count":43,"title":["Attribute Decoration of Attack\u2013Defense Trees"],"prefix":"10.4018","volume":"3","author":[{"given":"Alessandra","family":"Bagnato","sequence":"first","affiliation":[{"name":"TXT e-solutions, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Barbara","family":"Kordy","sequence":"additional","affiliation":[{"name":"University of Luxembourg, Luxembourg"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Per H\u00e5kon","family":"Meland","sequence":"additional","affiliation":[{"name":"SINTEF ICT, Norway"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Patrick","family":"Schweitzer","sequence":"additional","affiliation":[{"name":"University of Luxembourg, Luxembourg"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"2432","reference":[{"key":"jsse.2012040101-0","doi-asserted-by":"crossref","unstructured":"Abdulla, P. A., Cederberg, J., & Kaati, L. (2010). Analyzing the security in the GSM radio network using attack jungles. In T. Margaria & B. Steffen (Eds.), Proceedings of the 4th International Conference on Leveraging Applications of Formal Methods, Verification, and Validation - Volume 1 (LNCS 6415, pp. 60-74).","DOI":"10.1007\/978-3-642-16558-0_8"},{"key":"jsse.2012040101-1","unstructured":"Amenaza. (2011). SecurITree. Retrieved from http:\/\/www.amenaza.com\/"},{"key":"jsse.2012040101-2","author":"E. G.Amoroso","year":"1994","journal-title":"Fundamentals of computer security technology"},{"key":"jsse.2012040101-3","doi-asserted-by":"crossref","unstructured":"Baca, D., & Petersen, K. (2010). Prioritizing countermeasures through the countermeasure method for software security (CM-Sec). In M. A. Babar, M. Vierimaa, & M. Oivo (Eds.), Proceedings of the 11th International Conference on Product-Focused Software Process Improvement (LNCS 6156, pp. 176-190).","DOI":"10.1007\/978-3-642-13792-1_15"},{"key":"jsse.2012040101-4","doi-asserted-by":"crossref","unstructured":"Bistarelli, S., Dall\u2019Aglio, M., & Peretti, P. (2007). Strategic games on defense trees. In T. Dimitrakos, F. Martinelli, P. Y. A. Ryan, & S. Schneider (Eds.), Proceedings of the 4th International Workshop on Formal Aspects in Security and Trust (LNCS 4691, pp. 1-15).","DOI":"10.1007\/978-3-540-75227-1_1"},{"key":"jsse.2012040101-5","doi-asserted-by":"crossref","unstructured":"Buldas, A., Laud, P., Priisalu, J., Saarepera, M., & Willemson, J. (2006). Rational choice of security measures via multi-parameter attack trees. In J. Lopez (Eds.), Proceedings of the First International Workshop on Critical Information Infrastructures Security (LNCS 4347, pp. 235-248).","DOI":"10.1007\/11962977_19"},{"key":"jsse.2012040101-6","unstructured":"Byres, E. J., Franz, M., & Miller, D. (2004, December). The use of attack trees in assessing vulnerabilities in SCADA systems. Paper presented at the International Infrastructure Survivability Workshop, Lisbon, Portugal."},{"key":"jsse.2012040101-7","doi-asserted-by":"crossref","unstructured":"Dacier, M., & Deswarte, Y. (1994). Privilege graph: an extension to the typed access matrix model. In D. Gollmann (Ed.), Proceedings of the Third European Symposium on Research in Computer Security (LNCS 875, pp. 319-334).","DOI":"10.1007\/3-540-58618-0_72"},{"key":"jsse.2012040101-8","unstructured":"Diallo, M. H., Romero-Mariona, J., Sim, S. E., Alspaugh, T. A., & Richardson, D. J. (2006, June). A comparative evaluation of three approaches to specifying security requirements. In Proceeding of the 12th International Working Conference on Requirements Engineering: Foundation for Software Quality."},{"key":"jsse.2012040101-9","doi-asserted-by":"crossref","unstructured":"Edge, K. S., Dalton, G. C., II, Raines, R. A., & Mills, R. F. (2006, October). Using attack and protection trees to analyze threats and defenses to homeland security. In Proceedings of the IEEE Military Communications Conference (pp. 953-959). Washington, DC: IEEE Computer Society.","DOI":"10.1109\/MILCOM.2006.302512"},{"key":"jsse.2012040101-10","doi-asserted-by":"crossref","unstructured":"Fung, C., Chen, Y., Wang, X., Lee, J., Tarquini, R., Anderson, M., & Linger, R. (2005, October). Survivability analysis of distributed systems using attack tree methodology. In Proceedings of the IEEE Military Communications Conference (pp. 583-589). Washington, DC: IEEE Computer Society.","DOI":"10.1109\/MILCOM.2005.1605745"},{"key":"jsse.2012040101-11","doi-asserted-by":"crossref","unstructured":"Henniger, O., Apvrille, L., Fuchs, A., Roudier, Y., Ruddle, A., & Weyl, B. (2009). Security requirements for automotive on-board networks. In Proceedings of the 9th International Conference on Intelligent Transport Systems Telecommunications (pp. 641-646). Washington, DC: IEEE Computer Society.","DOI":"10.1109\/ITST.2009.5399279"},{"key":"jsse.2012040101-12","doi-asserted-by":"crossref","unstructured":"Herley, C. (2009). So long, and no thanks for the externalities: the rational rejection of security advice by users. In Proceedings of the Workshop on New Security Paradigms (pp. 133-144). New York, NY: ACM.","DOI":"10.1145\/1719030.1719050"},{"key":"jsse.2012040101-13","doi-asserted-by":"crossref","unstructured":"J\u00fcrgenson, A., & Willemson, J. (2008). Computing exact outcomes of multi-parameter attack trees. In R. Meersman & Z. Tari (Eds.), Proceedings of the On The Move to Meaningful Internet Systems (LNCS 5332, pp. 1036-1051).","DOI":"10.1007\/978-3-540-88873-4_8"},{"key":"jsse.2012040101-14","doi-asserted-by":"crossref","unstructured":"Kordy, B., Mauw, S., Melissen, M., & Schweitzer, P. (2010). Attack\u2013defense trees and two-player binary zero-sum extensive form games are equivalent. In T. Alpcan, L. Butty\u00e1n, & J. S. Baras (Eds.), Proceedings of the First International Conference on Decision and Game Theory for Security (LNCS 6442, pp. 245-256).","DOI":"10.1007\/978-3-642-17197-0_17"},{"key":"jsse.2012040101-15","doi-asserted-by":"crossref","unstructured":"Kordy, B., Mauw, S., Radomirovi\u0107, S., & Schweitzer, P. (2011a). Foundations of attack\u2013defense trees. In P. Degano, S. Etalle, & J. Guttman (Eds.), Proceedings of the 7th International Workshop on Formal Aspects of Security and Trust (LNCS 6561, pp. 80-95).","DOI":"10.1007\/978-3-642-19751-2_6"},{"key":"jsse.2012040101-16","doi-asserted-by":"crossref","unstructured":"Kordy, B., Pouly, M., & Schweitzer, P. (2011b). Computational aspects of attack\u2013defense trees. In P. Bouvry, M. A. Klopotek, F. Lepr\u00e9vost, M. Marciniak, A. Mykowiecka & H. Rybinski (Eds.), Proceedings of the International Joint Conferences on Security & Intelligent Information Systems (LNCS 7053, pp. 103-116).","DOI":"10.1007\/978-3-642-25261-7_8"},{"key":"jsse.2012040101-17","doi-asserted-by":"publisher","DOI":"10.1007\/s12209-009-0029-y"},{"key":"jsse.2012040101-18","doi-asserted-by":"crossref","unstructured":"Manikas, T. W., Thornton, M. A., & Feinstein, D. Y. (2011). Using multiple-valued logic decision diagrams to model system threat probabilities. In Proceedings of the 41st IEEE International Symposium Multiple-Valued Logic (pp. 263-267). Washington, DC: IEEE Computer Society.","DOI":"10.1109\/ISMVL.2011.12"},{"key":"jsse.2012040101-19","unstructured":"Mauw, S., & Oostdijk, M. (2005). Foundations of attack trees. In D. H. Won & S. Kim (Eds.), Proceedings of the International Conference on Information Security and Cryptology (LNCS 3935, pp. 186-198)."},{"key":"jsse.2012040101-20","doi-asserted-by":"crossref","unstructured":"Meland, P. H., T\u00f8ndel, I. A., & Jensen, J. (2010). Idea: Reusability of threat models - two approaches with an experimental evaluation. In F. Massacci, D. Wallach, & N. Zannone (Eds.), Proceedings of the International Symposium on Engineering Secure Software and Systems (LNCS 5965, pp. 114-122).","DOI":"10.1007\/978-3-642-11747-3_9"},{"key":"jsse.2012040101-21","doi-asserted-by":"publisher","DOI":"10.1109\/MPRV.2009.68"},{"key":"jsse.2012040101-22","doi-asserted-by":"crossref","DOI":"10.21236\/ADA387544","author":"A. P.Moore","year":"2001","journal-title":"Attack modeling for information security and survivability"},{"key":"jsse.2012040101-23","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2008.05.013"},{"key":"jsse.2012040101-24","unstructured":"Pi\u00e8tre-Cambac\u00e9d\u00e8s, L., & Bouissou, M. (2010). Beyond attack trees: Dynamic security modeling with Boolean Logic Driven Markov Processes (BDMP). In Proceedings of the European Dependable Computing Conference (pp. 199-208).Washington, DC: IEEE Computer Society."},{"key":"jsse.2012040101-25","unstructured":"Roy, R., Kim, D. S., & Trivedi, K. S. (2011). Attack countermeasure trees (ACT): towards unifying the constructs of attack and defense trees. Security and Communication Networks."},{"issue":"4","key":"jsse.2012040101-26","first-page":"124","article-title":"Threat modeling using attack trees.","volume":"23","author":"V.Saini","year":"2008","journal-title":"Journal of Computing Sciences in Colleges"},{"issue":"12","key":"jsse.2012040101-27","first-page":"21","article-title":"Attack trees.","volume":"24","author":"B.Schneier","year":"1999","journal-title":"Dr. Dobb\u2019s Journal of Software Tools"},{"key":"jsse.2012040101-28","unstructured":"SHIELDS. (2008-2010). FP7 project, grant agreement 215995. Retrieved from http:\/\/www.shields-project.eu\/"},{"key":"jsse.2012040101-29","unstructured":"Tanu, E., & Arreymbi, J. (2010). An examination of the security implications of the supervisory control and data acquisition (SCADA) system in a mobile networked environment: An augmented vulnerability tree approach. In Proceedings of the 5th Annual Conference on Advances in Computing and Technology (pp. 228-242)."},{"key":"jsse.2012040101-30","unstructured":"T\u00f8ndel, I. A., Jensen, J., & R\u00f8stad, J. (2010). Combining misuse cases with attack trees and security activity models. In Proceedings of the International Conference on Availability, Reliability and Security, Krakow, Poland (pp. 438-445). Washington, DC: IEEE Computer Society."},{"key":"jsse.2012040101-31","unstructured":"Vesely, W. E., Goldberg, F. F., Roberts, N. H., & Haasl, D. F. (1981). Fault tree handbook (Tech. Rep. No. NUREG-0492). Washington, DC: U.S. Regulatory Commission."},{"issue":"1","key":"jsse.2012040101-32","doi-asserted-by":"crossref","first-page":"20","DOI":"10.20533\/ijisr.2042.4639.2011.0003","article-title":"Unified parametrizable attack tree.","volume":"1","author":"J.Wang","year":"2011","journal-title":"International Journal for Information Security Research"},{"key":"jsse.2012040101-33","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2005.08.004"}],"container-title":["International Journal of Secure Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.igi-global.com\/viewtitle.aspx?TitleId=66406","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,6,28]],"date-time":"2019-06-28T16:12:49Z","timestamp":1561738369000},"score":1,"resource":{"primary":{"URL":"http:\/\/services.igi-global.com\/resolvedoi\/resolve.aspx?doi=10.4018\/jsse.2012040101"}},"subtitle":[""],"short-title":[],"issued":{"date-parts":[[2012,4]]},"references-count":34,"journal-issue":{"issue":"2"},"URL":"https:\/\/doi.org\/10.4018\/jsse.2012040101","relation":{},"ISSN":["1947-3036","1947-3044"],"issn-type":[{"value":"1947-3036","type":"print"},{"value":"1947-3044","type":"electronic"}],"subject":[],"published":{"date-parts":[[2012,4]]}}}