KIT | KIT-Bibliothek | Impressum | Datenschutz

The Cost of Repetition: A Compositional Scalability Model for Attack Trees

Fruböse, Clemens ORCID iD icon 1,2; Hetzel, Eva ORCID iD icon 1,2
1 Karlsruher Institut für Technologie (KIT)
2 Institut für Informationssicherheit und Verlässlichkeit (KASTEL), Karlsruher Institut für Technologie (KIT)

Abstract:

Repeated cyber attacks rarely entail constant attacker costs: Tool reuse, learning effects, detection, and access burn-out can produce economies or diseconomies of scale. Yet existing quantitative attack tree analyses typically treat costs and impacts as static values and therefore miss how attacker incentives change under repetition. In this paper, we add a previously overlooked dimension to attack tree based risk analysis, which is the number of attack executions. We lift cost and damage from static scalars to execution-indexed functions and provide compositional AND/OR propagation rules that yield path-level cost and damage profiles, enabling joint cost–damage analysis under repeated executions. The resulting cost–damage relations can be non-concave due to scalable costs and nonlinear damage effects (e. g., economies of scale, saturation, or threshold behavior).
On illustrative attack trees, we show that scalability reshapes optimal attacker choices across objectives (net benefit, return on investment, budget- and target-constrained): A path optimal for a single execution may be suboptimal for multiple executions, even switching paths across executions can be optimal. ... mehr


Postprint §
DOI: 10.5445/IR/1000197131
Frei zugänglich ab 31.08.2027
Originalveröffentlichung
DOI: 10.1007/978-3-032-35298-9_18
Zugehörige Institution(en) am KIT Institut für Informationssicherheit und Verlässlichkeit (KASTEL)
Publikationstyp Proceedingsbeitrag
Publikationsjahr 2027
Sprache Englisch
Identifikator ISBN: 978-3-032-35298-9
ISSN: 0302-9743
KITopen-ID: 1000197131
HGF-Programm 46.23.02 (POF IV, LK 01) Engineering Security for Energy Systems
Erschienen in Quantitative Evaluation of Systems and Formal Modeling and Analysis of Timed Systems : Third International Joint Conference, QEST+FORMATS 2026, Liverpool, UK, September 2–4, 2026, Proceedings. Ed.: M. Chen
Veranstaltung 3rd International Joint Conference, QEST+FORMATS (2026), Liverpool, Vereinigtes Königreich, 02.09.2026 – 04.09.2026
Verlag Springer Nature Switzerland
Seiten 313–330
Serie Lecture Notes in Computer Science ; 16913
Vorab online veröffentlicht am 30.08.2026
Schlagwörter attack trees, cumulative cost curves, risk quantification, scalability of attacks, security economics
Nachgewiesen in OpenAlex
Relationen in KITopen
KIT – Die Universität in der Helmholtz-Gemeinschaft
KITopen Landing Page