arrow
Return

Using Attack Trees for Security Education and Training: Simplifying Threat Analysis

delete2026-01-01
delete0
PRE
AI
D
Damas P. Gruska *
A
Aliyu Tanko Ali
M
Martin Leucker
DOI:10.1007/978-3-031-94924-1_5delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Modern cybersecurity education must prepare learners to understand how security threats can be realized and to diagnose and respond to attacks, under real-world constraints-such as incomplete or ambiguous information. This paper introduces two educational approaches. First, we adapt attack trees, a threat-modeling technique, into an intuitive framework for teaching security reasoning to non-experts, including children. By breaking down attacks into visual, step-by-step scenarios, learners systematically identify risks and countermeasures, fostering critical thinking and collaboration. Second, we propose a method to quantify the diagnosability of attacks, measuring how much information is needed to identify an attacker's actions (which are unseen). This approach helps educators design realistic training exercises where learners prioritize evidence and act decisively under uncertainty. Finally, we discuss how this framework could be translated into a security tool accessible to a wide range of users.
Keywords:
Attack Trees
Diagnosability
Security
Human and Societal Aspects of Security
Cybersecurity Education

Journal

I
INFORMATION SECURITY EDUCATION. EMPOWERING PEOPLE THROUGH INFORMATION SECURITY EDUCATION, WISE 2025
IF:
0
Papers:
17
Citations:
0

Organization

C
Comenius University Bratislava
Scholars:
9.0K
Papers: 6.0K
Citations: 4.8K
U
University of Lubeck
Scholars:
7.6K
Papers: 5.3K
Citations: 1.5W